Feature Request: Replace MSP with a Native Local Web GUI for Desktop Administration
I’d like to propose introducing a dedicated, local-only web management interface for Firewalla devices, rather than relying on cloud-hosted portals.
A few key reasons why a native local interface is essential for desktop management:
-
Avoiding Artificial Subscription Barriers: Desktop management currently requires the Firewalla MSP subscription, even though the portal simply reads data that already resides on the local router. Users shouldn't need a recurring cloud subscription just to manage local hardware from a PC.
-
Industry Standard Functionality: Dedicated local web GUIs are the standard across enterprise and consumer networking appliances. Requiring external cloud portals and third-party auth services for basic desktop access adds unnecessary single points of failure.
-
Hardware Capability: Modern Firewalla appliances have more than enough processing power and memory to host a light, responsive web server directly on the device.
Restoring direct, local-first administration would give desktop users a secure, self-contained, and subscription-free way to manage their networks.
-
When we started the project, we want everything to be simple and also powerful, this is where the "app" is coming from.
Why not a local web? or even cli? If I remember correctly, we want the presentation layer (UI) to be separate from the control logic, meaning, they should never be running on the same box. The reason is, a lot of the attacks are often web based, and to keep another layer (web) will take a lot more effort and time to have it separate from the "security" part of the box.
The MSP interface (https://firewalla.net) is a standalone interface, which at the moment only cost $4 a month, and has a lot more functions beyond just a simple management interface. (Like AI and also another security engine that can loop through 30 or 180 days of data)
-
Would not running the UI in a container solve the same machine issue, as virtual machines are more often than not, more secure than the physical hardware running them? I mean these boxes are forced to have open ports to the whole wide internet because of the usage of 3rd party services to create and maintain the connections for MSP... Would it not be more secure to not have these forced connections, and have them only accessable from the local lan?
And on another note, all this forced AI integration and people will soon be lumping you in with M$ and Copilot... or Google/Chrome with the 4gb AI model...
I mean we paid a premium price for top end gear... Should the interface not match what we paid for? When the company started... running the software on a raspberry pi, where the system barely had enough power to route the network traffic, a separated system made sense... We are well past those days... these are not little $35 SOCs... You are averaging what? around $600ish - $1000ish... for that price I shouldn't even be asked about a subscription for software that should be built into the system... -
OK... You can edit the votes all you want... You expect me and other people to believe that users are all for paying a subscription to use something that is for features like being able to configure your router? Features that are built into 99.9% of routers that they don't charge you extra for?
You forget all the requests for this feature I have seen posted, that have mysteriously disappeared, or were never made live to the forum users... but were somehow downvoted...
What is the point of forums if you disrespect your users to such an extent...
For some reason you make me think of this: https://www.youtube.com/watch?v=NqcWFRy7Gx8
(and lets not forget the 'for the moment it costs...' so clearly the price for something that should be free, and built into the router is going up...) -
I know...
system load 0.47 Memory usage 32% Processes 306 swap 0%
I mean... no way nginx would have any room to run there...
secure behind the firewall... inaccessable from the wan...
unless you guys mean to state that the firewalla is actually insecure... I mean the default user is still 'pi'
I mean SSH daemon is always running and you guys can manage to keep it isolated from the WAN... -
It sucks that we are asked to pay on top of the $1,000 for a premium box to use a web UI. To add insult to injury, we are given BS reasons above as to why it lowers the security posture to do so. The APIs are already on the box. That's how MSP manages the box. What on earth are you talking about? Even Fortigate provides that on a box that costs less than the Gold Pro version. I am starting to look around for alternatives now.
-
Unfortunately, I agree. When I purchased (Gold Pro) nearly a year back, there was what looked like a local UI in progress. The phone app would be nice as a supplementary interface, but it's incredibly limiting when it comes to practical usage. When the new direction for the MSP was announced, I felt like my own data was being sold back to me, which has left me frustrated. Well, "betrayed" is much more accurate. With so many companies pushing people into unnecessary subscriptions and generally taking advantage of people, it was incredibly disappointing to see and I considered selling my appliance off and just moving to OPNsense.
I'm typically pretty unforgiving when I feel like a company's burned me and I usually do immediately cut ties, no matter the cost or effort involved, and never return, BUT I realize a company like this, that relies mostly on 1-2 product sales per average customer... a reasonable subscription is a sensible way to assure ends meet. Since the pricing is reasonable, I went ahead and went against my stubborn instincts for the first time, probably ever, and went with the $5/month subscription. I'm still on the fence though, if I'm honest. I still haven't shaken the feeling that I've been taken advantage of.
I'd absolutely still prefer a local-only UI. I'm not comfortable with sharing my data with ANY company, especially not the ins and outs of my damn router.
If there had been had been a local web UI that allowed column sorting, filters, typing with a damn keyboard (I can't overstate how much I hate phone keyboards), and so on, but MSP offered additional useful features, I'd have likely subscribed, but without the bitter aftertaste.
Please sign in to leave a comment.
Comments
8 comments