Firewalla Managed Security Portal Introduction

Follow

Comments

44 comments

  • Avatar
    Support Team

    No, the charging hasn't started yet. We will ensure that our existing MSP users experience a smooth transition, and we will provide you with prior notification before any access is terminated.

    Can you access your Purplewalla via Firewalla App? Does the box still have access to the Internet?  Please contact support at help@firewalla.com so the engineers can help you directly. 

    1
    Comment actions Permalink
  • Avatar
    Alejandro Sánchez Márquez

    Thanks team, it was already sorted out.

    1
    Comment actions Permalink
  • Avatar
    Client Support

    @Chris

    Your query is incomplete. Note the content-type is missing in your query.

    curl --request POST --url 'https://MSP_name.firewalla.net/v1/flows/query' \
    --header 'Authorization: Token 3c....x' \
    --header 'Content-Type: application/json' \
    --data '{ "limit": 300, "start": 1680138615, "end": 1680224893}' \
    |  jq '.[] | {ip,fd,blocked}' | grep fd | wc -l

    300

    see also https://help.firewalla.com/hc/en-us/community/posts/8124104287123/comments/9358203524243

    0
    Comment actions Permalink
  • Avatar
    Chris Hewitt

    @ClientSupport ... yup. that works. PICNIC!

    But, strangely, I still can't pull blocked in-bound flows. Nor can I find them on the Firewalla.

    But none of these are being returned (I also tried with a limit of 4500).

    There is this, which is FD=OUT, but no IN.

     

    curl -s --request POST --url 'https://XXXXXX.firewalla.net/v1/flows/query' --header 'Authorization: Token XXXXXXXXXXXXXXXXXXXXXXXXXX' --header 'Content-Type: application/json' --data '{ "limit": 3000 }' |  jq '.[] ' | grep -A20 -B20 "194\.110\.203\.225"

    {
      "ts": 1680270630.926,
      "deviceIP": "xxx.xxx.xxx.xxx",
      "devicePort": "3389",
      "duration": "",
      "fd": "out",
      "gid": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
      "gid_extracted": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
      "category": "intel",
      "download": "",
      "intf": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
      "port": "41847",
      "count": 2,
      "country": "RU",
      "device": "if:xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
      "host": "194.110.203.225",
      "ip": "194.110.203.225",
      "ltype": "audit",
      "protocol": "tcp",
      "type": "ip",
      "upload": "",
      "wanIntf": "XXXXXXXXXXXXXXXXXXXXXXXXXX",
      "blocked": true,
      "blockPid": "",
      "blockType": "ip",
      "networkName": "WAN",
      "onWan": true,
      "intfInfo": {
        "name": "WAN",
        "type": "wan",
        "uuid": "XXXXXXXXXXXXXXXXXXX"
      },

     

     

     

     

    0
    Comment actions Permalink
  • Avatar
    David Tragger

    I have 3 Golds (in 3 separate personal, not business, locations) and 1 Purple for Travel. Sure I'll try the services in this Trial Beta moment... but it's an absolute non-starter that you'd then force me into an insanely cost prohibitive business plan model because of these personal device limits. You are truly alienating your base here. If you look at the comments there are a lot of us in this same situation. Hopefully you revisit your device limits and devise a MUCH more suitable plan... otherwise why would I keep investing into the Firewalla platform if my ability to then to better manage launches the costs-to-operate insanely high? Right now I seem to already be beyond the limits. Please review the scope of what is personal and what is business, perhaps based on other metrics other than just physical units. Otherwise this service is going to be dead on arrival (out of beta) to a lot of your long term supporters NOT using them for business means. If this is the direction Firewalla chooses to hold onto, it looks like I'll have a few units to sell off soon.

    2
    Comment actions Permalink
  • Avatar
    Shew

    Fully agree with David's post.

    I personally have 3 Purples in two homes and mobile.

    But maybe more importantly, I'm a Firewalla advocate. I've helped many friends and family get them as well.  And I frequently help those folks get things working or understand alarms.

    Why would you make this more difficult for your advocates?  Sure, we can work around not having MSP and add a phone to their router.  But why not make it more seamless - especially for personal, non-commercial use. 

