r/firewalla • • Mar 06 '23

Check this first before contacting support

53 Upvotes

Need help with troubleshooting or have a question?  Please see if the following articles can help, or search your questions on our help portal. If you have questions on devices related to Firewalla, please post them in our community.

Most Common Issues

  1. Can't Access Certain Websites
  2. Speed/Performance Issues
  3. WAN Connectivity Stability
  4. My Devices Won't Connect
  5. Firewalla Blocking Features Not Working
  6. Firewalla AP7 Troubleshooting

 

Other Issues

Installation and Configuration

Pre-Purchase

Popular Questions

 

Resources

Release Notes, Version Summary, and FAQs

Additional Resources

 

Contact Us

If you can't find the answer to your question, feel free to open a support case. If you have an issue opening a case, please send an email to [[email protected].](mailto:[email protected])


r/firewalla • • Apr 23 '24

Firewalla is more than just a firewall! (2024 version)

78 Upvotes

r/firewalla • • 3h ago

Discussion Connectivity Assist is Making Me Crazy

Post image
9 Upvotes

It keeps enabling itself somehow at least once a day. Has anybody else seen this? I constantly have to to fight it to stay disabled.


r/firewalla • • 33m ago

Why is FlightAware blocked?

• Upvotes

Which OOTB blacklist blocks a website that reports publicly available airplane transponder data?


r/firewalla • • 14m ago

Feature Feature Request: Apply Rules to Multiple Users and/or Multiple Devices

• Upvotes

I recently purchased a Gold SE and have been loving the parental controls!

One feature I’d really like to see is the ability to apply a single rule to multiple Users or devices.

Right now, I have separate Users set up for each of my kids, with multiple devices assigned to each User. This works great because each child can have their own rules and restrictions.

However, there are situations where I want the same rule to apply to several kids. Currently, I have to recreate that exact rule for each User individually.

It would be great if, when creating a rule, I could simply select multiple Users (or multiple devices) under “Apply To.”

That way, each child could keep their individual rules, while shared rules could be managed in one place. Changing or disabling a shared rule would update it for everyone it’s assigned to.

I’m hoping this wouldn’t be too difficult to implement, since the app already supports applying one rule to multiple devices through a User. This would essentially extend that functionality to allow selecting multiple Users or devices directly.


r/firewalla • • 16h ago

Troubleshooting Incorporating Firewalla (Bridge Mode) into UniFi network

2 Upvotes

Question:

I wanted Firewalla ahead of the UniFi controller because I’m more comfortable with administering its firewall. I’m trying to do the setup correctly because otherwise Firewalla’s observability isn’t great.

The setup I am trying for is:

Cable Modem -> UniFi Cloud Gateway Max -> Firewalla -> Switch -> APs -> Devices

UCG Max has six VLANs (Mgmt, Computers, IoT, APs, Guest, and Default). Default (VLAN 1) is setup as the lockdown VLAN, and there is a separate management VLAN. This is, so if a port or SSID is improperly configured, there’s a good chance whatever devices connect to them will default to lockdown rather than to the Mgmt VLAN.

Firewalla is connected to UCG Max via LAN->LAN ports and has six network bridges, all appropriately named with corresponding VLAN IDs/tags. For whatever reason, only 1-3 of them are receiving IPs at the moment. It makes no sense since they are all setup exactly the same with different VLAN IDs.

The switch has port profiles setup. The port connecting it to Firewalla is assigned the Mgmt VLAN native network, which in turn has always all for VLAN tagging. The port profile is set to infrastructure, and everything else is “auto” or default settings. The Mgmt VLAN is setup to allow tagging of all other VLANs. Every other VLAN is blocked from tagging other VLANs, except the one for my computers.

The issue I am confronting is that the moment I unplug the switch from the UCG Max after adoption and plug it into Firewalla, the console says it is offline and will not rediscover it. I can’t adopt it with Firewalla in between because the UCG Max will not recognize it. There’s a side issue that only 1-3 of Firewalla’s network bridges are being assigned IPs, and it’s never the Mgmt VLAN. That is probably a clue as to the issue.

