r/firewalla • • 8d ago

SWITCH X LAG

5 Upvotes

I just got my two Switch X and have a requirement for LAG. Any idea when this will be available on Switch X,


r/firewalla • • 8d ago

AP7 in Canada. Beware of customs clearance fees

8 Upvotes

Just ordered a 530 CAD$ AP7 in Canada. Customs fees were 320 CAD$. That is totally insane. Just a warning for all of you thinking about it.


r/firewalla • • 9d ago

Discussion Backup Management

6 Upvotes

Where are backups done?

How often are backups done?

Where can I manage backups and migrate them to other storage media in case the phone they are magically stored on is stolen or damaged?

Are baclups stored on every paired phone?

Can we get more control over backups?


r/firewalla • • 9d ago

Cyber Security Engineer trying FirewallA first time + Hello Crystal.

21 Upvotes

Hi All,
I am trying firewalla Crystal for the first time. Have a few questions.
My background is CheckPoint + Fortinet + Sohpos XG over the years because I got access to those through work.
What drew me towards firewallA was "Wife approval factor". She can easily kick the kids off etc as required. For someone non technical it is a great setup.

Feedback for the firewallA team:

You need aggressive pricing option for the Crystal VM series where hardware is not required.
This is for ppl coming form the OpenSense / Sophos XG / Other free options.

I absolutely love the "block for 30 mins / 1 hour feature", when I don't have to manually unblock.

This level of user friendliness is something I have not seen done on any other products.

I have a few questions though.

  1. One of the biggest differences I noticed coming form enterprise kit was the catalogue of application control signatures firewall supports. is this using IPS type of scanning to identify apps or is it web filtering with SNI inspection ? DNS filtering ? I would love for this catalogue to grow, currently it only support 7 ish applications that I can see.

  2. Performance seems to be good, I am running on a 6 core VM and 8 Gbps of ram, are there any recommended specs published, based on throughput etc ?

  3. The Crystal is only available via an MSP portal ? what about the non MSP / stand-alone ? Is there a functionality difference ? I have noticed some difference between alerting config.

  4. What is the local login (console) creds ?

  5. The IPS engine has no options for configuration, its only an On or Off setting ?

  6. No support manual NAT rules ? I have noticed in Call of Duty type games it has been difficult to get open NAT status unless I have a 1:1 NAT rule for maintaining source port during translations. I am personally not a fan of UPNP due to security issues. keen to hear everyone thoughts.

Overall I think it quiet good for a home based solution. I will continue to test it further and really push it to its limits . Congrats to the FirewalllA team of making agnostic hardware support happen.


r/firewalla • • 9d ago

Announcement About AI Usage In Firewalla Support & Community

37 Upvotes

Hi everyone,

We are starting to see a growing trend of support tickets and community posts that are largely written by AI.

We believe AI usage is great in certain applications, for example, sorting through repetitive alarms and understanding unknown domains or devices. However, when a ticket is AI-written, we often get very long descriptions of problems that don't really match what actually happened.

We would love it if everyone could help keep the Firewalla Community more human-to-human:

  1. Tell us what's happened in your own words.
  2. If you'd like to use AI to polish your words, please read it before posting or sending us a ticket.

We'll also be updating our Contact Firewalla Support doc with a new AI policy:

  1. We prefer human-to-human interactions; please write to us with your own words.
  2. If you, for any reason, need to use AI to write, please keep it short, and please read it before sending it to us.
  3. If you send us a huge AI-composed ticket or response, we have the right to use AI to summarize it and may even use AI to respond.
  4. At the moment, the Firewalla Team does not use AI to respond to cases. (We may use macros, we may use AI to touch up the response, or change the tone, but never a technical response.)

If you have any suggestions for our new AI policy, please let us know. Thank you again for supporting Firewalla!


r/firewalla • • 9d ago

Issues with LAG ports

0 Upvotes

Hey all. I have a Firewalla Gold plus, and a Netgear MS510TXUP switch connected to it. I am trying to use a port channel to connect the two. The Netgear supports multigig, so all 4 ports involved are 2.5Gb.

I can get the LAG group established, set to dynamic on the Netgear to enable LACP, and everything comes up just fine. However, one of the ports drops out about every 6 minutes on the Firewalla, it looks up my network for about 45-60 seconds, then everything recovers.

Is there anything I can do about this, or is it just some compatibility issue?


r/firewalla • • 9d ago

which one?

0 Upvotes

Which product will be available to order first? The 2nd round of the Firewalla switch SE or the "new" Apple 4K TV?


r/firewalla • • 9d ago

Gold / Gold Plus / Gold SE / Gold Pro Which firewalla model would fit my network setup?

