MSP 2.10.0 is now available to all MSP Early Access users!
To join our Early Access Program:
- Click the Switch to Early Access button on your MSP Dashboard when you see the Update Available banner.
- Alternatively, go to your MSP Settings page (top right corner of your MSP Interface) > scroll down to MSP Update > select Early Access for the Release. Your MSP Instance will upgrade automatically within 1-2 minutes.
Firewalla Managed Security Portal (MSP) is our web interface designed for security and infosec professionals to manage multiple Firewalla boxes easily. Learn more about MSP here, and sign up at firewalla.net/plans.
New Features
1. New Single-Box MSP View
We've optimized the MSP experience for users who manage a single Firewalla Box. With the Single-Box MSP View, you can:
- Open the Single Box Dashboard by default and quickly access features like Performance, Networks, Wi-Fi, and VPN Client from the left navigation bar.
- Manage Box Settings and Mobile Access directly from Inventory.
- Import and manage all Box Target Lists from the Single Box view.
- Manage Protect (Firewalla AI and MSP Active Protect) from the Single Box view.
Requirements for the new Single-Box view:
- Only one Firewalla Box in your MSP Inventory
- No Box Groups configured
- No VPN Mesh configured
2. Email Notifications: Alarm and Event Summary Digests
Introducing MSP Notifications! MSP can now send Summary Digests to keep you updated on recent activity via email. Summary Digests currently support:
- Alarms and Network Events
- Daily and weekly email frequencies
Email Notifications are automatically configured to send to the MSP owner. For Business Plans, up to 10 MSP Admins (Owner + 9 Members) can be configured as recipients. Notifications will be sent to the email used for the MSP account.
Learn more about managing MSP Notifications.
Here's an example of an email you could receive:
3. Import Target Lists from GitHub (Experimental)
In this MSP release, you can now Import Target Lists from GitHub. To help regulate what lists can be imported, only lists that are available on fw-public-lists are supported.
- fw-public-lists is a Firewalla-managed GitHub repository of community-maintained optional blocklists and other datasets. It is open-source, and anyone can contribute to it.
- Target list can be a "list" or a link to a public avaliable list.
- These lists are community-curated and may not be 100% complete or accurate. Use at your own discretion. Firewalla does not guarantee the behavior of third-party domains, nor does it mandate the use of these lists.
To import Target Lists to Firewalla MSP, click Target Lists on the left navigation bar, and click Import Target List. Lists from fw-public-lists will be marked with a yellow "Community" label and will be synced periodically.
- To contribute or request a specific External List, please see https://github.com/firewalla/fw-public-lists.
- We are not responsible for the content of any submitted list and do not verify whether a list is valid, accurate, compliant, or legally usable. All responsibility for the submitted content rests solely with the submitter. We reserve the right to remove any list at our discretion, including in cases of discrepancies, violations, licensing conflicts, usage restrictions, or quality issues.
- This feature will remain experimental, and if not enough users, we may disable it in the future.
4. My Firewalla Merged with MSP
Our free web interface, My Firewalla, is now merged with Firewalla MSP as a new portal: MSP Lite.
MSP Lite has all the same free features as My Firewalla, but with a new, updated look to match the rest of Firewalla MSP. With the unified codebase, MSP Lite also supports additional minor features and enhanced security, including email authentication before accessing your Firewalla and two-factor authentication support.
To access the new Free Portal,
- Navigate to Firewalla MSP at https://beta.firewalla.net
- Click Sign In in the top right corner. You'll need a Firewalla MSP account to access the Free Portal.
- Then, scan the QR code to sign in to your box, just like you would before.
For existing paid MSP users (Professional and Business Plans), you'll now see all your other MSP portals in one place, and a QR code to easily access the Free Portal for any boxes not part of your paid MSP portals.
5. Grant Mobile Access from MSP
We now support adding Mobile Access directly from the MSP Interface. Unlike Temporary Access, which previously allowed users to manage a box for 24 hours via the mobile app, Mobile Access can give permanent access.
