Questions tagged [watchguard]

Watchguard make firewalls and other network devices, and related management and monitoring software.

Watchguard (http://www.watchguard.com) is an American network security company, which creates firewalls, wireless access points and associated network security devices, management and monitoring software.

Their main products include:

The Watchguard XTM firewall range

These are targeted at small to medium businesses, and they focus on being feature-rich with network features (site-to-site VPNs, remote user VPNs, firewall clustering, multiple WAN connections, VLANs, QoS and bandwidth reservations, bandwidth limits and very configurable firewall policies), high level control and monitoring of network traffic and internet use (website blocking by category, specific application blocking, per-user and per-group policies) and defense-in-depth with integrated security services (AntiVirus, AntiSpam, Intrusion Prevention signatures, deep packet inspection and protocol analysis for HTTP/HTTPS/FTP/DNS/etc.).

Watchguard firewalls are available as small office devices (XTM 2 and XTM 3 series) with optional integrated WiFi, fullsize rackmount devices for central offices and datacenters (other XTM and M devices), and as virtual machines (the XTMv range) for VMware and Hyper-V deployment.

Their business model is to have a standard firewall software offering, with the more advanced features available by purchasing licensing upgrades, and to have the same management tools, configuration format and monitoring apply up and down the hardware range. The hardware range is differentiated by processing power, memory and number of interfaces of different speeds, although some of the advanced features are unavailable on the smallest models or the XTMv virtual firewalls.

Watchguard XCS Range

The XCS devices are dedicated email filtering devices, with detailed control of users and groups, attachments, content scanning and filtering.

Watchguard AP range

These are wireless access points]1 designed to be used with a Watchguard firewall. The configuration is done as part of the firewall configuration and the access points pick up their settings from the firewall.

Watchguard SSL range

Dedicated SSL VPN portal device for end user access to a central site. They offer The features in these are increasingly included in by the newer firewall firmwares,

Their software includes

Watchguard System Manager

The desktop version of the firewall management software, it comes in two parts - firebox system manager for connecting to a firewall and seeing live status, traffic log messages, running diagnostic commands, and policy manager for editing the firewall policies and general device configuration.

Their firewalls also have a web interface for policy configuration, which is increasingly where Watchguard's focus is going.

Watchguard Dimension

A virtual machine appliance which integrates logging from Watchguard firewalls, alerting from those logs, and analysing the logs and presenting a web interface of the results.

The analysis covers things like bandwidth use per policy, per host, per server, per connection type. Internet access / website use per user or group. Numbers of connections per policy. Attacks detected, and their sources. Usage levels at different times of day, and so on.

Watchguard LogServer and ReportServer

These are Windows services which accept encrypted logging connections from Watchguard firewalls and store them in a PostgreSQL database, it can send email email alerts on firewall log events.

ReportServer analyses the logs and generates reports of internet traffic use, bandwidth use, and so on.

Both of these are being replaced by Watchguard Dimension.

Watchguard Central Management Server

A Windows service which manages firewalls, giving a single place to connect to for firewall management. It can save configuration revision histories, show diffs, and allow configuration rollback, schedule configuration changes and firmware upgrades, and has some support for firewall policy templates and VPN templates.

Utility software

Single-Sign-On helper services, for installing on Windows domain controllers, desktops, and Exchange servers - usable in different combinations to support different ways the firewalls can detect which network traffic is linked to which users and mobile devices.

SSL VPN Client - a VPN client for laptop and desktop users connecting to the SSL VPN service on Watchguard firewalls.

111 questions
2
votes
2 answers

Kernel Printk: xx message suppressed

Hi I have a watchguard firewall, and I lost access to the firewall before xmas, therefore I visited the site, upgraded the firewall to the latest firmware but unfortunatly, I am now having similar issues where I will lose access to the firewall,…
Kevin
  • 87
  • 1
  • 7
2
votes
1 answer

IPSec VPN between Amazon VPC and a Watchguard XTM?

I have a branch office behind a Watchguard XTM that needs VPN into an EC2 VPC. I am unfamiliar with Watchguard and am unable to find all of the knobs and dials in the flash admin interface to bring it in line with Amazon's expectations. After much…
allaryin
  • 323
  • 4
  • 10
2
votes
2 answers

Firewall policies don't apply to ping/tracert attempts?

