r/firewalla

How do you like our AI integrations so far?

How do you like our AI integrations so far?

AI can be a useful tool for analyzing things in different ways. It can see patterns more easily and look up various information much faster and more broadly than a human can... making it great for explaining domains, recognizing unknown devices, or checking Events.

Of course, we always recommend double-checking AI's work, since it can be wrong (just like a human).

More on Firewalla's AI Assistant: https://help.firewalla.com/hc/en-us/articles/40436794520595-Firewalla-AI-Assistant-Ask-AI-beta

u/Firewalla-Ash — 12 hours ago

Minor issues with passkey support in MSP 2.11.1

I added 2 yubi security keys to lock down my MSP and it seems to not want to kick in and use that, I even turned mfa off and it will only use the password and it’ll log in. Maybe just give it a bit longer I’m not sure

It calls the yubi keys roaming passkeys

reddit.com
u/No-Firefighter-2135 — 1 day ago

Update on the Firewalla Gold Plus SFP

We have had this unit ready since February of this year. Due to rising memory prices and uncertainty about whether to use DDR5, it was paused over and over again. And now, we're starting to see eMMC price increases and PCB shortages. (There is likely no end to these increases and shortages.)

So, we are just going to start manufacturing this, likely in small quantities. Hopefully, we don't have to wait a few months to ensure all the parts are there.

Unlike previous units, we've decided to sell this unit as it arrives. (We will still call the first batch "beta" and offer a better price discount.) There will not be a pre-order, since we can't guarantee delivery time.

Link to survey: https://forms.gle/W7GbirY7UFDmR1Js6 (By answering this survey, we'll send you a small coupon before the launch)

We are targeting early September 2026 for the first batch sale.

u/Firewalla-Ash — 1 day ago

My Vizio TV is going nuts LOL

Damn Vizio do you really need to keep doing this at a rate of 100k connections per hour? lol

u/CricketGreenz — 1 day ago

Anyone having trouble with Amnezia 2.0?

Just upgraded to Amnezia 2.0 on Firewalla and issued new certs to the 2.0 clients but can’t get any of them to connect, anyone else having this issue?

reddit.com
u/Numerous-Impact4901 — 1 day ago
▲ 30 r/firewalla+1 crossposts

Memory-Safe Secure Time: Setting up ntpd-rs + NTS on Firewalla

After successfully scripting `Chrony` on my Firewalla to fetch time via NTS and serve it to the LAN via NTP interception, I decided to see if I could replicate the setup using ntpd-rs. Turns out, it works perfectly.

While `Chrony` is Ubuntu's current default for NTS support (preventing MITM and spoofing attacks), Canonical is moving away from C-based utilities toward Rust. They will likely switch to ntpd-rs soon, potentially as early as 26.10 but definitely by 27.04, mirroring their recent shifts with tools like sudo-rs.

I’ve been running ntpd-rs on my Firewalla Gold Plus for a few days now, and it has been rock solid.

If you want to check them out, I’ve published updated scripts for both setups:

I would love it if, in the future, Firewalla used `Chrony` or `ntpd-rs` as the default timekeeper for Firewalla. Since Firewalla is security minded, the ability to use NTS as the canonical timekeeper serving secure time to the LAN network via NTP Intercept would be unique in this space (afaik competitors don't offer this) and trivial to set up, as I've shown. If they choose `ntpd-rs`, then there's even more memory-safe security with rust vs C.

Also, a quick plug for my other Firewalla-related GitHub scripts:

  • Install Huge Blocklists: Allows MSP Lite users to install and update massive (or any non-MSP/app available...) custom lists (like HaGeZi Pro++ or OISD Big) via the CLI. Tradeoff: Blocked events won't show up in the MSP or app GUI but can be viewed via CLI.
  • Unbound DoT Config + Tweaks: Sets up DNS-over-TLS (DoT) for IPv4 +/- IPv6 with a fallback to standard plaintext resolving, plus optimizes buffer settings to boost your DNS speed and also includes a few security tweaks.
  • Set up a Suricata Test Box: Thinking about upgrading to a Firewalla Pro for Suricata? This lets you test drive Suricata first to see how it works and if the upgrade is worth it for you.
u/Great-Cow7256 — 2 days ago

Policy Based Routing needed?

I have two broadband internet providers… VZ and TMO.

I got the TMO G5AR earlier this year, because  VZ has really started throttling.

I have connected the WAN port on the Purple to the G5AR via ethernet.

I have setup Multi WAN on the Purple by using WiFi on the Purple to the VZ box WiFi. It is set to Failover.

I ran network diagnostics on the Purple, both WANs report no errors.

For some reason, from the LAN side, DNS isn’t resolving URLs at all with the TMO as Primary. With VZ as primary DNS resolves correctly. I can access the internet with no problem from my notebook via WiFi on TMO.

Am I missing some required setup to handle the G5AR?

It is my understanding that Policy Based Routing might be able to work around the issue.

I assume you could route LAN port 53 calls to VZ, bypassing the issues with TMO.

Failover working would be great, but balanced would be even better.
How do I do that?

Thanks

Dennis

reddit.com
u/DWomack48 — 2 days ago

Tailscale exit node

For those of you who run tailscale as an exit node on your firewalla, are you able to see flows in the app? Or does it become sort of a ghost node with no visibility in firewalla?

reddit.com
u/AltruisticNetwork869 — 2 days ago

How to allow Bark App VPN?

How do I block VPNs for devices in the network, but still allow Bark App to work? Is there a way to allow ONLY the Bark VPN on my network?

reddit.com
u/fishbait-tailgate — 2 days ago

Switch SE and X Feature Request

As I moved some things around on my rack today it got me thinking about my future Switch SE.

