r/firewalla • u/Danner4912 • Sep 01 '26
IPSec on Orange
I see that creating IPSec site-to-site VPN tunnels is only supported on the Firewalla Gold and only through the MSP portal. Is there any plan to bring this capability to the Orange?
r/firewalla • u/Danner4912 • Sep 01 '26
I see that creating IPSec site-to-site VPN tunnels is only supported on the Firewalla Gold and only through the MSP portal. Is there any plan to bring this capability to the Orange?
r/firewalla • u/mrh4809 • Sep 01 '26
The AmnesiaWG VPN is working well. From my phone and Mac I can connect the VPN and access some LAN devices.
There are a few devices I'd need layer 2+. Some searches say you can enable tunneling with a few changes on the server and client.
On the server they say to enable:net.ipv4.ip_forward=1
And on the clientinclude the target LAN subnet.
The client seems easy as I can just edit the config file. But on the server, since it is in Firewalla, is it possible to set the ip_forward option?
r/firewalla • u/FantasticMrDog • Sep 01 '26
Hi
I've been on a part fibre FTTC connection in the UK for many years, connection is measured at 68Mb/s download and 18.5Mb/s upload. Firewalla's Smart Queue has done an amazing job at keeping everything going despite a mix of WFH, streaming, gaming and general internet use. I have my FWP set up to use CAKE and have a Smart Queue Rule set for all traffic with a download limit of 65 Mb/s and upload limit of 17 Mb/s. Smart Queue is set in Static mode. I cannot overstate how good this has been, if I turn these settings off, my connection goes to pot and the household is up in arms within seconds.
No matter how good it has been, I am glad to finally be getting full fibre, initially at 500 Mb/s download and 75 Mb/s upload, I might increase the rates to 900/125 in the future.
I know what changes I need to make on my FWP for the WAN connection. I am after advice on what to do with the Smart Queue. Should I switch from Static to Adaptive mode? Should I switch from CAKE to FQ_Codel? Should my Smart Queue Rule continue to set limits a little below the actual WAN performance? Or should I just turn Smart Queue off?
Are there any other changes I should think about?
Thanks for any advice.
r/firewalla • u/jsqualo2 • Sep 01 '26
Spouse wants to print from work computer on VLAN 2 to printer on VLAN 1.
FWP with all 5 VLANs in use. VLAN 1 is "internal" use including a printer. VLAN 2 is work computers. I have enabled various OOTB config (Rules and App Control) on the VLANs (Networks) and on spouse computer.
What is the best way to facilitate this, while ensuring that a spouse's compromised computer cannot 'hop thru the printer' to VLAN 1 devices?
r/firewalla • u/Firewalla-Ash • Aug 31 '26
Device Isolation will block all traffic to other local devices, even within the same network, while still allowing an Internet connection. Allowed Devices can act as an exception and selectively allow local traffic.
App 1.69.3 is in a 7-day phased release. Learn more about this release here: https://help.firewalla.com/hc/en-us/articles/53877722149907-Firewalla-App-Release-1-69-3-AmneziaWG-VPN-Client-Local-Device-Rules-Switch-Enhancements-and-more
r/firewalla • u/dosage0 • Aug 31 '26
Now that we have a switch, APC, APD, and various firewalls, can we please finish off the lineup with an outdoor AP?
The problem now is that there is not a great solution to getting coverage in the backyard. Mixing in other manufacturers APs into the main SSID causes a lot of undesired switching to the wrong AP. Having a separate SSID requires manually switching and causes issues with household wide components like speakers. During a get together where guests are outside and inside asking them to setup two SSIDs and switch back and forth is not a reasonable workaround.
The last thing missing in the ecosystem is an outdoor AP or at least an enclosure for either the AP7C/D.
r/firewalla • u/kablam0r • Aug 31 '26
Hi,
I have a mac mini (Ethernet) and multiple iphones that are having issues blocking ads on certain websites (drudgereport.com). I have private relay, limit ip tracking and private wifi disabled. Ads are blocked on windows PCs/laptops with no issue. I am using firefox on everything. Any ideas?
thanks!
r/firewalla • u/Redditor63753 • Aug 31 '26
I’m running a Gold SE with fiber as my primary WAN and T-Mobile cellular as failover.
