Questions tagged [watchguard]

Watchguard make firewalls and other network devices, and related management and monitoring software.

Watchguard (http://www.watchguard.com) is an American network security company, which creates firewalls, wireless access points and associated network security devices, management and monitoring software.

Their main products include:

The Watchguard XTM firewall range

These are targeted at small to medium businesses, and they focus on being feature-rich with network features (site-to-site VPNs, remote user VPNs, firewall clustering, multiple WAN connections, VLANs, QoS and bandwidth reservations, bandwidth limits and very configurable firewall policies), high level control and monitoring of network traffic and internet use (website blocking by category, specific application blocking, per-user and per-group policies) and defense-in-depth with integrated security services (AntiVirus, AntiSpam, Intrusion Prevention signatures, deep packet inspection and protocol analysis for HTTP/HTTPS/FTP/DNS/etc.).

Watchguard firewalls are available as small office devices (XTM 2 and XTM 3 series) with optional integrated WiFi, fullsize rackmount devices for central offices and datacenters (other XTM and M devices), and as virtual machines (the XTMv range) for VMware and Hyper-V deployment.

Their business model is to have a standard firewall software offering, with the more advanced features available by purchasing licensing upgrades, and to have the same management tools, configuration format and monitoring apply up and down the hardware range. The hardware range is differentiated by processing power, memory and number of interfaces of different speeds, although some of the advanced features are unavailable on the smallest models or the XTMv virtual firewalls.

Watchguard XCS Range

The XCS devices are dedicated email filtering devices, with detailed control of users and groups, attachments, content scanning and filtering.

Watchguard AP range

These are wireless access points]1 designed to be used with a Watchguard firewall. The configuration is done as part of the firewall configuration and the access points pick up their settings from the firewall.

Watchguard SSL range

Dedicated SSL VPN portal device for end user access to a central site. They offer The features in these are increasingly included in by the newer firewall firmwares,

Their software includes

Watchguard System Manager

The desktop version of the firewall management software, it comes in two parts - firebox system manager for connecting to a firewall and seeing live status, traffic log messages, running diagnostic commands, and policy manager for editing the firewall policies and general device configuration.

Their firewalls also have a web interface for policy configuration, which is increasingly where Watchguard's focus is going.

Watchguard Dimension

A virtual machine appliance which integrates logging from Watchguard firewalls, alerting from those logs, and analysing the logs and presenting a web interface of the results.

The analysis covers things like bandwidth use per policy, per host, per server, per connection type. Internet access / website use per user or group. Numbers of connections per policy. Attacks detected, and their sources. Usage levels at different times of day, and so on.

Watchguard LogServer and ReportServer

These are Windows services which accept encrypted logging connections from Watchguard firewalls and store them in a PostgreSQL database, it can send email email alerts on firewall log events.

ReportServer analyses the logs and generates reports of internet traffic use, bandwidth use, and so on.

Both of these are being replaced by Watchguard Dimension.

Watchguard Central Management Server

A Windows service which manages firewalls, giving a single place to connect to for firewall management. It can save configuration revision histories, show diffs, and allow configuration rollback, schedule configuration changes and firmware upgrades, and has some support for firewall policy templates and VPN templates.

Utility software

Single-Sign-On helper services, for installing on Windows domain controllers, desktops, and Exchange servers - usable in different combinations to support different ways the firewalls can detect which network traffic is linked to which users and mobile devices.

SSL VPN Client - a VPN client for laptop and desktop users connecting to the SSL VPN service on Watchguard firewalls.

112 questions
0
votes
2 answers

Separate WebBlocker settings, using one Watchguard XTM 505?

I support a school with 3 locations that uses a Watchguard XTM 505. They are implementing a BYOD wireless solution with Aerohive APs, and they will have 3 SSIDs (School, Guest, BYOD). Each SSID needs to have different WebBlocker permissions, how can…
msindle
  • 605
  • 8
  • 26
0
votes
1 answer

Can Watchgurard XTM 520 support 2nd network drop?