    If you want to implement this, you could limit the size of data stored per box or shorten the time period for retention. Maybe move your architecture to a serverless approach for logging since there won't be much traffic and the UX need will be very intermittent.

    2
    Comment actions Permalink
  • Avatar
    Matt Niswonger

    I think David makes a good point.  I love Firewalla as a platform, and the MSP is great, but I don't see the value in having to jump up to the business plan just because you need more than 3 boxes managed.  I would imagine there's a lot of people who have under 10 boxes for family and themselves; myself included.

    I'd gladly sacrifice somewhere else to keep cost down for you and allow more boxes for us.  Perhaps a tier with less storage (storage is expensive in the cloud) but allows more boxes.  Like 7 days worth of traffic flows instead of 30, but up to 10 boxes.  Or maybe host it in a cheaper AWS region even though it might be slightly slower, or allocate fewer compute resources.  I'm spitballing here.

    2
    Comment actions Permalink
  • Avatar
    Alejandro Sánchez Márquez

    Hi,

    I have noticed a change in the last weeks and I want to know why (or if others have the same issue).

    I do not see the incoming blocked flows anymore, not even from the Firewalla app. From there, I can only see the outgoing connections (top destinatios + outbound). For the blocked flows chart, I only see those pertaining to the DNS / ADblock system.

    Thanks in advance.

     

    0
    Comment actions Permalink
  • Avatar
    Client Support

    Hi @Alejandro,

    I don't think this is an MSP issue, but maybe something about this particular box. I'm going to open an issue to follow up with you so we can resolve this for you.

    1
    Comment actions Permalink
  • Avatar
    Alejandro Sánchez Márquez

    Solved!

    0
    Comment actions Permalink
  • Avatar
    Alejandro Sánchez Márquez

    Hello Firewalla team, while using the web interface, which is really nice (but still improvable), I noticed that there is no auto-update / auto-refresh feature when you are looking at flows, for example. 

    It would be really useful to implement it, no need for it to be configurable, something like 1 minute autorefresh would be nice, cause when you are waiting for seome traffic to be spotted you might need to refresh the page multiple times.

    And theres another thing which is important for me and maybe for others. Certain features are not implemented 1:1 between the app and the web interface. Im refering to the target lists, cause not being able to manage them, when suposedly the app remains the main source of management, is a nuisance.

    Thanks in advance and keep it up.

    0
    Comment actions Permalink
  • Avatar
    Bezmat

    Hi team,

    Love the MSP portal. Just added the Slack integration for Alerts but from what I can tell, System Events like "Box Offline" don't appear to be included in the Alerts sent via Slack. If that's true, can you please consider adding a Slack Webhook integration for System Events (using a different channel/workspace to Alerts)? This would mean I'm alerted immediately if a box goes offline (usually an internet outage), rather than finding out from the remote users.

    Cheers!  

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    @matt, let me relay this back to our developers. 

    0
    Comment actions Permalink
  • Avatar
    Yoav freiberger

    Even though I only have a single Firewalla box, I would still pay for this IF I could leverage the new block lists (Hagezi Pro++ that I put in a lot of effort for AGH replacement level filtering), without having to route through another box. However, SInce I have to have visibility to the gateway traffic uses (in a serious way not the app) - by pass geo restrictions and such, means domains need to be updated, and you always have to know which gateway the traffic exists. Probably an oversight, but i havent seen this neither on My.firwewalla.com, nor in what I see here in flows. For me the vital thing is to. see which wan interface is configured for traffic (e.g. all target list us domains through us vpn gateway, uk throgh uk, etc) yet it seems to just say (Even at the packet leve) source device, target domain, lan interface the device is on (all quite self explanatory)  but without seeing the wan gateway (even availlable on the app but totally not helpful with its limitations, i lost out on any of the benefits. again Id be happy to pay just to put my blocking in one, but without gatway and monitoring per domain, which is required to update target lists, and correct me if I missed something, the benefit, for me at least, is not there. Hope to get good news on this one. Thank

    1
    Comment actions Permalink

Please sign in to leave a comment.