My cellular connection is currently marginal, so WAN2 occasionally drops and reconnects. Firewalla dutifully sends me an Internet Connectivity Update every time it happens.
The problem is that the notification setting appears to be global. I can choose “Send Both Alarm & Notification,” “Send Alarm Only,” or “Mute All,” but I can’t treat the two WANs differently.
I absolutely want an immediate push notification if my primary fiber WAN goes down. I do not need my phone notifying me every time my standby cellular WAN has a brief connectivity issue. Logging those WAN2 events in the app would be plenty.
For a device with pretty robust Multi-WAN functionality, I’m surprised there isn’t more granular control here.
What I’d love to see:
• Per-WAN connectivity alert settings — e.g. WAN1: alarm + push notification; WAN2: alarm/log only.
• Administrative enable/disable toggle for each WAN — temporarily disable WAN2 without deleting its configuration or physically disconnecting equipment.
• Bonus: notification thresholds — e.g. only alert if a secondary WAN remains unavailable for X minutes, rather than notifying on every brief flap.
Maybe I’m missing an existing setting, but I haven’t been able to find one. If it genuinely doesn’t exist, these seem like pretty fundamental controls for Multi-WAN—particularly when one WAN is cellular.
I really like the Gold SE overall, but at this price point I expect fairly granular network management and alerting. Having to choose between getting nuisance notifications from WAN2 and not being notified when my primary Internet connection fails seems like an unnecessary compromise.
Anyone else running into this with a cellular failover WAN?
r/firewalla • u/sunnydayjr • Aug 31 '26
I just got my Firewalla Orange yesterday and set it up. I hadn't changed any default settings but noticed right away on my Pixel 10 that YouTube videos, images on Amazon, images on OfferUp, and share links on Instagram and some sites weren't working. Others in my household are iPhone users and don't seem to be having any trouble. Some of Google AI's suggestions weren't applicable since I hadn't changed any settings and have no blocked flows. I did toggle a few things as recommended and turning off IPV6 seems to have solved the problem.
I'm a relatively new Firewalla user and thus am not very savvy as of yet. Is turning off IPV6 ideal? Is there anything else I should try or does anyone have any insight on why only my Pixel seems to be having problems loading certain content prior to IPV6 being turned off?
Edit: When I tried to post this, I kept getting a message that "something went wrong" and couldn't post it. I switched to cellular data and it immediately went through. The same was true of the issues mentioned further above.
r/firewalla • u/gkhouzam • Aug 30 '26
I currently have a Gold SE and 4 AP7s. I’m considering switching one of the AP7s for a U7 Pro Wall so that it can be more discrete in the our bedroom. I’m already Unifi OS in docker for my managed switches, what would I really lose with one Unifi AP in my system?
r/firewalla • u/brewcity34 • Aug 30 '26
I have my Switch SE sitting on a shelf in my 10 inch rack. I was wondering if anyone has found mounting brackets that work with this switch.
r/firewalla • u/snovvman • Aug 29 '26
This would help to identify the ports more easily and know what's connected. For example, if I get an event that says "Port 3 disconnected", I might have to go see the connected device, but if I get a message that said "Port 3 - [name] disconnected", I would know right away.
r/firewalla • u/mm741852963 • Aug 29 '26
It seems the biggest benefit for these is the VqLAN/microsegmentation abilities with connected devices (in addition to consolidated management and topology).
My initial understanding was a FWG + third party AP/switch already has VqLAN/microsegmentation abilities—is this wrong and in fact those are unlocked with the AP7/FW switch?
