Firewalla app version 1.64 is now available to all beta users.
Please follow the links below to sign up for the Firewalla iOS or Android app beta program:
- iOS: https://testflight.apple.com/join/Nr0IMETY
- Android: https://play.google.com/apps/testing/com.firewalla.chancellor
Most feature in this release requires box version 1.980 or above, which is available on:
- Firewalla Gold Pro, Gold, Gold Plus, Gold SE, Purple, Purple SE Beta release
- Blue Plus: Alpha release
To join the Early Access program for 1.980
- On the beta or early access Firewalla app, go to Settings > Advanced > Beta Program.
- Tap 10 times on the text Join Box Beta Program.
- Tap on Early Access to upgrade your box to Early Access.
To join the Beta program for box 1.980
- Launch the Firewalla App > Settings > Advanced > Beta Program
- Turn on Join Box Beta Program
---
New Features
1. Local Flows (Requires box version >=1.980)
The app now supports displaying the flows across networks for Firewalla boxes with more than one Local Network configured. A chart on the box's main screen will show Data Transferred and the number of Local Flows for the last 24 hours. Tap the chart to see which device sends or receives the most data to or from other devices on your network.
Due to the memory limit, the detailed history of local flows are not supported on Firewalla Purple and Purple SE.
- If you have the Firewalla Access Point 7 installed, you'll be able to see all the connections between devices connected to the AP7.
- Local flows will only work in router mode. (bridge mode likely to come in a later release)
2. VPN Group for Failover (Requires box version >=1.980)
When connecting devices to a VPN, some service providers may offer multiple servers for failover in case one becomes unavailable. For boxes running in Router Mode, Firewalla now supports creating VPN groups, allowing you to create a VPN group that includes multiple VPN profiles for improved availability.
- Firewalla will connect to all VPN clients in the group at the same time. When the primary VPN profile fails, it will forward the traffic to the next available profile in the list.
- The order of the VPN profiles can be rearranged. Tap Edit in the top right corner of the VPN Group and drag and drop the profiles into the desired order.
Note: Port forwarding and Unbound over VPN are not currently supported with VPN groups; you may need to continue using individual VPN profiles for these features.
3. Firewalla AP7 Support (Requires box version >=1.980)
With App version 1.64 and Box 1.980, we are introducing Firewalla Access Point 7, which enables you to build a Zero Trust Network with Wi-Fi 7 and Firewalla.
More information can be found here: https://firewalla.com/ap7
Enhancements
1. iPad Landscape Mode (Experimental Feature)
In response to community requests, this release introduces iPad landscape support for Beta and Early Access users. As long as you are using both the Testflight App and your Firewalla box is in Beta or Early Access mode, landscape support will be enabled automatically and no configuration is needed. (This feature is experimental, we do not intend to release it to production soon.)
2. Display Roaming Event during Wi-Fi Test
To make the Wi-Fi test feature even better, we've added BSSID and Channel Info to the test. If you are walking around and your Wi-Fi connection has roamed from one AP to another, the graph will show the last four digits of the new BSSID and the channel your phone is connected to.
If you are using a Firewalla Access Point, the app will display the name of the Access Point instead. Tap the info icon to go directly to the Access Point's detail page.
Bug Fixes
- Fixed several display issues.
Known Issues
-
Issue: With the box 1.980 update, the live throughput chart on the box's main screen may show an unusually high spike for about 1 to 2 seconds after opening the app.
How to Fix: This issue has been fixed on the Early Access apps. Beta update is coming soon.
-
Issue: When the New Device Quarantine feature is enabled on one network, the new device alarm notifications for other networks (where New Device Quarantine is not enabled) may also show that devices have been quarantined. This is a UI display bug.
How to Fix: This issue has been fixed in the Early Access boxes. Beta update is coming soon.
-
Issue: Network flows may not be shown correctly on boxes set up recently.
How to Fix: This issue has been fixed in the latest update.
- Issue: Device Isolation or VqLAN is only available when the Firewalla AP7 is installed on your network and devices are connected to it. If a device connected to the AP7 with Device Isolation enabled switches to a different access point, the isolation button will be hidden. However, Firewalla will still block traffic to and from other networks for that device.
Comments
15 comments
Love the local flows! Will this show all flows between all LAN/VLANS?
Local flows will show traffic between LAN and VLAN (port or VLAN based segments). The detailed flows are only available on Gold series. (purple, you can only see a summary)
If you have the Firewalla AP7 (coming in January), you will be able to see same LAN traffic.
Are local flows not available if utilizing transparent bridge mode?
I'm using Firewalla Gold Pro Beta Release, Box version 1.9790 and iOS app version 1.64 (125). Is there a way to migrate/force the box to upgrade to version 1.980 in order to take advantage of the Local Flows?
I need to research differences between Early and Beta release's.
Can you get them to add the protocol as well as the port number on these flows?
@DanM
Please see our Early Access Onboarding instructions to upgrade your box to 1.980.
Thank you. I have sent the email and am awaiting a response. I looked at my app Beta Program option and the only choice is "Leave App Beta Program". I am assuming an alternate option will show up either automatically or once I have received an email confirming acceptance into the Early Access Program. If incorrect, please advise.
Thank you.
EDIT, Update: 10 taps was recognized and transitioning. Thank you
@DanM
Yes, once you have been accepted into the EA program, you should be able to move on to step 2 of the EA Onboarding instructions:
Hi - I am in the EA program and have the 1.980 firmware update installed with the latest (1.64) EA app on my FWG Plus device. When checking the Local Flows I don’t see any activity even though I have 6 VLANs and multiple cross VLAN transfers. Is this a known issue? Tks!
Do you have the segments isolated? via rules? if not, are you aware of any LAN to LAN traffic?
Yes, my segments are isolated using VLANs with Rules. I also tested copying a file from one segment/VLAN to another and did not see any activity in the Local Flows though I see the transfer/activity show under Live Throughput. NOTE: I have opened a ticket for this at support@firewalla.com as well.
VPN Group, I would suggest adding an option to cycle or randomize which VPN is in use within a group, having a list of many VPN that rotate could help with privacy vs hitting the same one first all the time.
Are local flows only work if the flow is going across the firewalla’s network ports? For me it doesn’t seem to track devices that are communicating between each other on the same switch downstream. Only devices whose traffic is crossing Firewalla local lan ports is tracked. Is that correct? Running Firewalla Gold in router mode.
Unless you are using the firewalla AP7 and your devices are attached to it, Firewalla local flows (in fact all firewalls) can't see your local flows between devices outside of the firewalla.
You can see traffic between devices in your LAN only if they are on different subnets (and assigned a separate VLAN ID in the downstream switch) otherwise there is no way for FWG to distinguish this traffic. E.G. Inter-LAN traffic (will show in Local Flows) ,Intra LAN (between devices on the same VLAN/LAN) will not show.
Please sign in to leave a comment.