- To learn more about Firewalla Crystal, go to beta.firewalla.net/crystal
In this guide, we'll walk through setting up Firewalla Crystal SE on Custom Hardware (Bare Metal).
The setup guide for virtual machines is coming soon
- Proxmox
- VMware ESXi
What You'll Need:
- A Firewalla MSP account that owns a Crystal SE ready for provisioning.
- A dual- or quad-port generic hardware device to use as Firewalla Crystal.
- A USB drive with at least 8 GB of space for the install file.
- A system (Windows, Mac, or Linux) to flash the software to the USB drive.
"Crystal" Hardware Minimum Requirements:
- 2 CPU cores (x86 architecture)
- 4 GB (4096 MB) memory
- 32 GB of storage
- 2 Ethernet interfaces
- Must boot from USB or an alternate flash drive
Pre-Configuration WARNING:
- Firewalla will automatically wipe all data from the device's HD. Please make sure you do NOT have any critical data stored on the host you use.
How to set up Crystal on Custom Hardware:
- STEP 0: Order a Firewalla Crystal
- STEP 1: Set Up Network Profile
- STEP 2: Download Software
- STEP 3: Flash Device
- STEP 4: Go Live
- Troubleshooting
STEP 0: Order a Firewalla Crystal
- If you are already an MSP owner, go to your MSP Portal and join MSP Early Access (MSP Settings → MSP Update → Release → Early Access).
- If your MSP is already in Early Access, click Update now on the banner of your MSP dashboard to update to version 2.12.
- If you don't have an MSP plan, sign up at beta.firewalla.net and sign in there. (No need to purchase an MSP plan first — we'll set up your MSP when you buy a Crystal.)
- Go to beta.firewalla.net/crystal, select your Crystal Type and Billing Cycle, then check out.
- After checkout, the page will show a Start Provisioning button. Click it to begin Zero-Touch Provisioning.
-
From the MSP management UI, you can also click the Provision button on the banner to start.
STEP 1: Set Up Network Profile
From Firewalla MSP's Zero-Touch Provisioning, set up your network profile and hardware.
Select the hardware that closely matches your Device Type, then click Next.
- Typically, this would be
Generic x86 (auto-detect) - For
Other, please enter the device brand, model, and number of ports.
Select your WAN Connection and LAN IP address, then click Generate Personalized Software.
Not sure which to choose?
- DHCP: Most common, works for most networks
- PPPoE: If your ISP gave you a login
- Static IP: If you have a fixed IP address
STEP 2: Download Software
Download the software image.
Prepare your USB drive.
- We recommend etcher.io for your flashing program.
- Flash the image you just downloaded to a USB Drive.
- Flashing will erase everything on your USB drive. If needed, back up the data on your USB drive before proceeding.
STEP 3: Flash Device
Configure Device BIOS Boot Priority
Once your USB drive is flashed with the Crystal image, it's time to flash your hardware.
WARNING: All pre-existing data on your hardware device will be erased. Installing Crystal software will repartition and overwrite the internal drive. Please back up any important files. This process cannot be undone.
WARNING: The WAN port CANNOT be changed after the unit is flashed
- Make sure your hardware device is powered off, then plug the USB drive into a USB port on your device.
- Connect the device's WAN port to a router or switch with DHCP enabled.
- An active internet connection is required for flashing. If you wish to connect this device to your modem with PPPoE or a static IP, the provisioner will guide you to rewire in step 4.
- If there is no dedicated WAN port, use any Ethernet port, and the provisioner will set it up as WAN.
- For example, we used ETH0 on our custom hardware to set it as WAN. For Crystal SE, this will bridge ETH1, ETH2, and ETH3 into a single LAN.
-
Make sure your device can boot from USB before continuing. You may need to configure the BIOS to change the boot priority.
- Connect a monitor and keyboard to your device.
- Power on the device.
- Immediately open the BIOS Setup. The hotkey depends on your hardware (usually
ESC,DEL, orF2). - Navigate to "Boot" or "Boot Priority" on the BIOS menu. If your USB drive is not listed as position #1, please move it. The BIOS menu will typically display which keys to use to move the Boot Options.
For example, our custom hardware has[UEFI: Samsung Flash...]as Boot Option #3. To fix it, we would select Boot Option #1 and change it to the Samsung Flash drive.
- Save your changes and exit BIOS. The device will now reboot from USB.
Begin Flashing
The provisioner will wait for the device to connect before it continues to flash the device. The Firewalla-provisioner flash console will display the current progress.
While flashing the device, check the monitor display of the device. If the provisioner doesn't show any progress, the monitor display can tell you what's happening in the background.
- The progress shown on the provisioner screen may be slightly delayed. If the provisioner doesn't show any flashing progress, or it shows that the download may take a few hours, please check that the monitor display shows the current transfer speed. It may take a minute or two for it to update with the correct estimated download time.
- Another example issue is “no cable on any Ethernet port detected”. This can typically indicate an issue with the WAN connection itself.
See Troubleshooting for more details.
STEP 4: Go Live
Your hardware is now running Firewalla Crystal. To move it to your network:
- Power off the device and unplug the USB drive.
- If you plan to move Firewalla Crystal to a different location, unplug the Ethernet cable from the device to the upstream router and connect it to your cable/fiber modem, if using it as your main router. Otherwise, you can keep the Ethernet cable as is. The port used during provisioning will be the WAN port.
- Before powering on your Crystal, please power off your modem, wait 5 min, then turn it back on. This will force your modem to forget the previous router.
- Power on the crystal device.
Then, click Continue to finish the setup. After the Crystal is online, you can use your Firewalla App to scan the QR code on the screen to pair with the device. You can also do this later, or pair it with other phones in Inventory -> Mobile Access.
Click Get Started to begin managing your Firewalla on MSP.
Troubleshooting
[STEP 3] Waiting for device to connect (takes more than 5 minutes)
- Check that the BIOS is configured to boot from the flashed USB drive. You may need to power-cycle the device to enter the BIOS. Pay attention to the monitor display on your device and press the hotkey to enter BIOS. The hotkey depends on your hardware (usually
ESC,DEL, orF2).
[Step 3] Flashing failed. Check the power and network cable connections, then restart provisioning.
- The hardware device may not be fully powered on. Double-check the power cables.
- The hardware device may not have an active internet connection. Double-check that the Ethernet port is connected to a device with a DHCP function.
- Restart provisioning will let you generate the image and start the process again.
[Step 3] Ethernet port or cable not being detected by the system
- Double-check that the Ethernet port is connected to a device with DHCP function. Depending on the hardware, the device may have lights on the Ethernet port to indicate link activity.
[Step 4] Waiting to Come Online (takes more than 5-6 minutes)
- Check the monitor display on your device. If it shows "no internet," double-check that the Ethernet cable is securely connected on both ends and the upstream network is active.
- If using a modem, try turning it off for ~5 minutes, then turn it back on.
Comments
0 comments
Please sign in to leave a comment.