Firewalla doesn't seem to really support routing

Comments

6 comments

  • Avatar
    Firewalla

    Do you have a quick network diagram we can look at? Is this for a home network? business network? or small campus network?

    Firewalla mainly focus on home and small business (<300 or 400 devices)

    0
    Comment actions Permalink
  • Avatar
    Derek Small

    My home network isn't too complicated, however I do have 6 Vlans/DMZs, and several firewalls that I can direct the default route on my core switch through for testing.  There are about 50 devices on my internal network including wireless connections.

    0
    Comment actions Permalink
  • Avatar
    Derek Small

    OOps, the IP on the inside interface of the Firewalla is actually .40, not .30.

    0
    Comment actions Permalink
  • Avatar
    Derek Small

    Typically on most firewall platforms I would configure objects (devices) for all the subnets on my network that I want to allow access to the Internet.  Then in the firewall rules, I would specify those objects as the source, and "ANY" as the destination. 

    I could forgive a vendor for selling a product for $100-200 that is limited to allowing only what you connect directly to it.  But there are a number of firewalls on the market for $500 that don't have such a restriction. I admit most of them are going to require you to pay for anual support to keep the features running, but that is why I wanted to give Firewalla a try.

    I am also really confussed why you have the ability to configure routes on the Firewalla, if you cannot configure firewall rules to allow traffic from the sources you would be creating the routes for.  If that is just to create a default route to point to your ISP, then why not just give a field where users can specify the destination gateway for a default route?

    I added a route for 10.0.0.0/16. and pointed it to my core switch (10.0.100.1). So the Firewalla can send traffic towards my Core switch for my other subnets, but that would never happen because the firewall policy on the Firewalla will never allow traffic from any source except 10.0.100.x

    0
    Comment actions Permalink
  • Avatar
    Support Team

    Can you try to add the other VLAN subnets. e.g. 10.0.10.0/24 to "Source Networks" and see if it works?

    You can find "Source Networks" by:

        Box main screen -> Network -> NAT Settings -> Source Networks

     

    0
    Comment actions Permalink
  • Avatar
    Derek Small

    OK. That worked. I thought I looked everywhere for something. In retrospect it seems like an obvious place to look.  Thank you for the help.

    0
    Comment actions Permalink

Please sign in to leave a comment.