Questions tagged [watchguard]

Watchguard make firewalls and other network devices, and related management and monitoring software.

Watchguard (http://www.watchguard.com) is an American network security company, which creates firewalls, wireless access points and associated network security devices, management and monitoring software.

Their main products include:

The Watchguard XTM firewall range

These are targeted at small to medium businesses, and they focus on being feature-rich with network features (site-to-site VPNs, remote user VPNs, firewall clustering, multiple WAN connections, VLANs, QoS and bandwidth reservations, bandwidth limits and very configurable firewall policies), high level control and monitoring of network traffic and internet use (website blocking by category, specific application blocking, per-user and per-group policies) and defense-in-depth with integrated security services (AntiVirus, AntiSpam, Intrusion Prevention signatures, deep packet inspection and protocol analysis for HTTP/HTTPS/FTP/DNS/etc.).

Watchguard firewalls are available as small office devices (XTM 2 and XTM 3 series) with optional integrated WiFi, fullsize rackmount devices for central offices and datacenters (other XTM and M devices), and as virtual machines (the XTMv range) for VMware and Hyper-V deployment.

Their business model is to have a standard firewall software offering, with the more advanced features available by purchasing licensing upgrades, and to have the same management tools, configuration format and monitoring apply up and down the hardware range. The hardware range is differentiated by processing power, memory and number of interfaces of different speeds, although some of the advanced features are unavailable on the smallest models or the XTMv virtual firewalls.

Watchguard XCS Range

The XCS devices are dedicated email filtering devices, with detailed control of users and groups, attachments, content scanning and filtering.

Watchguard AP range

These are wireless access points]1 designed to be used with a Watchguard firewall. The configuration is done as part of the firewall configuration and the access points pick up their settings from the firewall.

Watchguard SSL range

Dedicated SSL VPN portal device for end user access to a central site. They offer The features in these are increasingly included in by the newer firewall firmwares,

Their software includes

Watchguard System Manager

The desktop version of the firewall management software, it comes in two parts - firebox system manager for connecting to a firewall and seeing live status, traffic log messages, running diagnostic commands, and policy manager for editing the firewall policies and general device configuration.

Their firewalls also have a web interface for policy configuration, which is increasingly where Watchguard's focus is going.

Watchguard Dimension

A virtual machine appliance which integrates logging from Watchguard firewalls, alerting from those logs, and analysing the logs and presenting a web interface of the results.

The analysis covers things like bandwidth use per policy, per host, per server, per connection type. Internet access / website use per user or group. Numbers of connections per policy. Attacks detected, and their sources. Usage levels at different times of day, and so on.

Watchguard LogServer and ReportServer

These are Windows services which accept encrypted logging connections from Watchguard firewalls and store them in a PostgreSQL database, it can send email email alerts on firewall log events.

ReportServer analyses the logs and generates reports of internet traffic use, bandwidth use, and so on.

Both of these are being replaced by Watchguard Dimension.

Watchguard Central Management Server

A Windows service which manages firewalls, giving a single place to connect to for firewall management. It can save configuration revision histories, show diffs, and allow configuration rollback, schedule configuration changes and firmware upgrades, and has some support for firewall policy templates and VPN templates.

Utility software

Single-Sign-On helper services, for installing on Windows domain controllers, desktops, and Exchange servers - usable in different combinations to support different ways the firewalls can detect which network traffic is linked to which users and mobile devices.

SSL VPN Client - a VPN client for laptop and desktop users connecting to the SSL VPN service on Watchguard firewalls.

112 questions
0
votes
0 answers

Deploying vhd from blob to Azure

We have some troubles in migrating VM(Linux) from local HyperV on Win 10 to Azure Cloud. We got a linux vhd - deploy it on HyperV - then save as static and upload to blob storade in Azure. Based on that - we make a new VM but it fails to…
0
votes
1 answer

watchguard port forwarding via SNAT

I have a problem with port forwarding on Watchguard. What I want? I need to access from Internet via public IP on different port (lets say 9999) to a Remote Desktop on a PC which is on local network (win 10). What I did? I created a SNAT policy,…
Artur
  • 21
  • 1
  • 1
  • 3
0
votes
0 answers

