Questions tagged [watchguard]

Watchguard make firewalls and other network devices, and related management and monitoring software.

Watchguard (http://www.watchguard.com) is an American network security company, which creates firewalls, wireless access points and associated network security devices, management and monitoring software.

Their main products include:

The Watchguard XTM firewall range

These are targeted at small to medium businesses, and they focus on being feature-rich with network features (site-to-site VPNs, remote user VPNs, firewall clustering, multiple WAN connections, VLANs, QoS and bandwidth reservations, bandwidth limits and very configurable firewall policies), high level control and monitoring of network traffic and internet use (website blocking by category, specific application blocking, per-user and per-group policies) and defense-in-depth with integrated security services (AntiVirus, AntiSpam, Intrusion Prevention signatures, deep packet inspection and protocol analysis for HTTP/HTTPS/FTP/DNS/etc.).

Watchguard firewalls are available as small office devices (XTM 2 and XTM 3 series) with optional integrated WiFi, fullsize rackmount devices for central offices and datacenters (other XTM and M devices), and as virtual machines (the XTMv range) for VMware and Hyper-V deployment.

Their business model is to have a standard firewall software offering, with the more advanced features available by purchasing licensing upgrades, and to have the same management tools, configuration format and monitoring apply up and down the hardware range. The hardware range is differentiated by processing power, memory and number of interfaces of different speeds, although some of the advanced features are unavailable on the smallest models or the XTMv virtual firewalls.

Watchguard XCS Range

The XCS devices are dedicated email filtering devices, with detailed control of users and groups, attachments, content scanning and filtering.

Watchguard AP range

These are wireless access points]1 designed to be used with a Watchguard firewall. The configuration is done as part of the firewall configuration and the access points pick up their settings from the firewall.

Watchguard SSL range

Dedicated SSL VPN portal device for end user access to a central site. They offer The features in these are increasingly included in by the newer firewall firmwares,

Their software includes

Watchguard System Manager

The desktop version of the firewall management software, it comes in two parts - firebox system manager for connecting to a firewall and seeing live status, traffic log messages, running diagnostic commands, and policy manager for editing the firewall policies and general device configuration.

Their firewalls also have a web interface for policy configuration, which is increasingly where Watchguard's focus is going.

Watchguard Dimension

A virtual machine appliance which integrates logging from Watchguard firewalls, alerting from those logs, and analysing the logs and presenting a web interface of the results.

The analysis covers things like bandwidth use per policy, per host, per server, per connection type. Internet access / website use per user or group. Numbers of connections per policy. Attacks detected, and their sources. Usage levels at different times of day, and so on.

Watchguard LogServer and ReportServer

These are Windows services which accept encrypted logging connections from Watchguard firewalls and store them in a PostgreSQL database, it can send email email alerts on firewall log events.

ReportServer analyses the logs and generates reports of internet traffic use, bandwidth use, and so on.

Both of these are being replaced by Watchguard Dimension.

Watchguard Central Management Server

A Windows service which manages firewalls, giving a single place to connect to for firewall management. It can save configuration revision histories, show diffs, and allow configuration rollback, schedule configuration changes and firmware upgrades, and has some support for firewall policy templates and VPN templates.

Utility software

Single-Sign-On helper services, for installing on Windows domain controllers, desktops, and Exchange servers - usable in different combinations to support different ways the firewalls can detect which network traffic is linked to which users and mobile devices.

SSL VPN Client - a VPN client for laptop and desktop users connecting to the SSL VPN service on Watchguard firewalls.

111 questions
1
vote
0 answers

Watchuguard access to external server from internal network

It looks, like my problem is common, I tried every single hint I found, but nothing is working. Here is my problem. I have an internal network behind Watchguard m400, with few VLAN's on ports. I need access from my internal network (addresses…
Kai
  • 33
  • 1
  • 10
1
vote
0 answers

Firebox x700 Reset to Default Not Working

I found a site that explains how to reset a Firebox 700 series back to default as you can see from this link: https://www.hashdoc.com/documents/7502/how-to-default-a-watchguard-firebox-700-or-x700 Everything works fine. I setup a separate…
stevenvog9
  • 11
  • 4
1
vote
2 answers

