Feature requests and question

Comments

14 comments

  • Avatar
    Firewalla

    Abnormal uploads are historical ... and they also aggregate a bunch of flows.   You can see this https://help.firewalla.com/hc/en-us/articles/360020926913-Abnormal-Upload-Alarms-Tutorial

    The QR code scan should be fairly quick, if you can't scan it, likely there is a bug in the app.  Can you let us know what phone you have? 

    0
    Comment actions Permalink
  • Avatar
    Jim

    I am using a Samsung Galaxy S8, have been able to scan the code 2 times since receiving my Gold. 1st time took about 10 mins of patience, second time about the same amoun of time but got a ;Invalid QR code' and gave up.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Do you mean, when you scan the QR code, the phone is not able to pick it up?  I do remember there is an option when scanning to manually type (or cut/paste) the license in there.   

    0
    Comment actions Permalink
  • Avatar
    Jim

    No, this is the QR login when trying to use https://my.firewalla.com/#/login

    You seem to need to scan it in every time you try to use the web console.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Will ask our dev to check the Android phone on that 

    There is a timer on each login.  The reason for that is, when you scan that QR code, the web server will establish a secure link with your box directly.   And since there is an encryption key involved, we keep that key in memory and wipe it after a certain duration.  (The scan is the key exchange process).    

    0
    Comment actions Permalink
  • Avatar
    Dpadron

    Can we add a way to get to the web gui, though a LAN address like regular hardware?

     

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    @Dpadron,  Firewalla is definitely not a regular router that runs say *WRT* software.    The main reason for us to run the web interface in the cloud is to increase feature velocity or the speed for us to developed new things.  

    If the web UI runs on the unit, the release cycle will be 3 to 4 months.  (There is nothing bad about this since we are already far better than traditional hardware).   But having the UI running on my.firewalla.com, will enable us to add new features in less than a day. (+1 extra day for testing)

    For example, one of you wanted a 30-day bandwidth usage,  it took us two days to get the feature running; 

    Another benefit of having the web outside the unit also includes the traditional "access" from anywhere... which is much more difficult to do if you are running it on the unit. 

    0
    Comment actions Permalink
  • Avatar
    Dmavelar

    I just wanted to mention that if you mount the Firewalla with the included bracket, you can't get to the QR code in any reasonable fashion... 

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    The QR code after the scan is also in the app if you need it. 

    1
    Comment actions Permalink
  • Avatar
    Dmavelar

    Really cool, I hadn't seen the QR under "Allow Additional Pairing". 

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Don't use that one, that QR is limited to a short duration.  The License is 

    Tap on the gears button (top right)->tap on about ->license

     

    0
    Comment actions Permalink
  • Avatar
    Dmavelar

    Oooh wow, that is buried! So what's the intent for the one in additional pairing?

    0
    Comment actions Permalink
  • Avatar
    Chris Hewitt

    @Dmavelar you can print the QR code and put it on the front of the Firewalla if you really need to regularly get access to it. For the past three months I have never found a need to scan the QR code.

    @Firewalla, I love the security on the web interface. Please don't change anything. For me, on an iPhone, scanning the QR code is a sub-second activity. I basically just wave my phone in front of the screen and BLAMO. In my professional life I use Kibana, McAfee, Falcon, Fidelis and other tools that have all sorts of login machinations and require authentication tools. This is secure and easy. Please don't change it - and keep it in the cloud!

    0
    Comment actions Permalink
  • Avatar
    FF

    Hello all,

    I think there are several issues to segregate:

    1. QR code vs string vs... 
      obviously the QR code is just a "convenient" way to scan a string, there is nothing preventing firewalla to also add the string matching the QR code on the sticker which will go around the problem for people who don't have a compatible camera phone... 
    2. QR code usage:
      There is an interesting flaw often overlooked with static QR codes (and strings on stickers), they can be copied and reused... including remotely.... In fact, to use it securely, you would typically only make use of it in combination with an activity which requires physical access to the device (pressing the reset button). if not, there is little value in using the QR code and you would be better of leverage a string dynamically accessible through the app or the appliance (like the ssh password). The problem is not really an issue for home use, but it can be a showstopper for business use  where staff turnover.
    1
    Comment actions Permalink

Please sign in to leave a comment.