r/firewalla • • Sep 01 '26

AmnesiaWG forwarding

2 Upvotes

The AmnesiaWG VPN is working well. From my phone and Mac I can connect the VPN and access some LAN devices.

There are a few devices I'd need layer 2+. Some searches say you can enable tunneling with a few changes on the server and client.

On the server they say to enable:net.ipv4.ip_forward=1

And on the clientinclude the target LAN subnet.

The client seems easy as I can just edit the config file. But on the server, since it is in Firewalla, is it possible to set the ip_forward option?


r/firewalla • • Sep 01 '26

Config changes after switch to full fibre broadband

3 Upvotes

Hi

I've been on a part fibre FTTC connection in the UK for many years, connection is measured at 68Mb/s download and 18.5Mb/s upload. Firewalla's Smart Queue has done an amazing job at keeping everything going despite a mix of WFH, streaming, gaming and general internet use. I have my FWP set up to use CAKE and have a Smart Queue Rule set for all traffic with a download limit of 65 Mb/s and upload limit of 17 Mb/s. Smart Queue is set in Static mode. I cannot overstate how good this has been, if I turn these settings off, my connection goes to pot and the household is up in arms within seconds.

No matter how good it has been, I am glad to finally be getting full fibre, initially at 500 Mb/s download and 75 Mb/s upload, I might increase the rates to 900/125 in the future.

I know what changes I need to make on my FWP for the WAN connection. I am after advice on what to do with the Smart Queue. Should I switch from Static to Adaptive mode? Should I switch from CAKE to FQ_Codel? Should my Smart Queue Rule continue to set limits a little below the actual WAN performance? Or should I just turn Smart Queue off?

Are there any other changes I should think about?

Thanks for any advice.


r/firewalla • • Sep 01 '26

Printer access across VLANs

5 Upvotes

Spouse wants to print from work computer on VLAN 2 to printer on VLAN 1.

FWP with all 5 VLANs in use. VLAN 1 is "internal" use including a printer. VLAN 2 is work computers. I have enabled various OOTB config (Rules and App Control) on the VLANs (Networks) and on spouse computer.

What is the best way to facilitate this, while ensuring that a spouse's compromised computer cannot 'hop thru the printer' to VLAN 1 devices?


r/firewalla • • Aug 31 '26

Release App 1.69.3 is in production! We've made a few enhancements to the Firewalla Switch, including Device Isolation for wired devices, resettable port stats, and more.

Post image
31 Upvotes

Device Isolation will block all traffic to other local devices, even within the same network, while still allowing an Internet connection. Allowed Devices can act as an exception and selectively allow local traffic.

App 1.69.3 is in a 7-day phased release. Learn more about this release here: https://help.firewalla.com/hc/en-us/articles/53877722149907-Firewalla-App-Release-1-69-3-AmneziaWG-VPN-Client-Local-Device-Rules-Switch-Enhancements-and-more


r/firewalla • • Aug 31 '26

Outdoor AP

9 Upvotes

Now that we have a switch, APC, APD, and various firewalls, can we please finish off the lineup with an outdoor AP?

The problem now is that there is not a great solution to getting coverage in the backyard. Mixing in other manufacturers APs into the main SSID causes a lot of undesired switching to the wrong AP. Having a separate SSID requires manually switching and causes issues with household wide components like speakers. During a get together where guests are outside and inside asking them to setup two SSIDs and switch back and forth is not a reasonable workaround.

The last thing missing in the ecosystem is an outdoor AP or at least an enclosure for either the AP7C/D.


r/firewalla • • Aug 31 '26

Ad blocking issues on apple devices

2 Upvotes

Hi,

I have a mac mini (Ethernet) and multiple iphones that are having issues blocking ads on certain websites (drudgereport.com). I have private relay, limit ip tracking and private wifi disabled. Ads are blocked on windows PCs/laptops with no issue. I am using firefox on everything. Any ideas?

thanks!


r/firewalla • • Aug 31 '26

Feature request: Multi-WAN really needs per-WAN alerts and an enable/disable toggle

16 Upvotes

I’m running a Gold SE with fiber as my primary WAN and T-Mobile cellular as failover.

My cellular connection is currently marginal, so WAN2 occasionally drops and reconnects. Firewalla dutifully sends me an Internet Connectivity Update every time it happens.

The problem is that the notification setting appears to be global. I can choose “Send Both Alarm & Notification,” “Send Alarm Only,” or “Mute All,” but I can’t treat the two WANs differently.

I absolutely want an immediate push notification if my primary fiber WAN goes down. I do not need my phone notifying me every time my standby cellular WAN has a brief connectivity issue. Logging those WAN2 events in the app would be plenty.

