Auvik Integration Guide

Auvik is an RMM (Remote Monitoring and Management) tool used by MSPs (Management Service Providers) for asset management. RMM agents are installed on MSP customer endpoints to discover, monitor, and manage IT assets. Auvik can discover WatchGuard devices and use authentication credentials to access specific device information such as subscription status, renewal date, hardware model, and other device properties.

This document describes how to use Auvik to discover and monitor a WatchGuard Firebox.

Platform and Software

The hardware and software used to complete the steps in this document include:

  • Firebox with Fireware v12.7.1 or higher
  • Auvik Cloud
  • Auvik Collector

This diagram outlines the topology used for this integration:

test topy

Set Up the Firebox

SNMP Settings

You must configure SNMP settings on the WatchGuard Firebox before you can use Auvik to discover the Firebox.

  1. Log in to Fireware Web UI (https://<your firebox IP address>:8080).
  2. Select System > SNMP.
  3. If necessary, click the lock the Lock icon to make changes.
  4. From the Version drop-down list, select v3.
  5. In the User Name text box, type WatchGuard.
  6. From the Authentication Protocol drop-down list, select SHA1.
  7. In the Password and Confirm text boxes, type the authentication password.
  8. From the Privacy Protocol drop-down list, select DES.
  9. In the Passwordand Confirm text boxes, type the encryption password.

Screenshot of Firebox, picture1

  1. Click Save.
  2. Select Firewall > Firewall Policies.
  3. Click Add Policy.
  4. From the Packet Filter drop-down list, select SNMP.

Screenshot of Firebox, picture2

  1. Click Add Policy.
  2. Configure the SNMP packet filter policy to allow traffic from Any-Trusted to Firebox. If you connect to an optional interface, specify Any-Optional instead of Any-Trusted.

Screenshot of Firebox, picture3

  1. Click Save.
    The SNMP policy should open with these properties:

Screenshot of Firebox, picture4

SSH Settings

You must configure SSH settings on the WatchGuard Firebox before you can manage the Firebox with Auvik.

  1. Select Firewall > Firewall Policies.
  2. Click Add Policy.
  3. Select Custom .
  4. Next to the Select a policy type drop-down list, click Add.

Screenshot of Firebox, picture5

  1. In the Name and Description text boxes, type the name and description.
  2. From the Protocols section, click Add.

Screenshot of Firebox, picture6

  1. From the Type drop-down list, select Single Port.
  2. From the Protocol drop-down list, select TCP.
  3. In the Server Port text box, type 4118.
  4. Click OK.

Screenshot of Firebox, picture7

  1. Click Save.

Screenshot of Firebox, picture8

  1. Click Add Policy.
  2. Edit the policy to allow traffic from Any Trusted to Firebox. If you connect to an optional interface, specify Any-Optional instead of Any-Trusted.

Screenshot of Firebox, picture9

  1. Click Save. The SSH policy should open with these properties:

Screenshot of Firebox, picture10

  1. If necessary, click the lock unlock to prevent further changes.

Set Up Auvik

Install Auvik Collector

  1. Log in to Auvik Cloud.
  2. Select Navigation > All Sites.
  3. Click Add Site.
  4. In the Add Site page, from the Relationship Type drop-down list, select Site.
  5. In the Organization Name text box, type the organization name.
  6. In the Desired URL text box, type the desired URL.

Screenshot of Auvik, picture1

  1. Click Next.
  2. Select All users.

Screenshot of Auvik, picture2

  1. Click Save.

Screenshot of Auvik, picture3

  1. Click the WGCDCECO organization name.

Screenshot of Auvik, picture4

  1. Select the Auvik Collector to download from the options, then follow the detailed installation instructions to install the Auvik Collector on the proper computer. This computer must be on a LAN that is connected to the WatchGuard Firebox.
  2. After the Auvik Collector is installed and successfully connection to Auvik Cloud, the Auvik Collector status is online on the All Sites page.

Screenshot of Auvik, picture5

SNMP Credential Settings

  1. Select Admin > Discovery > Manage Credentials > SNMP Credentials.
  2. Click Add SNMP Credentials.
  3. In the Description text box, type the description for the SNMP credentials.
  4. From the Version drop-down list, select Version 3.
  5. In the Username text box, type the user name WatchGuard.
  6. From the Auth Protocol drop-down list, select SHA.
  7. In the Auth Passphrase text box, type the auth passphrase.
  8. From the Privacy Protocol drop-down list, select DES.
  9. In the Privacy Passphrase text boxes, type the privacy passphrase.

Screenshot of Auvik, picture6

  1. Click Save.

Screenshot of Auvik, picture7

SSH Global Settings

  1. Select Admin > Discovery > Discovery Settings > Service Settings > SSH.
  2. From the Use Default Ports drop-down list, select No - Custom Ports.
  3. In the Port text box, type 4118.

Screenshot of Auvik, picture8

  1. Click Save.

SSH Credential Settings

  1. Select Admin > Discovery > Manage Credentials > Login Credentials.
  2. Click Add Login Credentials.
  3. In the Description text box, type the description for the SSH credentials.
  4. From the Connect Using drop-down list, select Telnet or SSH.
  5. In the Username text box, type the user name admin (this is WatchGuard Firebox default admin user name).
  6. In the Password text box, type the password.
  7. In the CLI Enable Password text box, type the password.

Screenshot of Auvik, picture9

  1. Click Save.

Add SNMP Monitor

  1. Select Admin > Discovery > Discovery Settings > Monitor Settings.
  2. Click Add Monitor Setting.
  3. In the Name text box, type the monitor name.
  4. In the OID text box, type 1.3.6.1.4.1.3097.6.3.1. This is the WatchGuard Fireware version OID.
  5. From the Type drop-down list, select String.
  6. From the Use as drop-down list, select Monitor Only.
  7. From the Poll Period drop-down list, select 1 minute.

Screenshot of Auvik, picture10

  1. Click Save.

Screenshot of Auvik, picture11

Test the Firebox and Auvik Integration

  1. Log in to Auvik Cloud.
  2. Select All Sites.
  3. Click the WGCDCECO organization name.
  4. The topology discovered by Auvik opens.

Screenshot of Auvik, picture12

  1. Click WatchGuard-XTM in the topology to see detailed information about this device.

Screenshot of Auvik, picture13

  1. Select Navigation > Debug > All OID Monitors.
    The Firebox Fireware versions open.

Screenshot of Auvik, picture14

  1. Select Navigation > Documentation > Configurations, then click the discovered WatchGuard-XTM device.

Screenshot of Auvik, picture15

  1. In the WatchGuard -XTM page, select Documentation > Configurations.

Screenshot of Auvik, picture16

  1. You will see all configurations that were previously backed up.

Screenshot of Auvik, picture17

  1. Select Manage Configuration > Export to export the selected configuration.

Screenshot of Auvik, picture18

The Auvik Restore button is not operational for WatchGuard products at this time. To restore these devices, export the configuration from Auvik, change the file extension to .xml, and import the file with the Fireware Web UI.