This guide will walk through the basic Firewalla Switch troubleshooting. If this guide does not help, please don't hesitate to email us at help@firewalla.com or use this link to create a support case, and our engineers will help you directly.
Switch Beta Resources:
- Discussion Forum (Login is required. If you don't have an account yet, please sign up here)
- Known Issues (Login is required. If you don't have an account yet, please sign up here)
Troubleshooting:
Networking Issues
1. Network is slow
- If using the Switch SFP+ port with an SFP+ to RJ45 adapter, please try the RJ45 port first, without the adapter.
- This helps isolate whether the network slowdown is related to the Switch itself or possible SFP+ adapter incompatibility.
- If speeds are normal with the RJ45 port, please see SFP+ Compatibility.
- Please test your Switch connections by visiting http://fire.walla:8833/ss/ over an Ethernet connection.
- This will rule out Wi-Fi as a variable.
- If using Safari and getting slower-than-expected results, try another browser such as Chrome.
- If you're experiencing speed issues between a high-speed device and a lower-speed device (e.g., from 2.5G to 10G, or vice versa), try toggling Flow Control on the Switch.
- On your Firewalla, go to Network > Topology > Switch Settings (top right corner) > toggle Flow Control. If it was off, please turn it on. Likewise, if it was on, please turn it off.
- If the above doesn't work, please try turning on flow control on other switches in your network.
2. SFP+ Compatibility
-
Please use widely compatible SFP+ adapters that work with multiple brands, such as TPLink, Netgear, Trendnet, etc.
- Most Ubiquiti SFP+ to RJ45 adapters will work. Please keep in mind that some may have strange behaviors, and we recommend trying a few other adapters.
- Most RJ45 adapters will get very hot.
- Avoid adapters that are built to work with a specific brand of network device (e.g., Cisco-only).
- The adapters in the image below generally work and were used in the Firewalla Office. (Disclaimer: we don't guarantee they will always work).
- Customer-verified adapters:
- Disclaimer: These are customer-verified, but are not all guaranteed to work in all situations.
- Please avoid adapters designed to work with a specific vendor (e.g., for Cisco). Read the product descriptions carefully, as some models may be locked to certain vendors. If possible, buy the "generic" version.
| Brand | Model | Notes | Suggested By |
| 10Gtek | SFP-10G-T-S | - | brewcity (Reddit) |
| 10Gtek | ASF-10G-T(HPP) | 30m RJ45 | H.2evAjyf-WPiU (forum.firewalla.com) |
| 10Gtek | ASF-10G-T80(HPP) | 80m RJ45 | H.2evAjyf-WPiU (forum.firewalla.com) |
| 10Gtek | CAB-10GSFP-P1M(HPP) | 1m DAC | H.2evAjyf-WPiU (forum.firewalla.com) |
| 10Gtek | CAB-10GSFP-P50CM-30 | DAC model | kckevin2 (forum.firewalla.com) |
| Nubasa | SFP-10G-RJ45-A | - | kckevin2 (forum.firewalla.com) |
| SODOLA | SL-10GE-T | 10G RJ45 SFP+ | azb (forum.firewalla.com) |
| TP-LINK | TL-SM331T | 1000Base-T RJ45 SFP Module | kdesch (forum.firewalla.com) |
| TRENDnet | TEG-10GBSR/2 | 10GBASE-SR SFP+ | pepper (forum.firewalla.com) |
- For more SFP+ Adapter Compatibility discussions:
Using Firewalla Switch
1. Network Loop Detected
A network loop happens when two ports end up connected in a way that creates a circle. This can slow down or possibly take down your network. Firewalla's STP (Spanning Tree Protocol) will automatically detect loops and block affected ports, so you stay protected, and your network keeps running.
If Firewalla detects a network loop, the app will mark the affected port(s) in yellow with an exclamation mark.