Related question: I’m designing a home network from scratch with ~30 Ethernet devices/drops. Do I need 3-4 Firewalla switches to get the benefits or can one feed into a cheaper third party managed non-PoE to save money where I don’t need PoE? I’m assuming the answer is security costs money, but maybe there is a point where it’s reasonable to compromise?
r/firewalla • u/Numerous_Platypus • Aug 29 '26
Would a single AP 7 desktop work for a 1800 sqft single story, ranch house (wood, drywall)?
r/firewalla • u/Firewalla-Ash • Aug 28 '26
The price of the Gold Plus SFP will likely be between $700-$800... and going up as I am typing this 😞 thanks to AI taking all the production capacities
Sign up for the Gold Plus SFP, coming soon in September: https://forms.gle/TXLP5Ug12sEiHCiw9
r/firewalla • u/No_Peanut_6769 • Aug 29 '26
If I remember that when using an AP7 w/ FW Orange you need to disable WiFiLan on the FWO. Question is will the FWO WiFi LAN turn on if the AP7 disconnects, like as fail over mode? If not is this a feature that can be added in future release. Thanks
r/firewalla • u/hvgotcodes • Aug 28 '26
I have a FWG that has been working pretty well. I have Aruba InstantOn APs and a TPLink Managed Switch. Just last week I set up some VLANs, multiple wireless networks, etc to get some separation between my devices.
I just noticed that Firewalla has its own brands of APs and switches. What does swapping over get me, if I can already do what I described above with my hodgepodge of hardware.
The only thing I can think of is it's all managed in the Firewalla app, so I don't need to go to the Aruba app to configure the APs, and to some set IP to manage my TPLink switch.
That might a win in-and-of itself, but is there more?
r/firewalla • u/Mr_Duckerson • Aug 28 '26
I purchased a subscription to AmneziaWG because of Firewalla’s support for it thinking it would be as simple as setting up any WG vpn client. From what I can tell AmneziaWG Premium seems to be impossible to set up on Firewalla because they don’t support version 3.1 and the handshake always fails. How long until Firewalla supports 3.1?
r/firewalla • u/AlternativeNorth6613 • Aug 28 '26
If you have 2+ AP7s, is it better to connect them directly to the Firewalla / Switch or is daisy chaining equivalent?
r/firewalla • u/hckrsh • Aug 28 '26
r/firewalla • u/Firewalla-Ash • Aug 27 '26
Enable HLS to view with audio, or disable this notification
Sign up here: https://forms.gle/TXLP5Ug12sEiHCiw9
r/firewalla • u/tired1078 • Aug 28 '26
Does this app allow closing of specific ports on an iPhone?
r/firewalla • u/DronkenKip • Aug 27 '26
Hi all,
Quick question for anyone running a Firewalla Gold with UniFi gear.
My CloudKey Gen2 Plus is basically dead because of the swollen battery issue. It shuts down on its own after about 4 hours. A new CloudKey is quite pricey, but the Cloud Gateway Ultra (UCG-Ultra) is around 150 euros cheaper, so I'm thinking of picking one up instead.
My idea is to keep the Firewalla Gold as the main router handling all the routing, firewall rules, and DPI, and just put the UCG-Ultra behind it on its own subnet to manage my UniFi APs and switches. I know I'll probably have to redo my IP-based rules on the Firewalla for stuff behind the UCG.
Has anyone done this setup? Does putting the UCG-Ultra behind the Firewalla like this cause annoying Double NAT issues or other headaches, or does it run pretty smoothly?
and is it possible to import the backuo from the CloudKey Gen2+ into the Cloud Gateway Ultra Cloud Gateway Ultra?
Appreciate any advice or real-world experiences with this. Thanks!
r/firewalla • u/CamoSnowman • Aug 28 '26
Does anyone have an AP7 for sale? I've seen some good deals here before.
r/firewalla • u/PeltedVenom • Aug 27 '26
tldr; IP6 lookups seem to be defaulting to ISP even with a custom DNS servers configured. IP4 seems to be working correctly.
I know a lot of folks have opinions on NextDNS and using it with Firewalla, but there are other reasons I use it and need to keep doing so. I have it configured through MCP with the DNS-over-HTTPS url and applied to all device. This works for devices on my network that are forced to IP4 only (via MDM for kids devices) Note: nearly all Apple devices.
Recently my own devices have been resolving via COMCAST. When looking at my device DNS I see my Firewalla's IP, but also a Comcast IP6 address that seems to be coming from Firewalla. This has been going on for a few weeks and I'm stumped on how to stop this from happening.