Firebox Web UI Integration with AuthPoint

Deployment Overview

This document describes how to configure multi-factor authentication (MFA) for Device Management users that log in to Fireware Web UI.

With Fireware v12.7.2 or higher, you can add AuthPoint as an authentication server on your Firebox. For Fireware v12.7.1 or lower, you can set up RADIUS authentication through the AuthPoint gateway and add a RADIUS user as a management user to the Fireware Web UI. For these configurations, you must register and connect your Firebox to WatchGuard Cloud as a locally-managed Firebox (this integration does not support cloud-managed Fireboxes). For detailed instructions to register and connect your Firebox to WatchGuard Cloud, see Add a Locally-Managed Firebox to WatchGuard Cloud.

Your WatchGuard Firebox must already be configured and deployed before you set up MFA with AuthPoint.

When you configure MFA, Device Management users can authenticate with a push notification or a one-time password (OTP). You choose which authentication method users can use when you configure the authentication policy in AuthPoint. The steps in this integration guide are for both authentication methods.

If you configure AuthPoint MFA with a Firebox resource (Fireware 12.7.2 or higher) and AuthPoint syncs users from an LDAP external identity, the Firebox must have network access to the LDAP server to authenticate the synced users.

WatchGuard Firebox Authentication Data Flow with AuthPoint

This diagram shows the data flow of an MFA transaction for a WatchGuard Firebox.

Before You Begin

Before you begin these procedures, make sure that:

  • A token is assigned to a user in AuthPoint
  • You have registered and connected your Firebox to WatchGuard Cloud as a locally-managed Firebox.

Configure AuthPoint MFA for Firebox Web UI

The steps to configure AuthPoint and your Firebox are different based on the version of Fireware that your Firebox runs.

Test the Integration

To test the integration of AuthPoint and the WatchGuard Firebox, you authenticate with a mobile token on your mobile device or a hardware token. For Firebox resources, you can authenticate with a one-time password (OTP) or a push notification. The authentication method you use is determined by the access policy for your Firebox resource.

When you log in to Fireware Web UI, your user name must exactly match the user name in AuthPoint. The user name is case sensitive.