Quote from: defaultuserfoo on Today at 03:20:50 AMI always read the notes that are being shown when I'm about to update. I don't recall any mentioning of the new rules at all, though my memory isn't what it used to be.
Yet if there had been a suitable warning about the new rules like I suggested in my previous post, I would have remembered it.
Quote from: Netlearn on Today at 02:17:58 AMo The firewall migration page is not something you need to jump into right away. Please make yourself familiar with the new rules GUI first and check the documentation for incompatibilities. Single interface from the floating interface will not be considered "floating" in priorities.
Quote from: defaultuserfoo on Today at 03:20:50 AMThis just has been handled badly.
Quoteno more warning than to back up your configuration and/or to take a snapshotIf you are not taking a snapshot before any similar system modification then you are making a mistake with which I cannot otherwise help you.
QuoteIf the Dirigera has no internet access, how can devices behind it have internet?
QuoteI shouldn't have assumed how your environment is.
Quote from: barney on Today at 03:39:44 AMNot sure what you mean here - the Dirigera is on the IoT VLAN?I didn't notice that. I'm sorry.
Quote from: barney on Today at 03:39:44 AMI don't generally 'constrain' anything directly. I log the default block rules and only create specific allow rules to pass the things I need. The only block rules I generally have are to intercept-and-not-log noisy clients before they get to the default block rule and get logged.
Quote from: barney on Today at 03:39:44 AMAlso, just to note, the block rule you suggest would only capture traffic from the Dirigera itself, not from the thread devices behind it.
Quote from: OPNenthu on April 21, 2026, 05:56:09 AMBy necessity of your design, since you split the hub off to a separate VLAN
Quote from: OPNenthu on April 21, 2026, 05:56:09 AMif you really must constrain it and its downstream devices to the IOT network
Quote from: mooh on April 21, 2026, 02:44:35 PMDon't worry about the thread devices. They only know the thread network and can't get out.
...
One of the recent revisions of Matter introduced a feature to allow Matter devices to communicate with the world.
{
"productName": "ALPSTUGA air quality monitor",
"hardwareAddress": "c2be2a915b99fd5c",
"iPv4Addresses": [],
"iPv6Addresses": [
"fde60a8291c018d8000000fffe002c00",
"fd2cd79a65f90001a09ba0cb1f92985d",
"fde60a8291c018d8d392333ab2732096",
"fe80000000000000c0be2a915b99fd5c"
]
}Quote from: Netlearn on Today at 02:17:58 AMPlease, read the release notes before upgrading. They are posted on a dedicated section of this forum and they are showed to the admin before upgrading, either by GUI or console.