I need a bit of advice here. We are having 2 XTM 520 firewall configured in HA by a consultant previously. The FW are connected to a 100 mbps network drop currently. I have taken over the work but I am not too familiar with the FW. We are planning…
ledmirage
  • 101
0
votes
1 answer

GPO Setting to allow workstations to use VPN

Is there a GPO setting that allows non-admins access to change their network settings. Which is what the SSLVPN does? If so, what is it? Background : I've got a few laptops that are used by Domains admins, that can access the Watchguard SSLVPN. But…
NeerPatel
  • 329
  • 2
  • 6
  • 18
0
votes
1 answer

How to forward external traffic from specific port to specific external ip?

How do i forward outgoing traffic for specific port from internal network to specific external ip in watchguard? I know how to forward incoming traffic using SNAT.
Iternity
  • 183
  • 1
  • 2
  • 7
0
votes
3 answers

VPN: Cisco / Watchguard: IKE lost contact with remote peer

I'm trying to set up a lan-to-lan VPN between a Cisco ASA 5510 (7.0(5) firmware, IP 222.222.222.222) and a Watchguard X750e firewall (10.2 firmware, IP 111.111.111.111) Phase 1 comes up but then the message "IKE lost contact with remote peer,…
DrStalker
  • 6,946
  • 24
  • 79
  • 107
0
votes
1 answer

Is this considered 2 Factor Authentication?

Trying to create a 2 Factor Authentication for users to access data remotely. Here my scenario: We have a Watchguard to VPN into the network - If we use it's internal DB to store authentication information. Then use Active Directory credentials to…
NeerPatel
  • 329
  • 2
  • 6
  • 18
0
votes
4 answers

looking for free windows/linux process watchdog

i have process running on windows and linux , i need watch dog that will email me if some process is down more then N seconds/minutes and also this watch dog will try to start it after N time and N trys , is there such thing ?
user61104
  • 519
  • 1
  • 8
  • 16
0
votes
1 answer

Watchguard Firebox SSL certificate validation failed

I'm really stuck on this one! I have two Watchguard firebox firewalls. My SSL certificates expired and I bought two new wildcard certificates from RapidSSL. I couldn't get the certificate to install on the first one. "certificate validation…
0
votes
3 answers

WatchGuard 'Internal Policy' intermittently blocking outbound web traffic

I have a lot of legitimate outbound traffic intermittently being denied by WatchGuard's "Internal Policy." Today I tried to go to Splunk's homepage and my traffic was denied by my watchguard XTM 22 with Pro upgrade. What is the "Internal Policy"…
vfilby
  • 177
  • 2
  • 3
  • 9
0
votes
1 answer

Watchguard Firewall - bridge a public IP to another interface?

I have a Watchguard XTM 8 series firewall, and it is setup in mixed routing mode. I have a /24 public IP range and I want to pass one of those IPs to another interface on the firewall WITHOUT using NAT - because I want to connect a Cisco router to…
0
votes
2 answers

Watchguard SSL VPN and Outlook 2010

Recently I installed a watchguard xtm 21 appliance. Everything went fine until I updated from Office 2007 to Office 2010. Behind my watchguard appliance I've got an Exchange 2007 server, which I was able to reach with Outlook 2007 (when working…
Andrew
  • 103
  • 5
0
votes
1 answer

watchguard fb x10 and x15 password reset

Is it possible to reset the password on watchguard fb x10 and x15 devices without clearing the config? We have 2 of these devices, they appear to have a serial port but not sure if that provides a console method to reset p/w.
Chris
  • 1
  • 2
0
votes
1 answer

watchguard xtm small business server 2003 installation guide

Does anyone have a recommended step-by-step for configuring a watchguard xtm for all of SBS 2003's services (e.g. Exchange, OWA, PPTP, SharePoint, Remote Web, Active Sync, etc)?
Sally
  • 345
  • 2
  • 3
  • 12
0
votes
3 answers

Datacenter firewall - considering Sonicwall nsa 240, looking for suggestions

We are looking into putting a hardware firewall into a data center to protect our rack of servers. We are using the servers for terminal services and we have 2 x 1GB connections to the Internet. We have about 50 servers supporting about 250 users…
Adam Chetnik
  • 542
  • 6
  • 19
0
votes
2 answers

Setting up a watchguard policy to allow sharepoint site access from the internet

I have a sharepoint site that I have full access to over the local network, but from the internet I just get webpage can not be displayed. I've checked the settings in IIS and Sharepoint and everything looks fine. This leads me to believe that our…
user50654