Could I put in a feature request for individual port on/off schedules?

I run lots of POE devices and think it would be nice to say turn off POE APs at night. Or Poe Cameras during the day in select locations.

Thanks in advance!! As always huge long time fan and user of firewalla!

reddit.com
u/11jwolfe2 — 3 days ago

migrate from another box question...

I have a firewalla Gold (original) and will be upgrading it to a Gold Plus. I found some pretty strait forward instructions, but my question is about what does/or does not transfer in the migration?

On my existing Gold, I have a point-to-point VPN setup with another location running a Purple. The gold is the VPN server and it also serves several VPN clients (laptops and phones).

When I migrate to the gold plus, will it carry over the VPN related config (DDNS? etc) or will I have to recreate the VPN config from scratch? Likewise, the devices (laptops and phones) which use a wireguard client to connect to the existing Gold VPN server, will they all need to be reconfigured?

Thanks in advance.

reddit.com
u/CorsairVelo — 4 days ago

Your Firewalla is a sophisticated security device, with many things happening inside. We are thinking about exposing these 'Events' in the app. What do you think? Which version do you prefer?

Our designers have two ideas:

  • V1: Merge all Events into one place
  • V2: Keep existing Network Health Events separate
u/Firewalla-Ash — 6 days ago

Weekday and weekend block for kids

Right now I have a block rule for 1030pm to 7am...everyday.

But on the weekend I want to go from 1130pm to 7am for Friday and Saturday.

Any ideas?

I w

reddit.com
u/Thinkb4Jump — 4 days ago

If my printer's on one wireless network, can I access it from another?

Just updated my main home wifi network to WPA3 (personal), from WPA2/WPA3 combo.

But now my Brother laser printer (HL-2275DW) cannot connect to this. (It claims it can use WPA2-personal TKIP/AES). The printer includes a USB port, but not ethernet.

I have a separate IoT network that includes WPA2, so I could connect the printer to this.

I have a Firewalla Purple, using a tp-link Archer AX3000 in access point mode running both wifi networks (plus a third guest network). The tp-link has a usb port but it's only for storage/disk access, not hosting printers.

Question: if I connect the printer to the IoT network to meet the printer's lower security demands, can computers/phones connected to the main WPA3-secured network also see it and print to it? Obviously everything going through the router shows up on my Firewalla, but can I print from one wireless network to another?

...and if not, any suggestions for a solution here?

thanks so much!

reddit.com
u/maybefromthefuture — 5 days ago

Is there any way to sort the VPN Client list?

I’m referring to the top level VPN Client screen and not a VPN Group. I have a growing list and it would be nice to be able to sort by name. I don’t think this is possible but wanted to see if I’m overlooking anything. Thanks.

reddit.com
u/pacoii — 4 days ago

DNS booster - dns issues

2 adguard servers.
primary / secondary

with dns booster turned on for my devices, once I shutdown my primary dns server, all other dns servers stop working. (whether that is my secondary, or if I use 1.1.1.1 / 8.8.8.8 / whatever)

it seems to be related to dnsmasq im pretty sure.

(dig @<ip> version.bind CHAOS TXT returns a dnsmasq_UNKNOWN answer)

anyone got any ideas what I might have configured that would be causing this?

u/Nexus_Explorer — 4 days ago

How is DAP eligibility determined?

I have 3 smoke detectors, they are all the same model. One of them is DAP eligible and in the learning phase. The other two are marked as ineligible for some reason. I have checked and they all connect to the same domains. Why would one be eligible and the rest not?

Would it be possible to make it so we can manually turn on DAP for the devices we want? At least for the learning phase since it doesn't block anything. Then if it turns out it needs more access than is feasible for DAP to manage it can be prevented from moving into optimizing/active phase.

reddit.com
u/MemoryDemise — 5 days ago

Upload speed slow on multiple device

Has there been any changes lately because my upload speed on some devices (wired and wireless) are down to just 1-2 Mbps.
When testing on phone, I get really good upload speed.
I've tried to restart both the Firewalla and ATT modem.

All speed tests are to the same Comcast Server nearby, and all devices are connected to the same network.

https://preview.redd.it/l9bwsj4p4djh1.png?width=1320&format=png&auto=webp&s=25c0cf27ec92e47a57e051c2e4e2c5cf4c603dc5

https://preview.redd.it/yai6rq214djh1.png?width=439&format=png&auto=webp&s=6c5d2141103604d1f68ddc6c9acf99bc35849683

https://preview.redd.it/vtxt2zne4djh1.png?width=346&format=png&auto=webp&s=fbfdc1e6c4b30cc1c4e561413542309ca0db65e1

https://preview.redd.it/yp2dx0ki4djh1.png?width=1320&format=png&auto=webp&s=ad879a21322eeb32fe8d9bfee386259ac94188ec

reddit.com
u/scvready0808 — 6 days ago

Triple WAN failover

I’ve seen this suggestion brought up here on Reddit and on firewall a forums. Was curious, is it really that hard now, especially with AI coding, to add a third wan failover? I have FWG+ and have spent the week scoping out a possible jump to Unifi ecosystem so I can get triple wan failover. The dual wan failover already exists so the logic and routing gates are already there in terms of scaffolding. Wanted to check one more time if this is going to be implemented or if it is 100% abandoned as a feature on a future update before I actually make the leap. Love firewall and this feature is the only one that would make me switch. I have fiber, Xfinity and Starlink. I know I’m not alone as there have been others asking for it. I do realize we are edge cases and probably under 1% of the user base. I also think the complexity of implementing a third WAN failover is not a big undertaking or if it was Open source I can have it added.

reddit.com
u/marcvv — 5 days ago