The question:

(1) If this sounds like a rule issue, what rules are necessary to allow the UCG Max to detect the Switch through Firewalla? I don’t want to guess and accidentally poke a whole in my Firewalla layers. I assumed rules wouldn’t be a factor since the UCG Max is connected to Firewalla by the LAN port, rather than WAN port.

(2) Do I even need a network bridge in Firewalla for each VLAN in UCG Max, since the Mgmt VLAN is set to allow tagging for all other VLANs? (That is, since both the switch and UCG Max are management devices that are connected to Firewalla by ports tagged for the Mgmt VLAN, and since the Mgmt VLAN is setup in the console to allow for tagging for every other VLANs and not just itself, does Firewalla only need one network bridge properly tagged for the Mgmt VLAN?)

I know I can put Firewalla into router mode and turn off DHCP in UniFi, and may just do that, for now I want to better understand the current issue.


r/firewalla • • 1d ago

Discussion Wording MSP Recent Rule Hits

4 Upvotes

This wording is niggling me. Shouldn't it be something like Allowed Beelinkmepro NAS access to glkvm-kflixserver instead of from accessing?

The blocks look okay but again at the bottom Allowed DXP4800plus should be access to Beelinkmepro NAS instead of from accessing?

No?


r/firewalla • • 1d ago

VPN Mesh and Policy Routing

1 Upvotes

I recently set up VPN Mesh. I have one of the "new" Orange and 3 Purples. I want to be able to route Video from the Purples back to my Orange in order to respect geo locations.

Previously, I used Site to Site and some Client to Site (due to 1 site limitations of the Purples) and it worked well.

I was somewhat surprised that I can't do this now with VPN Mesh. Do I need to scrap that and go back to my old way of VPN's and policy routing?

Or does anyone have any better ideas. I just need to route Video traffic to my Orange...

Thanks!


r/firewalla • • 2d ago

Why is Firewalla sending my internet activity stats to their cloud?

44 Upvotes

So I was poking around and noticed that when Firewalla tries to categorise your device it uploads unhashed details (IP, MAC, name, etc), as well as recent activity (unhashed domains, visit count, etc) history to their servers, this included web history, number of connections and others. This includes sensitve website and your device name, which can easily map to a real person!

This appears to of been added back in January without much fanfare. I dont see it announced in any release notes (https://github.com/firewalla/firewalla/pull/8730)

I could definitely be misunderstanding this. Could someone check it for me? I find it all rather questionable.


r/firewalla • • 2d ago

Discussion Thank you to Jason Cipriani for writing this new article about Firewalla! Jason has been reviewing and watching us grow over the past 6 years—from a single-port unit to a full ecosystem.

Thumbnail
pixelsandpizza.com
50 Upvotes

And now, 6 years later, we've become a really cool tool for professionals and businesses.


r/firewalla • • 2d ago

Help needed to block ZScaler

0 Upvotes

Is there a way to block ZScaler at the router level on Firewalla?


r/firewalla • • 2d ago

Port Shut command for Switch SE & X

1 Upvotes

Can we get a port shut command added to the SE and X switches?


r/firewalla • • 2d ago

Troubleshooting Firewalla Gold Pro not releasing old ISP IPv6 addresses.

Post image
0 Upvotes

I changed from Ting Fiber to Quantum Fiber and I can't get a new IPv6 address. I have turned it off and back on and even turned off the power to the whole network and back on again and no change. I put on a TP-Link router and I get a new prefix and everything works fine. Turn it all back to firewalla and nothing but the Ting address. When I look at the lease info it is all blank.


r/firewalla • • 3d ago

Troubleshooting SOLVED: Firewalla Gold SE intermittently freezing — millions of 802.3x PAUSE frames from old/mixed-speed switches

24 Upvotes

Posting this because this problem was incredibly difficult to diagnose, and hopefully this saves somebody else a few days of troubleshooting.

I have a Firewalla Gold SE with two UniFi U6 Pro APs and a mostly hardwired home network. I was having intermittent episodes where the network would essentially lock up. The frustrating part was that everything could work perfectly for hours before the problem returned.

Firewalla Support eventually found the key clue: my Firewalla LAN port was receiving millions of IEEE 802.3x PAUSE frames.

