Security Review / Firewalla Threat Intelligence Validation Request
We are currently evaluating the integration of Hagezi's Threat Intelligence Feeds into Firewalla as an additional DNS-based threat intelligence source.
Before enabling this feed, we would like to understand the validation workflow and any potential privacy or data exposure concerns.
Specifically, could you please clarify the following:
- When an end user accesses a website or domain, does Firewalla validate the request locally against the downloaded threat intelligence feed, or are DNS/domain queries sent externally to the Hagezi service for validation?
- Is any user browsing information, domain lookup data, or network telemetry shared with Hagezi during the validation process?
- Are visited domains, including business-related sites, stored, logged, or retained by any external provider as part of this feed?
- Does enabling this feed introduce any data privacy, compliance, or information exposure risks?
- Is the threat intelligence list downloaded and maintained locally on Firewalla, or does it require real-time communication with third-party infrastructure?
Our goal is to ensure that enabling this feature helps improve protection against malicious domains, phishing, malware, and command-and-control traffic without introducing unnecessary privacy or compliance concerns.
Kindly share the architecture, validation workflow, and any privacy-related considerations before we proceed with implementation.
-
Firewalla does not share anything with anyone outside of the Firewalla company. For privacy and cloud usage, please see this article https://help.firewalla.com/hc/en-us/articles/360012760073-Questions-related-to-privacy-and-data-visibility
Everything should be happening locally inside your firewalla box. And in case there is an overflow, firewalla cloud is used as a backup. (this is the reason we don't allow arbituary lists getting installed, they do cost memory)
Please sign in to leave a comment.
Comments
1 comment