Block new device until approved

Comments

39 comments

  • Avatar
    Firewalla

    Stacy

    We did that first, but the problem is, consumers often forget to tap on allow ...  So the easiest and most logical way is do the opposite.  allow until blocked. 

    0
    Comment actions Permalink
  • Avatar
    Stacy Haven

    I can see that logic. That was why I was thinking that it could be an option that you only turn on when you want to make sure that nothing on the network can "call home" when you are in this mode. I guess if all my devices were showing in the firewalla devices list I wouldn't be so worried, but the fact that my router is showing them, but the firewalla isn't makes me nervous.

    2
    Comment actions Permalink
  • Avatar
    Firewalla

    We are curious on the devices that only shows up in the router.  Firewalla does pretty deep scans, and pretty sensitive to any kind of packets.  Do you happen to know what these devices are?  (we have seen virtual interfaces inside the router works this way)

    I've logged your request already, will see if someone want to work on it. 

    0
    Comment actions Permalink
  • Avatar
    Stacy Haven

    I don't. Those devices aren't showing on the network currently that I can see. I was originally thinking that they might be from my vmware esxi box, but the mac addresses from that are in sequence. Or at least the first three octets are anyway. The weird part is that if I see a notice for any device I always make sure I know what it is before I approve it. But I don't check everyday so maybe it showed as an alert and then I didn't allow it. My hope is that it would show up under devices approved or not, but signify as such. However, the ones in question aren't even in the list of devices so the only way to know is to catch the device.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Stacy

    The device will show up regardless in the device list.    One possibility is router may be tracking IP addresses, and the same device may have different IP's.  We can dig this further if you want.  Feel free to send us a email at help@firewalla.com, we likely will ask you for support access to your box

    0
    Comment actions Permalink
  • Avatar
    FK

    I would also like to see a switch where you can at least choose to decline new devices.

    2
    Comment actions Permalink
  • Avatar
    Simon Cutting

    +1 from me for the blocked until allowed switch. :)

    3
    Comment actions Permalink
  • Avatar
    Didier Salembier

    +1

    for now I'm still using FingBox to block all new devices "until proven otherwise" but I hope this could be an option we can enable on Firewalla!

    1
    Comment actions Permalink
  • Avatar
    Eduardo

    +1 it would be great to have

    0
    Comment actions Permalink
  • Avatar
    Damon

    +1 I'd like the option to block until approved, but make it optional to enable this mode.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    We had this type of feature before ... but the problem with that was, people always forget and then you get connection problems ... then problems come to us.   So, we revert it back to allow and block if you care.   Having these knobs also costs engineering, so we decided to go with allow and if you care, block it, model.

     

    0
    Comment actions Permalink
  • Avatar
    Damon

    When I first purchased my blue this functionality was in place, and it was one of the reasons purchased the product as my router was failing miserably at this functionality. It's a bit disappointing that the feature was stripped out without being an option, and the suggestion to disallow after connected is very different in both management of devices and end user perception. Now I'm back to looking for a device that will support the deny until allowed.

    0
    Comment actions Permalink
  • Avatar
    Didier Salembier

    FingBox does the job and a combination with firewalla is possible!

    1
    Comment actions Permalink
  • Avatar
    Firewalla

    We are working on something that's a lot better ... stay tuned.  It will make things a lot more secure.

    0
    Comment actions Permalink
  • Avatar
    Richard

    Hi, I just bought a Blue to replace a FingBox and don't see any option to turn on blocking by default (also signed up for beta), the option to switch on a secure by default approach that FingBox uses seems much more sensible to me, fine if you leave it off by default like FingBox does, but not to have it is a miss... I'm wondering if I should plug my FingBox back in...

    0
    Comment actions Permalink
  • Avatar
    Didier Salembier

    For me THAT is the main reason to keep my FingBox running (and the wonderfull speedtest of course).

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Firewalla co-exists well with Fing, so feel free to plug it back in.  As of default block, it will be part of the Gold release, and that code should work with the Blue when it is done. 

    0
    Comment actions Permalink
  • Avatar
    Richard

    Great, thanks, I'm signed up for a Gold. thanks!

    0
    Comment actions Permalink
  • Avatar
    Michael Bierman

    @firewalla Is this feature still planned? will it be in Gold?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    It will be in the Gold as part of the lockdown feature.  

    1
    Comment actions Permalink
  • Avatar
    Derek Breydin

    Hi, sorry to drag an old thread up, recieved my gold yesterday, set it up last night, I'm really happy with it but was looking to set the system to block new devices and only allow once I press unblock rather than to have to block, was wondering if the feature was ever added?

    1
    Comment actions Permalink
  • Avatar
    Firewalla

    Heard you all, loud and clear.   We initially build the feature to block and approve.  And now we are changing it a bit to have the device placed into a group.  And that group, you will be able to configure 'any' policy you want on it.    The change should not be difficult, and we are hoping to get it out in 30 days to beta.

    3
    Comment actions Permalink
  • Avatar
    Derek Breydin

    Thanks 😊

    0
    Comment actions Permalink
  • Avatar
    Michael Bierman

    Thank you firewalla. This will be helpful (esp with changing MAC addresses). 

    Would you consider adding the ability to alert in rules? For example, a rule that says for any new device:

    1. allow internet only.
    2. alert admin a new device has joined. 

    this will allow someone to have some basic connectivity right away and then be granted more. I could imagine a different circumstances where people would not want to be notified like when someone joins a guest WiFi network. 

    0
    Comment actions Permalink
  • Avatar
    Randy

    Would be nice to have either or option for this.

    At least if blocked until approved is checked/switched could potentially stop hackers temporarily anyway. May place this under the advanced area.

    Then if the Block Until option is chosen, then grey out the option to approve until blocked.

    The first would allow the end-user the ability to have ultimate control of their internet access. So I think that would need to be under the advanced user area. But initial install would default to the allow until blocked option.

     

    $0.02

    1
    Comment actions Permalink
  • Avatar
    Chris Hewitt

    Gold user (love it) - but just had a device connect that I don’t want to connect. Looked for a default block option. Nope.

    Now I am sad. Do you want to turn my frown upside down? Please add an option for default quarantine for any previously unseen device.

    +1 to the OP

    1
    Comment actions Permalink
  • Avatar
    Firewalla

    We are testing it now, hopefully, it will go to beta soon ... the Quarantine group policy can be defined by you.  

     

     

    2
    Comment actions Permalink
  • Avatar
    valmikam

    Any updates on this? Without this feature, my Gold will sit on the shelf, heating up and smelling like burnt plastic but not being useful in the process :-(

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    As of today, 8/25/2020, the code is ready, and it is getting staged into early access release.   The team got tied up with Indiegogo Gold support cases ...  So we decide to push back the release until we can take a breath.   If you are interested, please sign up for early access on the gold https://help.firewalla.com/hc/en-us/community/posts/360046872134-Early-Access-Onboarding

     

    1
    Comment actions Permalink
  • Avatar
    valmikam

    Thanks for the quick reply. Signed up for early access. Please drop a note here when the feature is available in early access.

    Do I need a different version of mobile app as well?

    0
    Comment actions Permalink

Please sign in to leave a comment.