To support Firewalla key features like cybersecurity protection and parental control, the little red box analyzes network traffics and raises alarms to notify the user with related activities, such as:
- Connecting a new device
- Possible cyber attacking
- Abnormal uploading
- Playing a game
- Watching video
- Accessing adult content website
- Connecting to VPN Server
- Malware Download
- Open Port
1) Unless specified, alarms are default allow until blocked.
2) No matter archived or not, all alarms will be automatically deleted in 30 days.
Here are some tutorials on how to handle Alarms.
- Archived Alarms
Tap on "Tuning" icon on the top right corner of alarm UI to enter Alarms Settings Page.
Alarm Settings is where you configure two things:
- whether you want the box generates a certain type of alarm or not
- whether you want to receive App notification or not
You can create or delete alarm settings directly under Alarm Settings -> each Alarm Type. Or you can do it when click "Mute" button in alarm page.
There are 2 sections in alarm settings, General Setting and Specific Setting.
General Setting is applied to all devices.
- Send Both Alarm & Notification: Both alarm and App Notification will be generated.
- Send Alarm Only: Only alarm will be generated, but you will not receiver App Notification.
- Mute All: Neither alarm nor App notification will be generated.
Specific Setting is where you define the exception, to mute Alarms on a specific device and/or on a specific domain.
Example: Mute Alarms on a device when accessing a certain subnet
If you want to mute Abnormal Upload Alarms when Annie's iMac is accessing subnet 18.104.22.168/24.
Step 1: Tap on "Alarm Settings" on the upper right corner of Alarms page. Tap on "Abnormal Upload".
Step 2: Tap on "Mute". (If the general setting is set to Mute All, there will not be a choice to mute specific device/destination.)
Step 3: Tap on "Add Destination" -> Enter "22.214.171.124/24". (Destination can also be a certain IP Address / Domain.)
Step 4: Tap on "Next" -> Apply to "Annie's iMac". (If you don't want to specify a device, tap on "All Devices.")
The setting will be created under "Mute" -> "Mute Destination". Currently, settings cannot be modified. If you want to modify, delete it first and then recreate it.
Example: If you have a Ring device, you can mute following 126.96.36.199/16, 188.8.131.52/16, 184.108.40.206/16, 220.127.116.11/16, 18.104.22.168/16 to mute the cloud upload. (contributed by Firewalla community)
Alarm Handling - Mute
The "Mute" button on alarms UI means, you understand the activity and are OK to archive it.
Under the alarm that you want to Mute, tap on the "Mute" button. Determine whether to Archive this Alarm, Mute alarms on this domain, or mute alarms on a certain kind of activity, then tap on the choice.
- Archive - this option will archive this alarm. Similar behavior happens again in the future, you will still receive alarms.
- Mute domain / Mute xxx activity - these options will archive not only this alarm, but also archive all similar alarms you see in the alarm list. In addition to that, these options will create a new rule in alarm settings under the corresponding category alarm's "specific setting" section. Similar behavior happens again in the future, you will not receive any alarm.
For example, if you choose to "Mute domain googlevideo.com, apply to device My iPhone", Firewalla will generate a specific mute rule in Alarm Settings -> Video Activity, which results in no alarm will be generated and sent when My iPhone access *.googlevideo.com.
To undo the mute action, you can
- find the archived alarm and tap "undo mute"
- open Alarm settings, find the corresponding setting and delete it.
Alarm Handling - Block
The "Block" button on alarms UI means, based on the alarm details, you determine it is unsafe to access the site, you want to block it for future access.
Under the alarm that you want to Block, tap "Block" button. Determine whether to block this device / all devices from accessing an IP address, a specific domain, or a certain type of activity, then tap on the choice.
- All blocking options will archive not only this alarm, but also archive all similar alarms you see in the alarm list.
- All blocking options will also create a blocking rule to the little box. Similar activity happens again in the future will be blocked automatically by Firewalla. The generated rule can be seen in "Rules" UI.
- The difference between block domain / block site / block IP address boils down to the number of IP addresses to be blocked (Domain > Site > IP address).
To view, edit or delete the generated blocking rules, checked out this article: learn more about Rules.
Alarm Handling - Detail
If you need more help on this alarm, just click the alarm once. It brings up an alarm detail page, more information related to the alarm can be seen here, such as site registration, location of the server, previous 6-hours data transfer between your device and that site, and even Firewalla intelligence service suggestion regarding to this transfer.
When determining whether an alarm is "good" vs "bad", it is both a science and an art.
Alarm Handling - Delete/Archive
If you'd like to remove an alarm from the alarm list, tap on "…" on the top right corner of the alarm, you'll find the action of "Delete alarm permanently" or "Archive".
- Archive - to remove the alarm from the alarm list, and put it into the Archived Alarm list.
- Delete - to remove the alarm from the Box completely.
Tap on "More actions", you can choose to delete or archive all alarms in the alarm list.
By the way, even if you don't do anything, all alarms will be deleted automatically in 30 days.
As mentioned above, the action of either Mute or Block will archive all matched existing alarms. If you want to review these alarms, they can be found at the top right corner of the alarm page.