Abnormal upload alarm about firewalla device

Comments

4 comments

  • Avatar
    Firewalla

    Very likely this is the traffic from VPN.  And due to how we accounting things, the device from VPN is all from Firewalla.  We will likely start to mask this and then fix the name in the coming versions. 

    0
    Comment actions Permalink
  • Avatar
    Mark Canup

    Thanks for your response. That would make sense, except that I don't have VPN enabled.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    If you do not have VPN enabled, the other possibility is packets are routed via the tunnel interface inside the firewalla box, which makes the traffic look like firewalla.   Since we may be asking a few private details of your network, I have created a case on this.  Will follow up with you there.

     

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Quick summarization of what we have found;  The problem here is a bug in the Firewalla software, which happens when upload alarm was generated, it was looking in the past 8 hours window.   And it just happens the IP address of the device who generated that alarm 8 hours ago, now assigned to Firewalla.  (And at the moment of the alarm, the IP address of the device changed to a different one).  

    We have created an issue and see if we can better take care of this condition.  

    1
    Comment actions Permalink

Please sign in to leave a comment.

Powered by Zendesk