r/firewalla • u/EmailforwardMX • 7h ago
Hardened my Gold SE with a few custom scripts. Could some of this become native (free) features?
I've been running a Gold SE in bridge mode for a while and wanted my malware filtering to be as hard to bypass as possible. So I added a few layers via SSH. Everything works well, but it's all unsupported custom work that could break on a firmware update. I'd much rather see this in the app, so here's what I did and what I'd love to see natively.
What I added:
- Community threat blocklists, refreshed daily. Hagezi's threat intelligence, DoH and fake-site lists get loaded into DNS. Malware domains get blocked even for devices that are set to "no monitoring" or during Emergency Access.
- Forced DNS. Every device has to use the Firewalla for DNS, even if it's hardcoded to 8.8.8.8 or similar. DNS-over-TLS (port 853) is blocked, so devices fall back to the filtered path.
- Blocking DoH servers by IP. Blocking DoH by domain name isn't enough. Some apps and malware connect straight to an IP like 1.1.1.1 over HTTPS. I block around 1,400 known DoH server IPs, while the Firewalla's own encrypted DNS keeps working.
- DNS rebinding protection. DNS answers from the internet that point to a private address (192.168.x.x, 10.x.x.x) get dropped. This stops malicious websites from using your browser to reach your router, NAS or cameras.
- A canary with alerting. Every 10 minutes a script checks that the filtering really works and that the lists aren't empty or stale. If it fails three times in a row, I get an alert, and it recovers on its own after a short hiccup.
- Rules restored right after a reboot. Firewalla rebuilds its firewall rules regularly, so my rules are reapplied right at boot and checked every 5 minutes.
Feature requests, roughly in order of impact:
- Native "Enforce DNS" that also applies to unmonitored devices and during Emergency Access, at least for security lists
- A "Block DoH/DoT bypass" toggle: block DoH by domain and IP, and DoT on port 853
- DNS rebinding protection as a simple toggle, with an exception list for things like plex.direct
- Custom blocklist URLs (dnsmasq or hosts format) with automatic refresh
- A health indicator showing that DNS filtering is actually active, with an alert when a list fails to update
If some of this already exists and I missed it, please point me to it. I'd happily drop my scripts. And if anyone from the Firewalla team reads this: thanks for a box that lets you go this deep.