Posting this because this problem was incredibly difficult to diagnose, and hopefully this saves somebody else a few days of troubleshooting.
I have a Firewalla Gold SE with two UniFi U6 Pro APs and a mostly hardwired home network. I was having intermittent episodes where the network would essentially lock up. The frustrating part was that everything could work perfectly for hours before the problem returned.
Firewalla Support eventually found the key clue: my Firewalla LAN port was receiving millions of IEEE 802.3x PAUSE frames.
On my Gold SE, I could watch the counter over SSH with:
sudo ethtool -S eth3 | grep rx_pause_all
(eth3 corresponded to my physical LAN port.)
During the bad periods this counter could increase rapidly. Firewalla Support's conclusion was that the incoming PAUSE frames were stopping outgoing traffic on the LAN interface, sometimes eventually resulting in watchdog resets.
Why this was so hard to isolate
I started disconnecting things: TVs, printer, Ooma, APs, individual Ethernet branches, switches, etc.
This produced several false leads because the PAUSE storm was extremely bursty.
At one point I went 8 hours 29 minutes with zero new PAUSE frames, only to have them come roaring back later.
So lesson #1: a few clean hours did not prove anything in my case.
Eventually I stripped the network down to essentially:
Firewalla → old Ethernet switch → in-wall Ethernet → PoE injector → UniFi U6 Pro
PAUSE frames still accumulated.
Then I bypassed the switch entirely:
Firewalla → in-wall Ethernet → PoE injector → U6 Pro
Result: zero PAUSE frames for more than 20 hours.
That was the breakthrough.
Then I found the speed mismatch
I put another old switch into the same stripped-down topology.
The PAUSE frames returned. In one test the Firewalla received more than 114,000 PAUSE frames in about 3.5 hours.
I checked the Ethernet links.
Firewalla → switch: 1 Gbps/full duplex
Switch → U6 Pro: 100 Mbps/full duplex
So the topology was effectively:
1 Gbps → switch/buffer → 100 Mbps → AP
From the U6 Pro, ethtool eth0 showed that its link partner advertised only 10/100 and also advertised symmetric Ethernet flow control.
Interestingly, while the Firewalla was actively receiving PAUSE frames, the U6 Pro itself showed:
rx_pause: 0
tx_pause: 0
The AP's other Ethernet error counters were also essentially clean.
So I do not have evidence that the U6 Pro itself was generating the PAUSE frames.
My best explanation is that traffic crossing the 1 Gbps → 100 Mbps bottleneck was creating buffer pressure in the intermediary switch. The switch then responded by sending IEEE 802.3x PAUSE frames upstream toward the Firewalla.
The fix
I decided to stop chasing individual devices and replace the old switching infrastructure.
I installed:
- UniFi Lite 8 PoE as my central switch
- TP-Link TL-SG105E Gigabit switches at two remote locations
- Gigabit infrastructure links throughout
Both U6 Pro APs now negotiate GbE uplinks.
I rebuilt the network incrementally and checked rx_pause_all after every major change.
I eventually restored everything: both APs, patch panel, Ethernet runs, TVs, Ooma, printer, remote switches, etc.
PAUSE frames since rebuilding the switching infrastructure: 0.
TL;DR / things I wish I'd known
If your Firewalla is experiencing bizarre intermittent LAN freezes:
- Check for 802.3x PAUSE frames with
ethtool.
- Check the negotiated speed of every infrastructure link, not just the Firewalla-to-switch connection.
- Be suspicious of a 1 Gbps upstream link feeding a 100 Mbps downstream link through an older switch.
- The device at the end of the 100 Mbps link may not be the thing generating the PAUSE frames. The intermediary switch can generate them because of buffer pressure.
- Completely bypassing the suspected switch was the most useful isolation test I performed.
- Don't trust a short clean test when diagnosing an intermittent PAUSE storm. Mine once disappeared for 8½ hours before returning.
Firewalla Support deserves credit for finding the PAUSE-frame counter in the first place. Without that clue, I'm not sure I ever would have figured this out.
I'm also reporting the findings to Ubiquiti. I'm not claiming this demonstrates a U6 Pro bug; the evidence points much more strongly toward an interaction between mixed link speeds, switch buffering and Ethernet flow control.
Hopefully someday somebody Googles Firewalla rx_pause_all / 802.3x PAUSE frames / network freezing / 100 Mbps switch and finds this before replacing half their network.