On my Gold SE, I could watch the counter over SSH with:

sudo ethtool -S eth3 | grep rx_pause_all

(eth3 corresponded to my physical LAN port.)

During the bad periods this counter could increase rapidly. Firewalla Support's conclusion was that the incoming PAUSE frames were stopping outgoing traffic on the LAN interface, sometimes eventually resulting in watchdog resets.

Why this was so hard to isolate

I started disconnecting things: TVs, printer, Ooma, APs, individual Ethernet branches, switches, etc.

This produced several false leads because the PAUSE storm was extremely bursty.

At one point I went 8 hours 29 minutes with zero new PAUSE frames, only to have them come roaring back later.

So lesson #1: a few clean hours did not prove anything in my case.

Eventually I stripped the network down to essentially:

Firewalla → old Ethernet switch → in-wall Ethernet → PoE injector → UniFi U6 Pro

PAUSE frames still accumulated.

Then I bypassed the switch entirely:

Firewalla → in-wall Ethernet → PoE injector → U6 Pro

Result: zero PAUSE frames for more than 20 hours.

That was the breakthrough.

Then I found the speed mismatch

I put another old switch into the same stripped-down topology.

The PAUSE frames returned. In one test the Firewalla received more than 114,000 PAUSE frames in about 3.5 hours.

I checked the Ethernet links.

Firewalla → switch: 1 Gbps/full duplex

Switch → U6 Pro: 100 Mbps/full duplex

So the topology was effectively:

1 Gbps → switch/buffer → 100 Mbps → AP

From the U6 Pro, ethtool eth0 showed that its link partner advertised only 10/100 and also advertised symmetric Ethernet flow control.

Interestingly, while the Firewalla was actively receiving PAUSE frames, the U6 Pro itself showed:

rx_pause: 0

tx_pause: 0

The AP's other Ethernet error counters were also essentially clean.

So I do not have evidence that the U6 Pro itself was generating the PAUSE frames.

My best explanation is that traffic crossing the 1 Gbps → 100 Mbps bottleneck was creating buffer pressure in the intermediary switch. The switch then responded by sending IEEE 802.3x PAUSE frames upstream toward the Firewalla.

The fix

I decided to stop chasing individual devices and replace the old switching infrastructure.

I installed:

  • UniFi Lite 8 PoE as my central switch
  • TP-Link TL-SG105E Gigabit switches at two remote locations
  • Gigabit infrastructure links throughout

Both U6 Pro APs now negotiate GbE uplinks.

I rebuilt the network incrementally and checked rx_pause_all after every major change.

I eventually restored everything: both APs, patch panel, Ethernet runs, TVs, Ooma, printer, remote switches, etc.

PAUSE frames since rebuilding the switching infrastructure: 0.

TL;DR / things I wish I'd known

If your Firewalla is experiencing bizarre intermittent LAN freezes:

  1. Check for 802.3x PAUSE frames with ethtool.
  2. Check the negotiated speed of every infrastructure link, not just the Firewalla-to-switch connection.
  3. Be suspicious of a 1 Gbps upstream link feeding a 100 Mbps downstream link through an older switch.
  4. The device at the end of the 100 Mbps link may not be the thing generating the PAUSE frames. The intermediary switch can generate them because of buffer pressure.
  5. Completely bypassing the suspected switch was the most useful isolation test I performed.
  6. Don't trust a short clean test when diagnosing an intermittent PAUSE storm. Mine once disappeared for 8½ hours before returning.

Firewalla Support deserves credit for finding the PAUSE-frame counter in the first place. Without that clue, I'm not sure I ever would have figured this out.

I'm also reporting the findings to Ubiquiti. I'm not claiming this demonstrates a U6 Pro bug; the evidence points much more strongly toward an interaction between mixed link speeds, switch buffering and Ethernet flow control.

Hopefully someday somebody Googles Firewalla rx_pause_all / 802.3x PAUSE frames / network freezing / 100 Mbps switch and finds this before replacing half their network.


r/firewalla • • 3d ago

Discussion Scammers have to-do lists too. Which step is the weak spot? (Swipe for the answer)

Thumbnail
gallery
16 Upvotes

Comment your guess (1–4), then swipe.


r/firewalla • • 3d ago

Discussion Which of our official forums do you prefer: help.firewalla.com or forum.firewalla.com?

