Emergency Access (on a divide) bypasses “Traffic to All Local Networks” (on a network) rule
Device: Firewalla Gold (1.983)
On a Firewalla-managed Untrusted VLAN, a network-level rule blocks Traffic to All Local Networks and is applied always.
A test device is connected through a switch access port whose native VLAN is the Firewalla Untrusted VLAN. The target is in a separate Firewalla-managed VLAN with a different private subnet.
Expected behavior: According to Firewalla’s documentation, “Outbound Local Traffic Blocking Rules” are Not Paused when Emergency Access is enabled. A new TCP connection from the Untrusted-VLAN device to the target VLAN should remain blocked.
Actual behavior: With Emergency Access disabled, the cross-VLAN TCP connection is blocked. With Emergency Access enabled for the device, a new TCP connection to a controlled HTTP listener on TARGET-IP:9876 succeeds.
This makes Emergency Access bypass the documented local-VLAN isolation rule.
Please confirm whether this is a bug or whether there is an undocumented condition that causes an “All Local Networks” rule not to apply.
-
Thanks for flagging this. Pausing local traffic blocking rules, VqLAN, and Device Isolation when Emergency Access is enabled was an enhancement introduced in 1.983. With Emergency Access on, no local blocking rules are enforced; this lets you temporarily bypass local rules to debug connection issues.
The documentation is outdated, we'll get it updated soon.
Please sign in to leave a comment.
Comments
2 comments