The most common real-world Firewalla question isn’t about Firewalla at all — it’s about the mesh system you already own. You bought an eero or a Deco because the WiFi is effortless, then read our Firewalla coverage and wondered: do I have to throw away the mesh to get the firewall?
No. Keeping both is the standard setup — but only one arrangement of the two boxes works well, and the internet is full of the other one. Here’s the config that works, in the order that avoids the classic trap.
The mental model: one router per network
Both your mesh and your Firewalla can be routers. Networks want exactly one router. Every bad experience with this combo — broken port forwarding, gaming NAT errors, devices that can’t see the printer, VPNs that half-work — comes from accidentally running two, a condition charmingly known as double NAT.
So the decision is just: who routes? Two clean answers:
Option A — Firewalla routes, mesh becomes dumb(er) WiFi. Firewalla in Router mode behind your modem; the mesh switched into bridge/AP mode, doing WiFi only. Full Firewalla feature set, single NAT, textbook clean.
Option B — Mesh routes, Firewalla observes in Bridge mode. The Gold-class Firewallas can sit between modem and mesh as a transparent bump in the wire, inspecting everything while the mesh keeps routing. Keeps every mesh feature intact (eero’s app, HomeKit integration, etc.), still gives you monitoring, blocking and alarms.
Which one? If your mesh’s smart features matter to you (or the household would riot if the eero app changed), choose B. If you want maximum Firewalla control — VLANs, policy routing, VPN server — choose A. When in doubt, B is the gentler surgery; you can graduate to A later.
Setup order for Option B (the popular one)
The order matters more than the steps — do it in this sequence and the trap can’t spring:
- Note how your mesh gets internet (most home cable/fiber: DHCP, nothing to note).
- Power everything down. Modem, mesh, kettle on for morale.
- Cable the chain: modem → Firewalla’s WAN-side port; Firewalla’s LAN-side port → your mesh gateway’s WAN port.
- Power up in order, waiting each time: modem first, Firewalla second (set to Bridge mode in the app during onboarding), mesh last.
- Confirm single NAT: in the mesh app, its WAN address should be a public-looking IP, exactly as before Firewalla arrived. The Firewalla app should now be enumerating your devices as they chat.
Nothing about your WiFi changed — names, passwords, guest network all intact. The house notices nothing. You, meanwhile, now have per-device visibility and blocking on a network that previously offered “the light is white, so probably fine.”
Setup order for Option A
Same cabling, different modes: Firewalla onboards in Router mode; then in the mesh app, find bridge/AP mode (eero: Settings → Advanced → DHCP & NAT → Bridge; Deco: More → Advanced → Operating Mode → Access Point) and switch it. Reboot the mesh. All routing duties — DHCP, VLANs if you build them, VPN — now belong to Firewalla; the mesh purely paints the house with WiFi.
Fair warning on the trade: in AP mode, mesh vendors disable chunks of their app (eero’s own security extras, some parental toggles). That’s not a bug — those duties moved to Firewalla, which does them better anyway. But it’s why Option A households should pick one brain for parental controls, not two half-engaged ones.
The trap, explicitly
The broken setup we keep seeing: Firewalla in Router mode AND the mesh still in router mode. Symptoms: everything sort of works, then port forwarding doesn’t, game consoles complain about “NAT Type,” the Firewalla sees only one mysterious device (the mesh) instead of your actual gadgets, and someone concludes the product is junk. If your Firewalla device list shows one device where forty should be — this is you; revisit the mode choice.
Does it slow anything down?
On a Gold SE with a gigabit plan: no measurable difference in our speed tests, with full inspection on. The Purple SE tops out around 500 Mbps of inspected throughput — right-size the box to your plan, or see the SE vs Pro breakdown for the multi-gig cases. WiFi speed is unchanged either way; that’s still entirely your mesh’s department.
Mesh for coverage, Firewalla for eyes. It’s the rare “have both” answer in networking that isn’t a compromise — provided exactly one of them is steering.
