Help us make the Firewalla Switch

Pinned Featured

Comments

446 comments

  • Avatar
    Firewalla

    We are hoping to have a limited beta release in July. (still a few parts missing, but our ODM is optimistic to get them and build a small run)

    1
    Comment actions Permalink
  • Avatar
    snovvman

    Where's the line lol?

    0
    Comment actions Permalink
  • Avatar
    DanM

    Switch X Question: What is the 13th Port, an RJ45 on left side of the box? Main Port to connect FW router instead of using one of the other (8) RJ45 ports? Thank you.

    Firewalla support - Thank you for the fast response. I didn't see a similar port on the Switch SE

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Good question; That's the console port. We thought it is obvious, since you asked, we will go label it 

    0
    Comment actions Permalink
  • Avatar
    Jon MacDonald

    Why have a console port if it is completely managed by the app? Can that be turned into another usable port?

    1
    Comment actions Permalink
  • Avatar
    John Harrold

    I think they could fit in a few more ports if space were the only consideration. I think it's driven by heat production and energy consumption. It's also a white label device so it probably comes with the console port by default even if it's not needed. 

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    These are white-label (existing units from the ODM) loading our software. Not much we can do with customizing things, otherwise, you will see a cost ++ 

    And yes, Switch X power is inside the metal box, so it get a bit hot once you load all 400+ watts. Not much room for other things. 

    2
    Comment actions Permalink
  • Avatar
    Firewalla

    Update June 4, 2026

    • Targeting Beta in the middle of July with a very limited number of units.

    • Pre-sale / sale date, unknown, waiting for commitment on CPU/Memory/EMMC

    • Likely, both Switch X and Switch SE will be available. If not, Switch X will be there for sure.

    • Both units should have CE/FCC/Canada certifications. (Class A devices)

      • There are white-label units designed to be industrial or enterprise by the ODM.

    6
    Comment actions Permalink
  • Avatar
    Firewalla

    A not-so-professional SE (working hard) photo

    1
    Comment actions Permalink
  • Avatar
    Andre

    I guess this one is fanless, but can you tell us how loud is X model?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    For normal operations (we have 4 PoE+ running) on X, the fan is low spin, in office can't hear it. In a quiet room, if you are 3/4 feet from it, you can hear. Any further, not noticeable. (I'll get more scientic numbers when we get our final unit)

    But if you are starting to use most of the 400W PoE, then likely the fan will spin louder. (I assume when this happen, you will be placing it in a isolated rack)

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    The early access sale and pre-sale dates will likely be July 7 or July 14th. (mark your calendars) Both of these units will be discounted from the target price. (as usual)

    Early Access: These are early units, final hardware, and beta software. Shipping within a few days of placing the order. We want to get some early feedback while waiting for parts. (very limited quantity)

    Pre-Sale: These are future units, likely shipping in September or October. 

    We may have a pre-sale 2, since even the initial pre-sale units are limited due to the chip shortage. 

     

    3
    Comment actions Permalink
  • Avatar
    James Zeiger

    Sale in the morning, a particular time?  What time zone will the sale time be under? 

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    We usually start around 9 am Pacific Time.  

    0
    Comment actions Permalink
  • Avatar
    Andre

    Ok, I hope you will have enough se units, because people will buy those like crazy. There’s not too many ports on each, and I personally would need at least two of those. 8 ports, my Goodness, that’s so insufficient.

    0
    Comment actions Permalink
  • Avatar
    Mark9

    Ditto.  I need 3 of the SE units.

    0
    Comment actions Permalink
  • Avatar
    Ryan

    I’ll try for a single unit but I doubt I’ll be successful with everyone aiming for multiple.

    Still hoping for a smaller, gold pro sized switch down the road that can handle my 5gb fiber speed.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    We may separate the early access and pre-order buckets for the sale. The early access side will have a limit of 1 unit per kind of switch. And the pre-order one has no limit. The number of pre-sale units will be limited ( a lot more than early access) due to parts limitations. 

    Early access delivery is within few days. (we fly them over from Taiwan ...) And pre-sale is September / early October.