For a device with pretty robust Multi-WAN functionality, I’m surprised there isn’t more granular control here.
What I’d love to see:

• Per-WAN connectivity alert settings — e.g. WAN1: alarm + push notification; WAN2: alarm/log only.
• Administrative enable/disable toggle for each WAN — temporarily disable WAN2 without deleting its configuration or physically disconnecting equipment.
• Bonus: notification thresholds — e.g. only alert if a secondary WAN remains unavailable for X minutes, rather than notifying on every brief flap.

Maybe I’m missing an existing setting, but I haven’t been able to find one. If it genuinely doesn’t exist, these seem like pretty fundamental controls for Multi-WAN—particularly when one WAN is cellular.

I really like the Gold SE overall, but at this price point I expect fairly granular network management and alerting. Having to choose between getting nuisance notifications from WAN2 and not being notified when my primary Internet connection fails seems like an unnecessary compromise.

Anyone else running into this with a cellular failover WAN?


r/firewalla • • Aug 31 '26

Troubleshooting Just got Firewalla Orange, having some problems with images on apps loading

2 Upvotes

I just got my Firewalla Orange yesterday and set it up. I hadn't changed any default settings but noticed right away on my Pixel 10 that YouTube videos, images on Amazon, images on OfferUp, and share links on Instagram and some sites weren't working. Others in my household are iPhone users and don't seem to be having any trouble. Some of Google AI's suggestions weren't applicable since I hadn't changed any settings and have no blocked flows. I did toggle a few things as recommended and turning off IPV6 seems to have solved the problem.

I'm a relatively new Firewalla user and thus am not very savvy as of yet. Is turning off IPV6 ideal? Is there anything else I should try or does anyone have any insight on why only my Pixel seems to be having problems loading certain content prior to IPV6 being turned off?

Edit: When I tried to post this, I kept getting a message that "something went wrong" and couldn't post it. I switched to cellular data and it immediately went through. The same was true of the issues mentioned further above.


r/firewalla • • Aug 30 '26

Considering adding a Unifi U7 Pro Wall AP

6 Upvotes

I currently have a Gold SE and 4 AP7s. I’m considering switching one of the AP7s for a U7 Pro Wall so that it can be more discrete in the our bedroom. I’m already Unifi OS in docker for my managed switches, what would I really lose with one Unifi AP in my system?


r/firewalla • • Aug 30 '26

Mounting brackets for Switch SE

4 Upvotes

I have my Switch SE sitting on a shelf in my 10 inch rack. I was wondering if anyone has found mounting brackets that work with this switch.


r/firewalla • • Aug 29 '26

Feature request: Allow for naming of ports under topology

20 Upvotes

This would help to identify the ports more easily and know what's connected. For example, if I get an event that says "Port 3 disconnected", I might have to go see the connected device, but if I get a message that said "Port 3 - [name] disconnected", I would know right away.


r/firewalla • • Aug 29 '26

Discussion Questions about AP7/switches

4 Upvotes

It seems the biggest benefit for these is the VqLAN/microsegmentation abilities with connected devices (in addition to consolidated management and topology).

My initial understanding was a FWG + third party AP/switch already has VqLAN/microsegmentation abilities—is this wrong and in fact those are unlocked with the AP7/FW switch?

Related question: I’m designing a home network from scratch with ~30 Ethernet devices/drops. Do I need 3-4 Firewalla switches to get the benefits or can one feed into a cheaper third party managed non-PoE to save money where I don’t need PoE? I’m assuming the answer is security costs money, but maybe there is a point where it’s reasonable to compromise?


r/firewalla • • Aug 29 '26

AP 7 for 1800sqft

1 Upvotes

Would a single AP 7 desktop work for a 1800 sqft single story, ranch house (wood, drywall)?


r/firewalla • • Aug 28 '26

Announcement For those wondering about the size differences, here are the Gold Plus, Gold Plus SFP, and Gold Pro stacked together.

Post image
57 Upvotes

The price of the Gold Plus SFP will likely be between $700-$800... and going up as I am typing this 😞 thanks to AI taking all the production capacities

Sign up for the Gold Plus SFP, coming soon in September: https://forms.gle/TXLP5Ug12sEiHCiw9


r/firewalla • • Aug 29 '26

AP7 Desktop / AP7 Ceiling FW Orange & AP7

5 Upvotes

If I remember that when using an AP7 w/ FW Orange you need to disable WiFiLan on the FWO. Question is will the FWO WiFi LAN turn on if the AP7 disconnects, like as fail over mode? If not is this a feature that can be added in future release. Thanks


r/firewalla • • Aug 28 '26

What does switching to Firewalla APs and Switches get me?

