I think Firewalla just took down my network

Comments

9 comments

  • Avatar
    Wallace Mann

    Oh ... I have a Firewalla Gold sitting between a SURFBoard modem and a TP-Link ac4000 wifi / Linksys switch combo.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    There is no update to the Gold for sure.   If it happens again, I'd suggest do this (our standard tests)

    1. ping 1.1.1.1
    2. ping firewalla IP
    3. nslookup firewalla.com

    This will tell you which is broken. 

    1. ping 1.1.1.1 fails if ISP fail
    2. ping firewalla IP fails if firewalla is dead
    3. nslookup firewalla.com fails if the DNS system is dead

    There is also another possibility, which may trigger a bug in the Arris, which is timing related.   When your ISP is going up and down, which in certain cases the SURFBoard will assign a private IP to firewalla ... (this is a surfboard problem) 

    In general to fix this problem if you can try this

    1. Power off surfboard, wait a bit and power it on, wait until it is fully on, and connected.

    2. Power on Firewalla Gold 

    Above will ensure the surfboard not giving a private IP to firewalla Gold

    And if you want, you can open a case by sending an email to help@firewalla.com, we will be happy to look at the logs of the gold 

    0
    Comment actions Permalink
  • Avatar
    Wallace Mann

    Thanks for the suggestions.  I'll give that a try later today.

    W

    0
    Comment actions Permalink
  • Avatar
    Wallace Mann

    You mentioned the Arris bug.  Are there other cable modems that play nicer with Firewalla?  

    For example, my ISP lists the following as approved.  Off the top of your head, do you know if any of these would be better?

    • ARRIS SB6141 (my current)
    • ARRIS T25
    • ARRIS SBG8300
    • ARRIS SB8200
    • ASUS CMAX6000
    • HUMAX HGD310

    Thanks,

    Wallace

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    No idea, on the west coast, we are stuck with Xfinity ...  

    But in general, the ARRIS modems are not bad, it is just at times they give out the 192.168.100.x network address ... which throws a curveball ...

    0
    Comment actions Permalink
  • Avatar
    James Willhoite

    I too have Xfinity. My Firewalla Gold is set to Router mode. I have the ARRIS Surfboard (16x4) DOCSIS 3.0 Cable Modem, 686 Mbps Max Speed, Certified for Comcast Xfinity, Spectrum, Cox, Cablevision & More (SB6183 White) and I've had a issue in the past where my router (not Firewalla at the time) will lose power for a split second and then the ARRIS modem assign it the .100.x network like @Firewalla said. I bought a UPS to plug my modem and other networking devices in. We loose power briefly a lot where I live so it was always a headache to trouble shoot it, now I don't have to worry.

    Until Firewalla can push out the next version with the rate limit, I would suggest looking into the TP-Link EAP245 AP. I have this one for my network. I like it because I can create multiple SSID profiles on it, and set a rate limit for that profile. I have one for a "Guest" network that is limited to 10mbps. Might be good for the kids game devices (Wireless).

    0
    Comment actions Permalink
  • Avatar
    Wallace Mann

    Firewalla help got back to me and correctly diagnosed my problem as having entered a url (e.g., http://kid-gaming-site.com) instead of a domain into a domain level rule.  It's a known issue and it breaks DNS service.  Once I removed the "http://" everything worked fine.

    1
    Comment actions Permalink
  • Avatar
    Michael Bierman

    Good to know that you solved the problem. Hopefully in the future Firewalla will automatically strip schemes from rules automatically if they are a problem. 

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    That bug already fixed 1.971

    1
    Comment actions Permalink

Please sign in to leave a comment.