I know next to nothing about networking so apologies if this is a stupid or strange question. Our systems administration/IT support is outsourced to a consulting company. I was working with them to try and figure out a routing issue. We have…
John Straka
  • 200
  • 1
  • 11
2
votes
2 answers

Watchguard Firewall WebBlocker Regular Expression for Multiple Domains?

I'm pretty sure this is really a regex question, so you can skip to REGEX QUESTION if you want to skip the background. Our primary firewall is a Watchguard X750e running Fireware XTM v11.2. We're using webblocker to block most of the categories,…
bopapa_1979
  • 439
  • 1
  • 5
  • 12
2
votes
3 answers

Can connect through Watchguard mobile VPN, but can't ping or access network drives

We're having any issue in which some of our employess can no longer connect to our network drives when out of the office. We use Watchguard Mobile VPN (we have a Watchguard Firebox firewall) and the users are able to connect. That is, their status…
johnnyb10
  • 655
  • 4
  • 13
  • 28
2
votes
1 answer

Watchguard config, drop-in or mixed-routing mode?

I have a Watchguard XTM 2 that is currently acting as a firewall and a router for my business network, I currently have the WG setup in mixed-routing mode and am happy with the current configuration. The reason I am curious about drop-in mode is…
vfilby
  • 177
  • 2
  • 3
  • 9
2
votes
1 answer

Firebox 1250e Core Failing?

We have 2 Firebox 1250e Core firewall boxes in our production environment, serving as an active and passive mode. A few months back, the active box was flashing a warning light, so our consultant removed it, and plugged it in to a test network.…
Noah
  • 153
  • 1
  • 7
2
votes
1 answer

Block web browsing by older browsers

Given the vulnerabilities in older versions of IE, I want to enforce a rule that only the latest IE or Firefox is used to browse the web. I can't ensure that everyone's PC is up to date, so is there a firewall that will let me write a rule to…
Eamon
  • 63
  • 8
1
vote
2 answers

Watchguard SNAT not working

We are currently changing our external IP Address and trying to setup external access to your internally hosted website again without much luck. We use Go Daddy as our DNS host for our web domain and we use Watch Guard as our internal firewall. We…
Michael
  • 11
  • 2
1
vote
0 answers

Why is Watchguard dropping an open TCP connection?

We are using Watchguard version T35-W. When our system is under heavy load, we sometimes see active TCP client connections are dropped and become black holes. We think that this has something to do with the Per Client Quota global setting. We…
1
vote
0 answers

Traffic is not routing through Watchguard branch office vpn to Amazon aws VPN

Following this guide, I have successfully (I think) created a connection between my Watchguard physical VPN and an Amazon-VPC with a VPN attached to it but I cannot ping my EC-2. Amazon is setup as follows: My VPC has a VPN with a customer…
Josh S.
  • 11
  • 4
1
vote
0 answers

Watchguard Web UI Authentication with Active Directory user

Our WatchGuard firebox is configured to use active directory to authenticate VPN users. With Watchguard products, is it generally possible to use active directory to authenticate users that are attempting to configure the firewall itself, via the…
Ronnie Overby
  • 681
  • 2
  • 12
  • 24
1
vote
3 answers

Merge VPNs of two Watchguard firewalls into one firewall

I have two different Watchguard XTM 515 firewalls. Each has it's own set of VPNs created in them. Now I need to use only one firewall to handle the VPNs of both. But the problem is that I don't know the PSK of VPNs (I inherited those firewall after…
Hemant
  • 229
  • 1
  • 3
  • 12
1
vote
2 answers

Hyper-V DMZ environment

Im facing some problems trying to create a DMZ virtual machine in Hyper-v. Firstly, i want to create a DMZ so the company's smartphones can be managed remotely.We have an ESET ERA server installed, so we want to install the Mobile Device Connector…
Alex E.
  • 49
  • 5
1
vote
1 answer

Best way to connect dual SSID / VLAN wireless to Watchguard firewall

I'm currently sorting out our network so we can have new wireless access points with dual SSIDs, one for internal use and one for guest use. These will be setup so each SSID is on a different VLAN. I'm connecting them all to a PoE switch. Note, the…
george
  • 71
  • 8