If you recently added or moved a cable, Switch, or device, start by unplugging your most recent change and tapping Check Again in the app. Otherwise, try checking your full cable setup:
- Look at the affected port number(s) in the Firewalla App. Check the same physical port(s) on your Switch.
- Trace the physical cable from the affected port(s) to the other end.
- Check whether both cable ends land on:
- The same Switch, or
- Two devices that are already connected in another way. (For example, an AP7 connected to Switch A, but also connected to Switch B, and Switch A and B are connected.)
- If so, unplug one end.
- Tap Check Again in the app and see if the banner is cleared.
If the banner keeps returning after you've checked your cabling, try replacing the cable connected to the affected port and see if that solves the issue.
2. ACL Overflow
Local Tracking or Controls Disabled
ACL reflects the hardware-level entries currently active on your Switch. These entries are used for managing local traffic (e.g., VqLAN, Device Isolation, Allowed Devices), and understanding device-to-device communication. Usage is split into Control and Tracking and may increase with the number and complexity of rules applied.
Note that these are theoretical counts and can be influenced by
- Downstream devices count
- Group count
- Group policies or rules
- How your network devices talk to each other
The most efficient way is to have most of your Ethernet devices directly under the Firewalla Switch, which will make resource usage very efficient.
Here are some ways you can optimize ACL Usage.
Local Tracking Disabled
If you exceed the Switch's ACL limit, Firewalla will be unable to track local traffic between wired devices. Firewalla will continue enforcing local control rules (VqLAN, Device Isolation, etc.), but it may not record local flows.
Local Controls Disabled
If your Control ACL usage exceeds your ACL limit, Firewalla will be unable to control or track local traffic between wired devices. Firewalla will NOT enforce local control rules (VqLAN, Device Isolation, etc.) or record local flows.
Because your local control rules are no longer being enforced, we recommend lowering your usage as soon as possible. See Optimizing ACL Usage
Optimizing ACL Usage
To lower your ACL usage, here are some ways to optimize:
-
Reduce downstream Ethernet devices
- Try moving some devices to a different switch or network segment.
- If you have another switch connected downstream, this can increase your ACL usage.
-
Reduce local control rules
- Try reducing redundant or overlapping rules on local wired traffic.
-
Reduce downstream Wi-Fi devices on non-Firewalla APs
- Many Wi-Fi devices connected to your Firewalla Switch can increase ACL load.
- We recommend using the Firewalla AP7 to reduce ACL load on the Firewalla Switch via a secondary distribution algorithm.
-
Get another Firewalla Switch
- Each Firewalla Switch has its own ACL usage.
- Getting another Firewalla Switch can take the load off the primary Firewalla Switch.
- Upgrade to a Firewalla Switch model with a larger ACL capacity
Reset Switch to Factory Default
1. Reset from the App
- Make sure the Switch is powered on and connected to the Firewalla Box.
- Open the Firewalla app, go to your Firewalla's main screen, and tap the Network button -> Topology.
- Tap the Switch you want to reset.
- Scroll down to the bottom and tap Delete This Switch.
- The Switch will be deleted from the box and reset to factory default.
Note: If the Switch is not connected to the Box, deleting it from the app won't reset it to factory default. You'll need to manually reset the Switch following the steps below:
2. Reset via the Reset Button
Switch X
Switch SE
- Make sure the Switch is powered on.
- On the front of the Switch, use a pin to press the reset button for at least 10 seconds.
- Wait for the reset to complete. It will reboot automatically and become ready for pairing.
- Check the light status during reset:
| Power Light | Status Light | Switch Status |
| Solid On | Off | Reset Button Pressed |
| Off | Blink | Resetting |
| Blink | Off | Reset Finished, Booting Up |
| Off | Solid On | Reset Failed (Rare) |
- After resetting using the reset button, delete the Switch from the app:
- Firewalla Box's main screen -> Network -> Topology.
- Tap the Switch that you manually reset.
- Scroll down and tap Delete This Switch.
Comments
0 comments
Please sign in to leave a comment.