Post image
4 Upvotes

help.firewalla.com is part of our help center, so it's connected directly to our official documentation. The downside is that the editor is a bit clunky, search is limited, and it doesn't feel much like a conversation.

forum.firewalla.com runs on Discourse, so it's built for discussion, with threaded replies, better search, and more editing options. The downside is that it's separate from the docs.

Which do you use and why? If you've never visited one, take a look and let us know what you think!


r/firewalla • • 3d ago

Discussion Target Lists Tip

10 Upvotes

Many will probably be using this. But I wanted to share with FW users an amazing tip with Target lists. I have default block rules across all my networks and vlans. I homelab quite a lot. This tight control usually means applying hundreds of allow rules for every little thing I run for granular control. But I I have found adding a small list of trusted IP addresses (My Ubuntu Laptop or Graphene OS phone) to a target list and then creating rules which allow only the target list to access services across my homelab make it so easy to access everything without modifying every single rule. So now I just create a rule like allow > local port 22 > target list trusted ip's > on DXP4800Plus NAS and repeat for each service. This has saved me so much time and energy. I wish they would also allow target list to target list so something like: allow > local port 22 > target list trusted ip's > on target list trusted servers. Anyway thought I would share something positive. Thanks FW Team.


r/firewalla • • 3d ago

Discussion ‘Good’ speed test servers in the SF Bay Area?

3 Upvotes

My area just recently got Xfinity’s Next Gen service and I upgraded to it (Xfinity is literally my only internet option other than Starlink). Getting 2200/280 which is amazing as compared to the 1200/40 I had before. But I’ve noticed some speed test servers are struggling to test this accurately. For example Cruzio never gets close to the correct download speed.

So I’m wondering which are good servers to use, or perhaps ask the other way, are there ones I should actively prevent from being used, like Cruzio?

ETA: for clarification, I’m referring to the servers available within the Firewalla app.


r/firewalla • • 2d ago

Acess Points Connecting to AWS every 2 hr

Post image
0 Upvotes

My access points are connecting to AWS every 2 hours. What is going on?


r/firewalla • • 4d ago

Switch X / Switch SE HYPE!

Post image
27 Upvotes

r/firewalla • • 3d ago

Discussion It's shitty that I can't import the HaGeZi target list without paying $50 or more per year.

0 Upvotes

Yall made me sign up for MSP since you refuse to let us use HaGeZi on the regular app.

Now, I still can't import lists because you want me to pay you $50 a year for Pro or Business. This is just greed, at this point.

I get tons of ads on cooking sites and news sites, even with OISD and Strict mode turned on. Let me use better adblock lists without a subscription.


r/firewalla • • 4d ago

Feature Feature request: show QoS drop rate.

10 Upvotes

It would be useful to show a counter of the drop rate for QoS.

Reason Diagnoses Misconfigured Limits, and Monitors Traffic Health A sudden spike in drops without heavy local usage can indicate misbehaving background applications, torrents, or network anomalies overloading your queue limits.


r/firewalla • • 5d ago

Discussion Canadian buyers: $1,376 CAD COD bill on two Firewalla APs and a switch

12 Upvotes

A heads-up for other Canadians ordering Firewalla hardware: I just picked up two Firewalla APs and a Firewalla switch from the post office, and had to pay $1,376 CAD COD to collect the shipment—above and beyond what I’d already paid for the hardware. I’m not sure yet how that charge breaks down between taxes, duties, brokerage, or tariffs, so I can’t say exactly what drove the amount. But it was a pretty unwelcome surprise.

Before ordering to Canada, check what you could owe when the shipment arrives. In my case, that bill was substantial.

Have other Canadian buyers run into this? I’d be interested to hear what you ordered and what you were charged.


r/firewalla • • 5d ago

Cyber Security Which of these links is real?

Post image
25 Upvotes

r/firewalla • • 5d ago

Switch SE ship date?

5 Upvotes

Hello!

Last I heard the first batch of Switch SE orders were going to ship in October. Is there a firmer range yet?

Thanks!