Watchguard VLAN Head-Grasping needed

I am trying to wrap my head around setting up my new watchguard M400. Here's what I need to figure out and what I've done so far. My ISP provided me with a P2P IP, which I plugged into my interface (107. address). They also have me a block of IPs on…
1
vote
2 answers

Watchguard Mobile VPN with SSL - user can't connect - failed to open shared memory for openvpn command (error: 2)

I have a problem with my Watchguard VPN. I've set up the device for SSLVPN (added policies, users, a group etc.) according to this description from the Watchguard docs. The authentication itself works (no error about wrong login info with proper…
Christian
  • 199
  • 1
  • 2
  • 9
1
vote
1 answer

Proxy action for user-agent blocking with regular expressions not blocking

I have a server behind a Watchguard XTM firewall and want to block incoming RESTClients who has certain user-agents in their request headers. I have implemented several rules to do this: List image Here's one example of how I implemented them: Regex…
OHMR
  • 133
  • 4
1
vote
1 answer

WatchGuard Authentication equivalent with Cisco ASA X series

I am in the process of implementing Cisco ASA 5512-X devices with FirePOWER to replace WatchGuard firewalls. The WatchGuard devices in use are currently wrapping access to various services with a dynamic access list feature of WatchGuard called…
1
vote
1 answer

Watchguard BOVPN tunnel not connecting

I recently added a new subnet of servers in a remote site and tried to add a VPN tunnel to access them. The VPN connection was previously in use and is working for some of the routes but not all. I have Watchguard x5500 at both sites. The Office…
Ross
  • 71
  • 1
  • 6
1
vote
2 answers

How do I correct/set/syncronize time on Watchguard Firebox X500?

Looking at the logs on my firewall in realtime it appears that the time is slow by about 13 minutes. I might not have noticed but I'm troubleshooting a lan to lan VPN connection. It may be purely cosmetic or it might actually be an issue if the time…
pplrppl
  • 1,242
  • 2
  • 14
  • 22
1
vote
2 answers

OWA through a Watchguard Firebox 550e using Fireware XTM v11

I have just implemented a watchguard firebox 550e on my network. I can access the OWA (exchange 2003) without an issue from within the network. When I access it from outside, I login and a folder list appears on the left, but every view on the…
RoseofPurple
  • 106
  • 2
  • 5
1
vote
1 answer

External VPN users cant access mapped network drives with Name have to use IP address

It's not a massive problem but some users complain they can't access our storage drive when working externally across the VPN. For instance, internally they can type \\storageserver\adminfolders and it works with no problem. But externally it won't…
GordonBpdZenith
  • 67
  • 1
  • 11
1
vote
1 answer

Does the TCP-UDP-Proxy policy in Watchguard open me to security problems?

I don't remember seeing this policy since it seems to me like an "all ports open" kind of thing. It is set default "tcp:0(any) - udp:0(any)" If I disable this, even web traffic wouldn't work although I specifically have the HTTP-proxy policy…
Seth
  • 334
  • 2
  • 9
  • 21
1
vote
1 answer

Network Performance Issues w/ Watchguard XTM 23

I'm in charge of maintaining a small network for a client (around 10-15 computers) that has an internet connection to the outside world of 100mbps (ironically, though, I just ran a speedtest bypassing the firewall completely, and got…
David W
  • 3,405
  • 5
  • 34
  • 61
1
vote
2 answers

Watchguard Firebox "split" fibre optic line into 2 interfaces

We have a requirement on our Watchguard Firebox XTM505 to be able to split our incoming external interface, in this case a fibre optic dedicated leased line, 100/100. We use the line in our office of approx 30 machines however we also re-sell to an…
fRAiLtY-
  • 83
  • 1
  • 2
  • 9
1
vote
1 answer

Watchguard XTM Internal Policy Denial

Question on Watchguard XTM policy not allowing some traffic through. I have setup in Policy Manager named "TCP - NAS" that allows all TCP ports from External to SNAT from 192.168.10.13 -> 192.168.60.4 but am puzzled at why it's blocking some…
user192702
  • 921
  • 4
  • 15
  • 22
1
vote
0 answers

Watchguard - passwordless SSH login to block/ban IP addresses

I have Watchguard XTM22-W as my firewall. On it there are few 1-to-1 NAT policies through which I access local services (mainly SSH on different machines). All these machines have Fail2Ban installed and send everything to a central log server. All…
grs
  • 2,235
  • 6
  • 28
  • 36