Questions tagged [watchguard]

Watchguard make firewalls and other network devices, and related management and monitoring software.

Watchguard (http://www.watchguard.com) is an American network security company, which creates firewalls, wireless access points and associated network security devices, management and monitoring software.

Their main products include:

The Watchguard XTM firewall range

These are targeted at small to medium businesses, and they focus on being feature-rich with network features (site-to-site VPNs, remote user VPNs, firewall clustering, multiple WAN connections, VLANs, QoS and bandwidth reservations, bandwidth limits and very configurable firewall policies), high level control and monitoring of network traffic and internet use (website blocking by category, specific application blocking, per-user and per-group policies) and defense-in-depth with integrated security services (AntiVirus, AntiSpam, Intrusion Prevention signatures, deep packet inspection and protocol analysis for HTTP/HTTPS/FTP/DNS/etc.).

Watchguard firewalls are available as small office devices (XTM 2 and XTM 3 series) with optional integrated WiFi, fullsize rackmount devices for central offices and datacenters (other XTM and M devices), and as virtual machines (the XTMv range) for VMware and Hyper-V deployment.

Their business model is to have a standard firewall software offering, with the more advanced features available by purchasing licensing upgrades, and to have the same management tools, configuration format and monitoring apply up and down the hardware range. The hardware range is differentiated by processing power, memory and number of interfaces of different speeds, although some of the advanced features are unavailable on the smallest models or the XTMv virtual firewalls.

Watchguard XCS Range

The XCS devices are dedicated email filtering devices, with detailed control of users and groups, attachments, content scanning and filtering.

Watchguard AP range

These are wireless access points]1 designed to be used with a Watchguard firewall. The configuration is done as part of the firewall configuration and the access points pick up their settings from the firewall.

Watchguard SSL range

Dedicated SSL VPN portal device for end user access to a central site. They offer The features in these are increasingly included in by the newer firewall firmwares,

Their software includes

Watchguard System Manager

The desktop version of the firewall management software, it comes in two parts - firebox system manager for connecting to a firewall and seeing live status, traffic log messages, running diagnostic commands, and policy manager for editing the firewall policies and general device configuration.

Their firewalls also have a web interface for policy configuration, which is increasingly where Watchguard's focus is going.

Watchguard Dimension

A virtual machine appliance which integrates logging from Watchguard firewalls, alerting from those logs, and analysing the logs and presenting a web interface of the results.

The analysis covers things like bandwidth use per policy, per host, per server, per connection type. Internet access / website use per user or group. Numbers of connections per policy. Attacks detected, and their sources. Usage levels at different times of day, and so on.

Watchguard LogServer and ReportServer

These are Windows services which accept encrypted logging connections from Watchguard firewalls and store them in a PostgreSQL database, it can send email email alerts on firewall log events.

ReportServer analyses the logs and generates reports of internet traffic use, bandwidth use, and so on.

Both of these are being replaced by Watchguard Dimension.

Watchguard Central Management Server

A Windows service which manages firewalls, giving a single place to connect to for firewall management. It can save configuration revision histories, show diffs, and allow configuration rollback, schedule configuration changes and firmware upgrades, and has some support for firewall policy templates and VPN templates.

Utility software

Single-Sign-On helper services, for installing on Windows domain controllers, desktops, and Exchange servers - usable in different combinations to support different ways the firewalls can detect which network traffic is linked to which users and mobile devices.

SSL VPN Client - a VPN client for laptop and desktop users connecting to the SSL VPN service on Watchguard firewalls.

111 questions
0
votes
2 answers

WatchGuard blocking internal UDP packets

I'm seeing lots of packets that our WatchGuard firewall is dropping. They're all hitting either 255.255.255.255. or 224.0.0.1 using UDP 8612 / 1947 / 17500. Since I've started seeing these messages our internet seems a lot slower. How can I allow…
gvjonjones
  • 11
  • 1
  • 5
0
votes
2 answers

DNS servers trying to send data to Google+ - Google DNS

I was looking through my watchguard traffic today and noticed a lot of traffic going from my two local DNS servers to "Google-Plus". I'm assuming watchguard has that labeled incorrect as the IP addresses they are trying to connect to are the Google…
0
votes
2 answers

Routing between 2 networks and 2 routers

I have a WatchGuard XTM33 and a Cisco ASA 5505, current network is running off of the Cisco and I want to eventually migrate over to the WatchGuard using new IP scheme. ASA 192.168.111.1/24 WG 10.0.0.1/23 If I setup the WG and configure one of the…
nGX
  • 344
  • 1
  • 6
  • 19
0
votes
2 answers

Firewall Upgrade from Watchguard Firebox Core 550e

I'm looking for any Firewall recommendations that meet our requirements below. In one of our racks we're currently using a Watchguard Firebox Core 550e Firewall. It's served us well for the past few years but we're now in need of an upgrade. Our…
user2946
  • 263
  • 4
  • 8
0
votes
0 answers

Can I use both one-to-one NAT and port mapping on one Watchguard FireBox?

