Abnormal upload alarm about firewalla device
I received an abnormal upload alarm from the Firewalla device itself. I see posts indicating that it's normal for the Firewalla device to upload to firewalla.encipher.io, but this abnormal upload was to 100.25.83.65, which appears to be an AWS address in Virginia. Should I be concerned about this?
Thanks...
-
If you do not have VPN enabled, the other possibility is packets are routed via the tunnel interface inside the firewalla box, which makes the traffic look like firewalla. Since we may be asking a few private details of your network, I have created a case on this. Will follow up with you there.
-
Quick summarization of what we have found; The problem here is a bug in the Firewalla software, which happens when upload alarm was generated, it was looking in the past 8 hours window. And it just happens the IP address of the device who generated that alarm 8 hours ago, now assigned to Firewalla. (And at the moment of the alarm, the IP address of the device changed to a different one).
We have created an issue and see if we can better take care of this condition.
Please sign in to leave a comment.
Comments
4 comments