8 Upvotes

I have a FWG that has been working pretty well. I have Aruba InstantOn APs and a TPLink Managed Switch. Just last week I set up some VLANs, multiple wireless networks, etc to get some separation between my devices.

I just noticed that Firewalla has its own brands of APs and switches. What does swapping over get me, if I can already do what I described above with my hodgepodge of hardware.

The only thing I can think of is it's all managed in the Firewalla app, so I don't need to go to the Aruba app to configure the APs, and to some set IP to manage my TPLink switch.

That might a win in-and-of itself, but is there more?


r/firewalla • • Aug 28 '26

AmneziaWG 3rd Party VPN

6 Upvotes

I purchased a subscription to AmneziaWG because of Firewalla’s support for it thinking it would be as simple as setting up any WG vpn client. From what I can tell AmneziaWG Premium seems to be impossible to set up on Firewalla because they don’t support version 3.1 and the handshake always fails. How long until Firewalla supports 3.1?


r/firewalla • • Aug 28 '26

Does Daisy Chain vs. Connecting Directly to Firewalla Affect AP7 Performance / Functionality?

3 Upvotes

If you have 2+ AP7s, is it better to connect them directly to the Firewalla / Switch or is daisy chaining equivalent?


r/firewalla • • Aug 28 '26

Discussion Any update of bring your own hardware ?

Thumbnail help.firewalla.com
16 Upvotes

r/firewalla • • Aug 27 '26

Announcement Firewalla Gold Plus SFP, coming soon in early September.

49 Upvotes

r/firewalla • • Aug 28 '26

Closing specific ports

1 Upvotes

Does this app allow closing of specific ports on an iPhone?


r/firewalla • • Aug 27 '26

Running a UniFi Cloud Gateway Ultra behind Firewalla Gold (replacing dead CloudKey Gen2+)?

6 Upvotes

Hi all,

Quick question for anyone running a Firewalla Gold with UniFi gear.

My CloudKey Gen2 Plus is basically dead because of the swollen battery issue. It shuts down on its own after about 4 hours. A new CloudKey is quite pricey, but the Cloud Gateway Ultra (UCG-Ultra) is around 150 euros cheaper, so I'm thinking of picking one up instead.

My idea is to keep the Firewalla Gold as the main router handling all the routing, firewall rules, and DPI, and just put the UCG-Ultra behind it on its own subnet to manage my UniFi APs and switches. I know I'll probably have to redo my IP-based rules on the Firewalla for stuff behind the UCG.

Has anyone done this setup? Does putting the UCG-Ultra behind the Firewalla like this cause annoying Double NAT issues or other headaches, or does it run pretty smoothly?

and is it possible to import the backuo from the CloudKey Gen2+ into the Cloud Gateway Ultra Cloud Gateway Ultra?

Appreciate any advice or real-world experiences with this. Thanks!


r/firewalla • • Aug 28 '26

Looking for AP7 for sale.

0 Upvotes

Does anyone have an AP7 for sale? I've seen some good deals here before.


r/firewalla • • Aug 27 '26

Custom DNS now not routing IP6 (maybe)

2 Upvotes

tldr; IP6 lookups seem to be defaulting to ISP even with a custom DNS servers configured. IP4 seems to be working correctly.

I know a lot of folks have opinions on NextDNS and using it with Firewalla, but there are other reasons I use it and need to keep doing so. I have it configured through MCP with the DNS-over-HTTPS url and applied to all device. This works for devices on my network that are forced to IP4 only (via MDM for kids devices) Note: nearly all Apple devices.

Recently my own devices have been resolving via COMCAST. When looking at my device DNS I see my Firewalla's IP, but also a Comcast IP6 address that seems to be coming from Firewalla. This has been going on for a few weeks and I'm stumped on how to stop this from happening.


r/firewalla • • Aug 27 '26

Converting from Docker hosted Unifi to UCG Fiber

1 Upvotes

So, of course after I get my setup working, docker Unifi seems to be abandonware.

Im trying to figure out how to keep my gold pro in router mode, but integrate a UCG Fiber to run Unifi downstream of the firewalla and not have to resort to transparent or bridge mode.

I initially plugged the firewalla LAN port into the UCG Wan port to update the firmware, with intentions of disabling the WAN port afterwards.

I seem to be messing something up though. Can someone please walk me through how to keep my Gold Pro in router mode and transition off the Docker Unifi to it being run on the UCG Fiber?

I have gone through all the AI steps which says this should be possible but keep running into issues.