This is great for scenarios where you may have lost previous box pairings on your phone, or if you'd like to remotely give users access to a Limited view of a box.
Only MSP Owners on the Business Plan can grant Mobile Access. To grant access,
- Click Inventory on the left navigation bar.
- Click the Mobile Access tab, then click Add Mobile Access.
- Select the Firewalla to grant access to, and choose Full Access or Limited for the Access Level.
Then, open the Firewalla App on the mobile device, tap [--] in the top left corner, and scan the QR Code generated by MSP.
(Firewalla App must be using App 1.68 to pair with Firewalla using the MSP-generated QR Code.)
Learn more about Mobile App Access Control.
6. Filter flows by Matched Rules
Previously, Firewalla MSP supported "BlockedBy" so you could filter any flows blocked by certain rules or features.
In this release, the filter has been renamed to "MatchedBy" and now supports all rules, including Allow, Time Limit, and Disturb rules, and supports additional Firewalla features.
You can also view all flows relating to a rule by:
- Clicking the Hit Count from the Rules list, or
- Clicking View Flows from your Rule Details.
Note: The hit count on a Rule is the number of hits since the rule was created, or the reset of that counter. When tapping "View Flows", it will be the flows from the last 30 days only.
7. Firewalla AI for Network Performance
Firewalla MSP now supports Firewalla AI for Network Events. With the extended data visibility, Firewalla AI can make better suggestions and identify patterns more easily.
To ask AI about the Network Events on Firewalla MSP,
- Navigate to a Single-Box view, and click Events in the left navigation bar.
- Click Ask AI about the events.
- Alternatively, click Performance in the left navigation bar. Firewalla AI will automatically analyze any past events.
Learn more about Firewalla AI Assistant.
Enhancements
1. Increased Limits - VPN Mesh, Target Lists, and Report Exports
For Professional and Business MSPs, we've increased the limits on certain features:
- VPN Mesh Limit (Professional): Up to 10 boxes per mesh.
- Target List Limit (Professional + Business): Up to 100 total Target Lists.
- Report Export Limit (Professional + Business): Export larger data sets for Reports.
2. General Enhancements
- Supported Creating Rules with MSP API.
- Firewalla AI Flows Search now uses the "Enter" key shortcut if the query is not in regular syntax format.
- For Business plans with boxes in 180-day seats, along with Flows, MSP now supports up to 180 days of:
- Alarms
- Performance (including Internet Speed and Internet Quality test results)
- System Events
- Target List ownership is now referred to as "Managed By". You can import/delete 3rd-party target lists in any view, and any target lists created on MSP are now always managed by MSP, and can be applied to any box.
- Supported IPv6 addresses as an optional column in the Device Table.
- Supported changing MSP Owners for Business MSP Plans. Please contact us at help@firewalla.com if you need to change MSP Owners.
Bug Fixes
Fixed an issue where boxes might incorrectly appear offline.
Fixed an issue where a Site-to-Site IPsec VPN connection may fail to establish.
Fixed an issue where the UI may incorrectly display a VPN client’s connection status.
Fixed an issue where some previously blocked flows may fail to sync to MSP after joining.
- Other UI improvements and minor bug fixes.
Known Issues
-
Issue: When adding a box (version 1.982) to an MSP instance, if it previously joined and left MSP (in MSP 2.7.0 or earlier), it may not sync part of the history flows (during the last 24 hours). Newly generated flows after joining the MSP will be synced correctly.
How to fix: This issue will be fixed in the next MSP version.
-
Issue: For certain allow rules, even when the flow hit count is not zero, clicking “View Flows” may return no results.
How to Fix: This issue will be fixed in a future box update.
-
Issue: When reloading the flows page or opening a flow report, filters applied by rules or devices may appear as rule IDs or MAC addresses instead of a descriptive name.
How to Fix: This issue will be fixed in a future update.
-
Issue: Flow Search with Firewalla AI may not correctly return results for flows matching specific rules.
Workaround: Use “Matched By” as a filter to find flows tied to a rule. Improvements to Firewalla AI are ongoing.
Comments
0 comments
Please sign in to leave a comment.