     

    0
    Comment actions Permalink
  • Avatar
    Darren

    Will there be any SE on the early access for UK customers?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Early access is USA only. 

    We will confirm in a week or two if we can pre-sale to other countries. (pending finalized certifications) Due to what's happening in the Middle East, shipping rates are going to be expensive for the EU. 

    0
    Comment actions Permalink
  • Avatar
    Chester B Weber

    I hope early access doesn't have restrictions.  if I buy it will have to replace what I have its entirety

    0
    Comment actions Permalink
  • Avatar
    Mark9

    I was planning on purchasing enough SE’s for early access to do proper testing of VqLAN.  However, Firewalla just posted that we “will have a limit of 1 unit per kind of switch” for early access.  This may submarine early access for me because I have two layers of switches, two Cisco’s for my Gold Plus’s two separate LAN’s, and Netgear 5 and 8 port switches in different rooms at the edge, all connected with Ethernet.

    I’m going to dive deep with questions to figure out whether there is any way to have non-Firewalla switches at the edge (at least temporarily) as others have also expressed interest in doing.  For example, there are small managed switches with port isolation which can be configured.  There are a few unmanaged switches with a hardware isolation toggle that allow no east-west traffic (TP-Link TL-SG1210MP).  And there are some MikroTik switches supporting bridge horizon (similar to the hardware isolation toggle).

    The challenge with these isolation techniques comes when a device must talk with other devices (they will work if a device only talks to the internet).  Will VqLAN work for the following cases in a two layer switch architecture where the Firewalla router talks to a Firewalla switch which in turn talks to edge switches which do not allow east-west traffic:

    1. Will Firewalla allow device to device communication when the two devices are in separate edge switches?
    1. Going a step further, will Firewalla enable local-proxy-arp on their routers and switches so ARP will work between devices in the same subnet on the same edge switch, thus allow the devices to talk to each other? Enabling local-proxy-arp will cause the Firewalla routers and switches to answer the ARP on their behalf with its own MAC address. 
    1
    Comment actions Permalink
  • Avatar
    Firewalla

    Sorry about the limit, we need all thanks to the AI boom

    You can still mix switches, when you have a non-firewall switch, firewalla app will not be able to control / view flows of devices attached to that device; It may still be able to see flows and control access if the devices on a non-firewall edge switch is talking to a device on a firewalla switch.

    Firewalla can't see device-to-device traffic that never crosses any firewalla switch. 

    Even when device traffic goes over a firewalla switch, we also can't guarantee we can capture or manage that traffic, due to ACL limitations. 

    If you don't care about the visibility and control, a third-party switch should work nicely. 

    0
    Comment actions Permalink
  • Avatar
    DanM

    Good question. I don’t have your complexity but am assuming down stream edge switches will have no issues other than crosstalk within a non-managed switch before AP’s (as link home run) to FW router or a 100% populated switch with same group of devices (Reolink PoE) connected to a dedicated core switch port. I’m a bit over my skis in the final management plan or options.

    0
    Comment actions Permalink
  • Avatar
    Mark9

    I will be testing the two non-Firewalla edge switch scenarios in early access, but would greatly appreciate if Firewalla can at least let us know if local-proxy-arp is configured in the Firewalla router (Ubuntu Unix) and the Firewalla switch.  For my and other's sake, I hope it is enabled!

    0
    Comment actions Permalink
  • Avatar
    Firewalla CM

    BTW, we're giving away 2 Firewalla Switch SE's in our newest contest! Check out the details and enter here: https://forum.firewalla.com/t/contest-2026-show-us-your-network-the-best-and-the-messiest/61 

    If you don't plan to enter, you can still participate by voting for your favorite submissions. Good luck to all!

    3
    Comment actions Permalink
  • Avatar
    Firewalla CM

    Switch X started building! Progress is looking decent. We can likely make the July 7 Pre-Sale date 🙂 

    3
    Comment actions Permalink
  • Avatar
    Eric

    @Firewalla CM

    Same progress/target for the SE?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Same progress for the SE. 

    0
    Comment actions Permalink
  • Avatar
    Eric

    Thanks

    0
    Comment actions Permalink

Please sign in to leave a comment.