Handling Specific Firewalla Alarms

Follow

Comments

7 comments

  • Avatar
    Paul C.

    Would we ever have the capability to classify our own rules and/or target lists as an alarm category?

    For example, I have a list of sites that can be accessed from my network but I want to know if they are ever accessed (an audit mode of sorts). I have these sites in a target list. I created a rule that allows access to these sites via the target list, simply to log that the rules have been hit (no further details, only that it was hit X times, and the day/time the rule was last hit). I would like to alarm when the specific rule is hit so I have details on what device, when, and which site it was. So if I could classify the rule as an alarm category (Gaming, Video, Porn, etc.), I could accomplish this.

    Hopefully this makes sense. It just seems logical to be able to alarm on rules we create. Thanks in advance and hopefully this can be added!

    0
    Comment actions Permalink
  • Avatar
    Firewalla CM

    Hi Paul, thanks for the request. Custom Alarms are not yet available, but you are welcome to cross-post it to our Feature Requests forums, or add on to an existing request: https://help.firewalla.com/hc/en-us/community/topics/115000356994-Feature-Requests

    That said, it is possible to manually edit our target categories. When creating a rule, tap the "i" icon next to a category, and tap "+" to add a new target. https://help.firewalla.com/hc/en-us/articles/360008521833-Manage-Rules#h_01EJG5XZPZSKSJY7EGTYXA0RM5

    0
    Comment actions Permalink
  • Avatar
    Raul

    When a security alarm is triggered, it creates a new rule blocking the source.

    I maintain a target list of IP/Domains that I have a rule set to block this list.
    Would it be possible for the security alarm to add the IP/Domain to the target list, rather than creating its own dedicated block rule?

    Not sure if this would be a feature request or if we can do this now, somehow. 

    0
    Comment actions Permalink
  • Avatar
    Firewalla CM

    Hi Raul, are you referring to when you receive an Alarm, and tap Block on the alarm, and it creates a new block rule?

    If you already have a target list created, you can tap the Alarm, tap the IP/Domain, and select Add to Target List. For more details, see: https://help.firewalla.com/hc/en-us/articles/1500005941962-Firewalla-Feature-Target-Lists#h_01HPF9H3BWQNBFCHQ6ZGPABSR9

    0
    Comment actions Permalink
  • Avatar
    Raul

    For security alarms, it automatically creates a block rule. So I have to delete that rule since I'm manually adding that IP/Domain to the global rule I already have in place via the target list.

    0
    Comment actions Permalink
  • Avatar
    Firewalla CM

    It sounds like you're referring to the Active Protect rules. These are automatically handled by Firewalla. There's no need to remove them and add them to your own target list blocking rule. Is there a specific reason you'd prefer to handle it yourself?

    You're welcome to create a formal feature request here: https://help.firewalla.com/hc/en-us/community/topics/115000356994-Feature-Requests

    0
    Comment actions Permalink
  • Avatar
    Raul

    I'd rather have 800 IP/Domains in a target list than a rule blocking each automatically, seems the most sensible. Automated blocking is huge, but adding a rule per trigger rather than within a target list seems overkill. 

    0
    Comment actions Permalink

Please sign in to leave a comment.