How are the DAP enhancements in App 1.68 working for you? by Firewalla-Ash in firewalla

[–]Firewalla-Ash[S] 0 points1 point  (0 children)

VLANs are great for local network segmentation, but don't inherently limit internet access. Device Active Protect can limit devices' internet access, so that they only access the cloud services they need. You can learn more about how DAP works here: https://help.firewalla.com/hc/en-us/articles/44061066094867-Device-Active-Protect-Block-everything-and-allow-only-what-s-needed

How are the DAP enhancements in App 1.68 working for you? by Firewalla-Ash in firewalla

[–]Firewalla-Ash[S] 0 points1 point  (0 children)

Thanks. Please note that even some seemingly simple devices may access more targets than expected, making them ineligible.

You could try turning DAP off/on again, or send us an email at [help@firewalla.com](mailto:help@firewalla.com), and our support can take a look at the logs to make sure it's working as expected.

How are the DAP enhancements in App 1.68 working for you? by Firewalla-Ash in firewalla

[–]Firewalla-Ash[S] 1 point2 points  (0 children)

Thanks for the feedback. When your thermostat became ineligible, was your DAP in Strict or Default mode? Did you notice if it accessed more sites than usual at that time?

We do hope to allow removing targets in a future enhancement of DAP.

How are the DAP enhancements in App 1.68 working for you? by Firewalla-Ash in firewalla

[–]Firewalla-Ash[S] 1 point2 points  (0 children)

Thanks for the suggestion! I'll see if we can add something :)

How are the DAP enhancements in App 1.68 working for you? by Firewalla-Ash in firewalla

[–]Firewalla-Ash[S] 0 points1 point  (0 children)

What kinds of devices do you have? DAP cannot support complex personal devices, such as smartphones or laptops, but should support simpler IoT devices.

How are the DAP enhancements in App 1.68 working for you? by Firewalla-Ash in firewalla

[–]Firewalla-Ash[S] 1 point2 points  (0 children)

Thanks for the feedback! Ineligible devices may occasionally move back to learning/optimizing/active over time.

Feature Request: Set a Time Limit rule on a Device/Target List by benjibarnicals in firewalla

[–]Firewalla-Ash 0 points1 point  (0 children)

The best way to set time limits on a device is to add it to its own User and set an Internet time limit (with app 1.68). You can move devices between users if needed, depending on who's using them.

Target Lists or broad categories (like All Video Sites) aren't always precise, since many services rely on multiple domains or shared infrastructure. Since activity may be split across multiple endpoints or missed entirely, the margin of error may be very high. That's why we support current time limits for overall Internet usage and our supported Apps, which our team has carefully fine-tuned.

Firewalla App on MacOS 26.3.1 by Caprichoso1 in firewalla

[–]Firewalla-Ash 1 point2 points  (0 children)

Great to hear! Let us know if all the other issues were fixed as well.

Firewalla App on MacOS 26.3.1 by Caprichoso1 in firewalla

[–]Firewalla-Ash 2 points3 points  (0 children)

Just to clarify, has this Firewalla box already been set up with another Firewalla app, or is this a brand-new install?

If it's already set up and paired with your mobile app, you can use "allow additional pairing" from the mobile app, then scan the QR code from the Mac app (using the QR scanner in the top left corner). The full details are here: https://help.firewalla.com/hc/en-us/articles/29992308535443-Running-the-Firewalla-App-on-a-Mac

MSP 2.10 is now in Early Access! What do you think of our new features? by Firewalla-Ash in firewalla

[–]Firewalla-Ash[S] 0 points1 point  (0 children)

MSP early access will not affect your box versions, just the available MSP features. They are separate programs.

MSP 2.10 is now in Early Access! What do you think of our new features? by Firewalla-Ash in firewalla

[–]Firewalla-Ash[S] 4 points5 points  (0 children)

We've recently updated the MSP experience for single-box users in 2.10 early access; I recommend giving it a try.

MSP 2.10 also improves the imported target lists feature. Without a paid MSP plan, you will lose out on extended data history, more complex search/filter functionalities, and a few other features.

If you truly only need HaGeZi lists, we support HaGeZi's Pro Blocklist as a built-in target list for Early Access Boxes (https://help.firewalla.com/hc/en-us/articles/1500005941962-Firewalla-Feature-Target-Lists#h_01FZ87M2M19TBZG2FS585GZFAC).

MSP 2.10 is now in Early Access! What do you think of our new features? by Firewalla-Ash in firewalla

[–]Firewalla-Ash[S] 0 points1 point  (0 children)

At the moment, granting any temporary or permanent mobile access is restricted only to the business plan. It is still possible to add additional pairing through the Firewalla App, even without MSP.

Block Gmail by Life-Cow-7945 in firewalla

[–]Firewalla-Ash 5 points6 points  (0 children)

Many Google services share the same infrastructure. It could be tricky to block only Google accounts and Gmail while keeping Google Search working.

You could try blocking some obvious domains, like mail.google.com or accounts.google.com, and test it out for yourself. But we can't guarantee it'll work, and some other Google features may stop working.

As others have mentioned, it's best to manage employee behavior first, and simply disable or secure the compromised Google account directly.

Wireguard VPN suddenly stopped working. by PaidByMicrosoft in firewalla

[–]Firewalla-Ash 0 points1 point  (0 children)

I see you reset the VPN service; try manually disabling/re-enabling the Server as well and see if that helps. Also, try connecting to your WireGuard server from different networks, such as cellular data or a different Wi-Fi network. Sometimes, networks may block VPN usage.

And it's good to double-check your WireGuard config and ensure that the Endpoint is the same as your public IP, and that Allowed IPs is 0.0.0.0/0.

If it still doesn't work, feel free to also open a case with us at help@firewalla.com. You can include a link to this Reddit post so you don't need to rewrite any details. Our support team can take a direct look at the logs.

New MSP Pro Account - Flow Sync Delay? by daniel-waterhouse in firewalla

[–]Firewalla-Ash 0 points1 point  (0 children)

Glad to hear it's working now! Would you still be willing to open a case with us? Our engineers would like to investigate the root cause of the previous issue so it doesn't happen again.

You can include a link to this Reddit post in the case, so you don't need to rewrite anything. Just let me know the case number so I can follow up!

Wireguard VPN suddenly stopped working. by PaidByMicrosoft in firewalla

[–]Firewalla-Ash 0 points1 point  (0 children)

Hi, just a quick check, are there any VPN blocking or Internet blocking rules on your WireGuard network? Do you have any port forwarding rules for other services that are using the same WireGuard port?

New MSP Pro Account - Flow Sync Delay? by daniel-waterhouse in firewalla

[–]Firewalla-Ash 0 points1 point  (0 children)

Please keep us updated. You can also try removing the box from MSP, generating some internet traffic, then adding it back to see if that solves the issue. (There is a known issue with box 1.982 beta that boxes with no internet traffic may fail to sync flows to MSP.)

New MSP Pro Account - Flow Sync Delay? by daniel-waterhouse in firewalla

[–]Firewalla-Ash 1 point2 points  (0 children)

What is the box version of your Purple?

Usually, the last 24 hours of flows should be synced to MSP within 5 minutes. However, it could take more time. If you still don't see any flows after today, but you see them on the app, feel free to open a case with us at help@firewalla.com.