Turn off flow logging?

Comments

21 comments

  • Avatar
    Firewalla

    You can turn  monitor off;

    tap on devices->[their device]->monitoring off

    The Monitoring button is used to control whether the device is monitored by Firewalla or not. When turned off, no traffic to that device can be monitored, flows will not be recorded, and no connection can be blocked by Firewalla.

    0
    Comment actions Permalink
  • Avatar
    Todd W

    Thanks for the quick reply! I'll read up on monitoring.  

    0
    Comment actions Permalink
  • Avatar
    GamerZer0

    This would be an interesting feature... have all the "safety features" ON but exclude specific devices from the main flows screen/view... So keep network protected... apply all my rules... but don't show me what device X and/or Y etc are doing or any details of the data flows.

    Something like Silent/Blind Protection.

    Turning off monitoring is not a solution here I guess.

    Could be related... Details on "What happens when Monitoring is off, or Emergency Access is on?":

    https://help.firewalla.com/hc/en-us/articles/16639311975059-What-happens-when-Monitoring-is-off-or-Emergency-Access-is-on-

     

    0
    Comment actions Permalink
  • Avatar
    Michael Bierman

    @gamerzer0 the problem I see with that is there is no way to see if the rules worked as intended. I can imagine that being a support nightmare. 

    0
    Comment actions Permalink
  • Avatar
    GamerZer0

    True... Maybe best to add filter in Network Flows screen to "exclude" one or more devices. Maybe that's one safe way to do it.

    0
    Comment actions Permalink
  • Avatar
    Todd W

    I think the way Pi-Hole handles this is great.  You can adjust the levels of logging to see what's getting blocked, etc. Flip a toggle when you're having problems to see what's going on, flip it off when you're satisfied.  

    I agree, turning off monitoring is not ideal.  There should be some level of granularity in determining what gets logged without compromising functionality.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    I may have missed the point on this thread. :(

    @Todd, do you mean to do filter the network traffic? or you don't see the logs of traffic?

    0
    Comment actions Permalink
  • Avatar
    Todd W

    @firewalla I don't want to see the traffic, but I want the functionality.  For example, it seems like disabling monitoring turns off things like ad blocking (bad) and I don't see the details of my teen's web use in flows (good).

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    In the next app 1.56, we will have a way to exclude traffic from devices while displaying the flows. This should work for you. 

    0
    Comment actions Permalink
  • Avatar
    Todd W

    Thank you! I look forward to testing that in the beta program!

    0
    Comment actions Permalink
  • Avatar
    1980cyber

    What does the noise include?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    This is what I got from the unreleased-release-notes 

    • System Noise: Excluding system noise will filter out background traffic on your OS system and commonly seen apps. It helps you focus on important activities within your network.

     

    0
    Comment actions Permalink
  • Avatar
    1980cyber

    can we configure the noise level?

    0
    Comment actions Permalink
  • Avatar
    Sean K

    I first wanted to say thank you for this feature. Could you also give us the ability to exclude based on port or protocol. i.e DNS. Can be noisy sometimes.

    0
    Comment actions Permalink
  • Avatar
    Zach

    Unfortunately, this update doesn’t solve the issue I think OP is asking for.

    I am also interested in managing a network for others in my household, but want to give them their own privacy. I want to be able to hide all traffic logging for a vlan, but still have firewalla perform rules and blocking on it. I would expect logs to be less descriptive, ex “an egress request was blocked” instead of “an egress request to ‘website domain here’ was blocked’.

    1
    Comment actions Permalink
  • Avatar
    Pat

    Hi @Zach @Todd W, i have put a request in at Feature Requests akin to Zachs comment above for a privacy mode on devices that protects privately. If you are interested please upvote there. https://help.firewalla.com/hc/en-us/community/posts/1500001208721/comments/54682572705043

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    This can only be done if you use the MSP (it has a proper login that's recoverable if anything went wrong). It has the "no-flow" seat (not expensive, $1 per month) that will allow you to manage but not "see" flows. (you still need a plan to drive it) https://help.firewalla.com/hc/en-us/articles/25037436951699-Firewalla-MSP-Managing-Seats#h_01HKTV8M5XXSKHSNWE90B07KZ3

     

     

    0
    Comment actions Permalink
  • Avatar
    Pat

    Thanks for the quick response , can this no-flow seat be utilised at the device level, as in no flow for surfing devices but flows for tv, smart home devices still being logged?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    not possible at the moment. It is pretty difficult to get consent on what device is allowed and what is not allowed. 

    0
    Comment actions Permalink
  • Avatar
    Zach

    Over time my idea for this feature could be as simple as a checkbox on the device that hides data on the client. Like the actual data would be there, but the view would be obscured

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    The main issue is that we don't formally have a recoverable admin user on the phone side to provision these permissions. (A small business of less than 50 people probably doesn't need this.) So the function to limit permissions can only be done by an admin user via the MSP, which can safely do many things, because that account can be recovered. 

    This means, it is possible to have MSP manage the fine-grained controls, but we are unsure how many are requiring this type of granularity 

    0
    Comment actions Permalink

Please sign in to leave a comment.