Watchguard - Configure custom domain IP resolve

A Watchguard firewall device used as DHCP server in a Local LAN office network. There is an internal web server pc connected within the same LAN. Lets say the website hosted in the web server accessible by entering this IP on any…
mjb
  • 171
  • 1
  • 1
  • 5
0
votes
2 answers

Ping responses don't make it back to mailserver behind watchguard firewall

Current suspect is the Watchguard Firewall. Most likely I am to blame as the person who edited the firewall rules. At a recent point in the past my company was on a different external IP address. I switched providers and thus changed external IPs.…
pplrppl
  • 1,262
  • 2
  • 14
  • 23
0
votes
1 answer

Watch Guard Total Security working over VPN

We have a warehouse and 4 other showroom locations. All the 4 locations are connect to the warehouse through a VPN. If we get a watch guard for each location and connect through a VPN. Would it be necessary to get the total security at all locations…
0
votes
1 answer

Is a Watchguard BOVPN or "site-to-site" VPN the best way to backup a server to a NAS at another location?

I currently have a customer who has two offices in separate cities. Each location has a Watchguard. They need a backup solution so we proposed a NAS to backup both servers to. The issue is the NAS will be onsite at one of the offices. I am trying to…
0
votes
1 answer

Port forwarding via Watchguard

I have problem with accessing oracle database with oracle SQL developer. I'm using Watchguard m400 as my firewall/router and Windows Server 2012 R2 as Oracle DB Server. I have server with local IP, lets say its 10.10.10.10, I NATted it with s-nat to…
jonhson
  • 1
  • 1
0
votes
1 answer

Watchguard blocking ports

I want to block the whole Internet for particular hosts. In this case I used policy 'Any" which basically blocks every single port (tcp+udp I believe). In FROM field I put particular IP address from host, and in TO I put any. I uploaded the config…
Kai
  • 33
  • 1
  • 10
0
votes
1 answer

Watchguard, accessing server with public IP from internal network

I can't go trough it. I need access from my internal network to a server with public IP. I have private network with few VLANs, and then I'm using Watchguard m400 firewall. The server, that I want to reach has only public IP. I can ping it from my…
Kai
  • 33
  • 1
  • 10
0
votes
1 answer

Lightswitch App AD authentication over SSL VPN

I have a lightswitch App (desktop app for windows) which authentications with AD against their logged in account, so the user doesn't need to log in again. This works great in the office but over the Watchguard SSL VPN in our office it doesn't work.…
dooglex
  • 1
  • 1
0
votes
2 answers

WatchGuard, external IP, different port

I have few external IP addresses, but I want to use one, and NAT to it different PC's. That's how it should look like. 123.123.123.123 that's my IP, and I want to have on it 3 PC's on different ports, for example 3111, 3112, 3113. I know how to NAT…
Kai
  • 33
  • 1
  • 10
0
votes
0 answers

Watchguard M400 Tagging VLAN

I have a problem with WatchGuard Firebox M400. I put interface 2 into VLAN mode. I created earlier few VLANs like: 10, 20, 30, 40, 110 and 199. When im puting those VLANs in that interface, i checked them all as TAGGED, then when I'm connecting a…
Kai
  • 33
  • 1
  • 10
0
votes
1 answer

Cannot access network resources once connected to VPN

To begin, it's important this excerpt is read and understood before anything is suggested: The VPN configuration has been untouched, as I'm the only admin user, and also the firewall itself has been powered up for over a year. This did work up until…
fRAiLtY-
  • 83
  • 1
  • 2
  • 10
0
votes
0 answers

Watchguard VPN Connection Issue

I am having problems setting up a BOVPN between an XTM510 and an XTM21-w. I have checked over the settings 3 times for all of the phases, tunnels and gateways on both sides and everything is correct. I checked the log files and did a search VPN and…
0
votes
1 answer

Malware lab with watchguard firewall

I have a quick question. This is more of a concept question than an actual problem, but basically what I'm trying to do is set up a malware analysis lab on one of my company's computers. I already have a base Windows machine with a bunch of VMs for…
ToxicProxy
  • 23
  • 2