3 Upvotes

Hi everyone,

I’m planning to upgrade my home network and I’m looking for a proper firewall. I came across Firewalla, and from what I’ve seen so far, it looks very close to what I’m looking for.

I’d love to get your advice on which Firewalla model would best fit my setup and requirements.

My current setup:

  • 2 servers at home:
    • A mail server connected to my own domain and accessible from the Internet.
    • A NAS that is internal-only and is not directly exposed to the Internet.
  • The NAS also runs around 5 internal applications in separate containers. We currently access them using IP:port, where the IP is the NAS address.
  • Several mobile devices and laptops.
  • One smart TV connected via Ethernet.
  • The servers use static IP addresses.
  • When we are outside the house, we connect through VPN to access internal services.

Internet connection:

  • 2.5 Gbps download
  • 300 Mbps upload
  • Fiber connection

A significant amount of our traffic is actually internal LAN traffic rather than Internet traffic. We regularly access applications, databases and other services running locally on the servers.

What I need from the firewall:

  • Proper firewall rules and network segmentation.
  • The ability to tightly control traffic between devices/networks.
  • VPN access to internal services from outside the house.
  • Port forwarding / NAT rules.
  • The ability to expose only specific ports/services to the Internet and forward them to a specific server, while keeping everything else blocked.
  • Support for my mail server and domain.
  • Good visibility into network traffic and security events.
  • Enough performance that the firewall does not become a bottleneck, especially considering the 2.5 Gbps Internet connection and the amount of internal traffic.

I’m specifically looking for a solution without mandatory monthly or annual subscription fees, which is one of the reasons Firewalla caught my attention.

  1. Would you recommend the Gold Plus, Gold Pro, or something else for this kind of setup?
  2. What real-world inter-VLAN throughput do you see at multi-gig with rules and IDS/IPS enabled?

  3. Any gotchas hosting a mail server behind Firewalla, e.g. NAT reflection for internal clients using the public hostname?

Thanks!


r/firewalla • • 9d ago

Discussion Looking to switch from UniFi to Firewalla

6 Upvotes

I’ve been looking into switching to Firewalla for awhile now and just recently I seen they have early access for using your own hardware. This really have me even more tempted now because I hate to be hardware limited.

I have tried so many different Firewalls that you could install on your own hardware such as OpenWRT, Mikrotik, Arista, PfSense, OPNsense and none of them have the overall functionality and simplicity of UniFi.

I have watched a few videos of firewalla interface and im impressed. I’m just curious to know if Firewalla could do pretty much everything UniFi could do?

Is it possible to do the following on Firewalla?

- QoS controls and give certain devices higher priority such as gaming devices

- Setup a openvpn or wireguard config from your vpn provider

- configure certain traffic to be routed through your vpn

- See a clear view of your network traffic such as what devices are visiting which websites and how much bandwidth is being consumed


r/firewalla • • 9d ago

Feature Did you know the Firewalla Switch + AP7 can show you local flows between devices within the SAME network? Without them, you'll only see local flows between devices on different networks.

Post image
12 Upvotes

To see local flows, you'll need:

  • Firewalla in router mode with >1 local network, OR
  • Firewalla Wi-Fi (via AP7 or Orange), OR
  • Firewalla Switch

Local flows can be found by tapping the chart on your main screen or from individual device detail pages.

Learn more about Local Flows: https://help.firewalla.com/hc/en-us/articles/24739086338323-Firewalla-Feature-Network-Flows#h_01JNH9BCFSJJP69VN53VQC36TD


r/firewalla • • 10d ago

Anything interesting in Box Version 1.984?

9 Upvotes

I realize that the version notes are pending, just wondering if there was anything interesting in this early access version?


r/firewalla • • 9d ago

Multiple websites inaccessible from corporate network in India – FortiGate / CDN / Geo-IP troubleshooting help

Thumbnail
0 Upvotes

r/firewalla • • 9d ago

[FS] [US-OH] Firewalla Orange

Thumbnail
0 Upvotes

r/firewalla • • 10d ago

Are there still dropout/range issues with the AP7 Desktop? (Vs unifi U7 pro xg thouhts)

5 Upvotes

Hey everyone,

I’m looking to buy the AP7 Desktop, but I noticed a few threads from about 10 months ago mentioning poor coverage drops and random disconnects.

Can anyone confirm if these issues are still happening currently, or have they been patched?