Old Watchguard III / 700. Is it possible to do both port mapping and one-to-one NAT? I recently changed ISP. Our external static range is a different range from the gateway subnet. Only way I could get it to work is to use one-to-one NAT for all…
Larry
  • 1
0
votes
1 answer

Clients intermittently cannot reach internal server, Windows network with Watchguard XTM

Small business has internal Windows network on a single subnet 192.168.16.x. There is a Watchguard XTM 330 firewall appliance which routes traffic to the internet. Leased line. Some users are having intermittent difficulty getting to an internal web…
timanderson
  • 263
  • 1
  • 4
  • 12
0
votes
0 answers

IPSEC VPN with same remote peer IP - Only 1 remote connection at a time

I am using a Mikrotik router to connect multiple road warriors (Avaya phones) with IPSEC VPN behind the same WAN address. The first phone connects fine, when the second phone connects the first phone looses network connectivity. This is due to the…
morleyc
  • 1,120
  • 13
  • 45
  • 86
0
votes
0 answers

Watchguard dimension backups

I've got a virtual machine with Watchguard dimension OS which writes a database backup every 7 days: I haven't checked for a couple of months but when I've logged on I've seen that the /var mountpoint is full and then is over a month that the vm…
AlexF
  • 103
  • 5
0
votes
2 answers

Firebox issuing incorrect DNS server over DHCP

I have had a Watchguard Firebox x55e since May w/o any issues. Upgraded to their new version 11 OS last Friday. We have two DNS servers specified for the external interface and have it handling DHCP. Yesterday morning it started issuing…
Charles
  • 23
  • 1
  • 6
0
votes
1 answer

WatchGuard XTM510, Dialed in VPN (PPTP) users cant Ping hosted datacentre machine on BOVPN

we have a BOVPN from our network 192.168.1.0/24 range to some hosted environments at a datacentre. 172.15.0.1/20 any machine on our internal network ranges can communicate with the systems at the data centre. Users remotely are dialing in onto the…
GordonBpdZenith
  • 67
  • 1
  • 11
0
votes
1 answer

How do I create a specific report on a Watchguard firewall?

I am trying to recover from the Cryptolocker virus, and keep getting blacklisted at CBL. I need specific communication data on ports above 1000. I do not see a way to setup a specific report of logging options. Is this possible to do? I have an…
Seth
  • 334
  • 2
  • 9
  • 21
0
votes
1 answer

Watchguard XTM blocking login attempts

routinely I'm seeing lots of login attempts to my mail server trying out various login names starting from A to Z coming from the one IP on one day and another IP on another day. Is there any means to detect this type of activities and block…
user192702
  • 921
  • 4
  • 15
  • 22
0
votes
1 answer

Watchguard Firewall SSLVPN

After running into some initial connection errors (which were resolved via Watchguard Firewall - Issues with SSLVPN), I'm able to accept the SSL certificate provided by the firewall and get further into the connection process / attempt. However, I'm…
David W
  • 3,405
  • 5
  • 34
  • 61
0
votes
4 answers

What are the instructions to reset a Watchguard Firebox X1000?

We had a Firebox X1000 model R6264S, and the power supply died. We purchased another one cheaply from Ebay, but I cannot find instructions anywhere about how to reset this device to factory defaults so I can reconfigure it. If anyone here has…
Jonathan Hickman
  • 33
  • 1
  • 1
  • 3
0
votes
2 answers

Separate WebBlocker settings, using one Watchguard XTM 505?

I support a school with 3 locations that uses a Watchguard XTM 505. They are implementing a BYOD wireless solution with Aerohive APs, and they will have 3 SSIDs (School, Guest, BYOD). Each SSID needs to have different WebBlocker permissions, how can…
msindle
  • 605
  • 8
  • 26