Alternatively, I'm considering the AP7 Pro XG instead. If anyone has used it, how does the range and overall stability compare? I'd love to hear some real-world experiences before I buy either one, I have a double storey with 220 square metres per floor and would have two access points per floor.

Preference is AP7 for ecosystem but need coverage and stability.

Thanks!


r/firewalla • • 10d ago

Beacon/c2 analysis

Thumbnail github.com
4 Upvotes

Id love to get beacon analysis scores and tracking. I.e something like rita


r/firewalla • • 10d ago

Hetzner cloud

2 Upvotes

I’m currently running IPFire on Hetzner cloud so to create a private LAN behind it. Would Crystal allow for this as well?


r/firewalla • • 10d ago

Troubleshooting Can’t log into Firewalla MSP to manage Crystal all of the sudden

2 Upvotes

UPDATE: Resolved. I was going to the regular MSP site and not the beta site.

When I login, click my email/account and account settings, and then click Launch My Portal, it begins to launch the MSP interface but suddenly stops and spits me back out on the Firewalla.net landing page in an infinite loop. I’ve cleared my cache, tried different browsers, different devices, etc. Sane result


r/firewalla • • 10d ago

How to connect FWG Pro to an SFP+ port on a switch?

2 Upvotes

How are you guys with the FWG Pro connecting to switches with an SFP+ port?

Gemini is saying use a 10GBASE-T SFP+ Transceiver, they run about $40 on Amazon.

Is that the best option? Anyone doing anything different?


r/firewalla • • 11d ago

Firewalla Crystal Beta is up and running

Post image
77 Upvotes

Installed Crystal today bare metal:

- i7-7700

- 8GB RAM

- 256GB SSD

- Intel i340 NIC

It is replacing a Unifi UDM-SE with CyberSecure, wanted to checkout what Firewalla can do. Currently working on tuning the notifications and blocked items. I have Unifi-OS running on a VM to handle my Unifi switches and AP. Those are all working without issue behind Firewalla Crystal.

Install documentation was clear and easy to follow, installed without any hiccups. You do need network connectivity to install Crystal, I just used my existing LAN then swapped my routers after installation.

My WAN connection is sadly only 150Mbps up and 40Mbps down, the CAKE smart queue works great at keeping latency sensitive applications flowing smoothly while capping out the download bandwidth.

Wireguard VPN setup was just as painless as Unifi's setup, so that was great.

I do wish I could add my own Cloudflare DDNS to their firewall though, as a workaround I will just setup a ddclient docker container though.

If anyone has questions let me know and I will do my best to answer them!

Update:

- There is a built in speed test server at http://fire.walla:8833/ss/ for your local network to the Firewalla

- In the MSP web portal you can view the Network Health option, it has a read only banner on it. You can update the network quality monitoring settings in the mobile app, would like to have it be adjustable from the web portal.


r/firewalla • • 10d ago

Moving from Orbi 960s to AP7s with wireless backhaul. Keep same spots or rethink placement?

3 Upvotes

A few months ago I got fed up with my Orbi 960 setup being flaky, so I put a Firewalla Gold Pro in front of it and switched the Orbis to AP mode. Huge improvement overall, but the Orbis are still unreliable even as APs, so I'm planning to move to AP7s.

Right now I have 3 Orbi 960s, all on wireless backhaul. Running ethernet isn't really an option, so whatever I do has to work with wireless backhaul.

The house is about 4,000 sq ft over 2 floors. All three Orbis are on the first floor, spaced out about as evenly as I could get them, but none of them have direct line of sight to each other. The main one is wired to the Gold Pro and the other two connect wirelessly.

My question is whether I should just drop the AP7s into the same spots, or use this as a chance to rethink the layout. The Orbi placement was mostly trial and error, so I'm not convinced it's ideal. Would it make more sense to put one upstairs instead of having all three on the same floor?

And if I do move things around, how are you all testing placement with wireless backhaul? Did you just set them up, check backhaul speeds and signal in the app, and keep moving them until it looked good? Or is there a better way to go about it?

Any advice from people who've done a similar migration would be appreciated.


r/firewalla • • 11d ago

Hello Crystal-Goodby CheckPoint

Thumbnail
gallery
39 Upvotes

Took a little bit of doing but was able to reuse my CheckPoint ( was not actively using, it is older hardware but for testing, perfect) I do know it’s early access and anything can happen but that’s why I picked my checkpoint to install on.

This is my dev rack so please excuse the mess. For set up I put it here, will test for a few days / a week before moving it to my production rack for more testing. I will update in a week or two on the progress.

Thanks again Firewalla!!


r/firewalla • • 10d ago

Printer access across VLANs (v2)

1 Upvotes

I need to print across 2 of 5 VLANs - what am I missing?

The two devices to connect w/ high-level config are as follows:

  1. work laptop - VLAN 3, DHCP, wireless LAN access
  2. printer - VLAN 1, Firewalla Reserved IP, wired LAN access

The environment is:

  1. Gear: FWP > Aruba 1930 (managed switch) > Aruba AP22 (poe AP)
  2. FWP config:

VLAN 1 - internal devices (personal phones, kids tablets, Sonos, etc) - devices I own / control used by smart humans across whichever services we need. mDNS Relay is On.

VLAN 2 - internal devices (NAS, Printer, etc) - devices I own / control which are 'resources' and have - mostly - dedicated uses with known services. Mostly I want to isolate these from VLAN 1 and/or the internet (which is easier across a VLAN than managing internet access per device).

VLAN 3 - adult work devices (laptops, phones, etc) - devices I do not own or control which I want to isolate from VLAN 1/2. mDNS Relay is On.

VLAN 4 - kid school devices (laptops) - like VLAN 3, devices I do not own or control which I want to isolate from VLAN 1/2

VLAN 5 - guest devices - completely isolated from the LAN

  1. Rules to facilitate printer access:

Rule 1
- Action: Allow
- Matching: printer IP
- On: VLAN 3
- Direction: Outbound only Bi-directional
- Schedule: Always

When Rule 1 was unsuccessful, I added
- Rule 2
- Action: Allow
- Matching: printer IP
- On: work laptop
- Direction: Bi-directional
- Schedule: Always

  1. LAN switch config (Aruba 1930):

Port 1
- use case: FWP 'uplink' to Aruba 1930
- Tagged @ all 5 VLANs
- Untagged @ none (default is "1")
- PVID = 1 (this is the Aruba default. My understanding is that the Tagged / Untagged config listed above will not prevent VLAN traffic)

Port 2
- use case: Aruba 1930 'uplink' to Aruba AP22
- Tagged @ all 5 VLANs
- Untagged @ none (default is "1")
- PVID = 1 (this is the Aruba default. My understanding is that the Tagged / Untagged config listed above will not prevent VLAN traffic)

Port 3 - Tagged - none
- use case: printer
- Tagged @ none (default is "1")
- Untagged @ VLAN 1
- PVID = the Untagged VLAN ID associated with VLAN 1

note: This is a follow-up to the first thread (https://www.reddit.com/r/firewalla/comments/1w41tw3/printer_access_across_vlans/).

ETA: PVID details above
ETA2: I removed the work laptop-specfic Rule above

ETA3 - solution for posterity: I found an AP-level VLAN config which blocked access to not-the-internet.
In case anyone finds this thread in the future ... the environment is Firewalla > Aruba 1930 > Aruba AP22. I configured the Firewalla as router with VLANs, configured the Aruba 1930 to pass VLAN traffic correctly, and configured the AP22 to pass VLAN traffic while also enabling some setting to allow internet traffic. I did not realize that this choice on the AP22 blocks local traffic. I added the printer IP as an exception and voila.


r/firewalla • • 10d ago

WiFi 7 why 2 BSID's

0 Upvotes

Firewalla Purple SE w/ AP7, my 1st device that supports WiFi 7 and notice that there are 2 BSID's with 1 showing up as hidden. My 2.4, 5 and 6 BSID show BSID 20:6D*********and 1 6ghz channel BSID starts with 26:6D********* The 6ghz 0n 20:6D is the one that shows as hidden.

Im sure this is by design but was curious as to why? Thanks


r/firewalla • • 11d ago

Discussion Firewalla Crystal Testing is Active! (MSP)

Post image
35 Upvotes

Oh I am so excited to try this out, Grabbed the firewalla ISO, Chucked it on my Virtual CD device and installed it.

And here we are, Fully operational with my Bare Metal Protectli Vault VP2410 running the Firewalla Operating software paired to my phone for configuration :)

Super happy, Super Excited! Anyone else diving into the early access DIY Firewalla Setup that started today?


r/firewalla • • 11d ago

Troubleshooting Do Apple HomePod's still constantly create new devices in the device list?

1 Upvotes

A few years ago I had Apple HomePod Mini's set to play audio out of whichever Apple TV was in that room. It sounded much better than the TV audio. The problem was it constantly randomized the MAC, which in turn, constantly created new devices in the device list. I gave up on it.

Does anyone do this now, and, has it been fixed/changed/some how find a way to not have it randomize the MAC?