SecureW2 and Wi-Fi in WatchGuard Cloud Integration Guide

Deployment Overview

This guide demonstrates how to integrate Wi-Fi in WatchGuard Cloud with SecureW2 authentication for users to authenticate and receive certificates for WPA2 Enterprise EAP-TLS Wi-Fi access.

Integration Summary

The hardware and software used in this guide include:

  • SecureW2:
    • SecureW2 JoinNow MultiOS Management Portal
  • WatchGuard:
    • WatchGuard AP330
    • WatchGuard Cloud Account
    • WatchGuard Firebox
  • Microsoft Server 2019
    • Active Directory

Test Topology

SecureW2 JoinNow MultiOS Management Portal interacts with the WatchGuard AP330 access point through policies to end users.

Topology diagram for SecureW2 authentication

SecureW2 Network Profile and RADIUS

Use the Device Onboarding section in the SecureW2 console to acquire the RADIUS information.

  1. Log in to the SecureW2 JoinNow MultiOS Management Portal and select Device Onboarding > Getting started.
  2. In the Quickstart Network Profile generator section, from the Profile Type drop-down list, select Wireless.
  3. In the SSID text box, type the SSID for the network that you want to secure with TLS.
  4. From the Security Type drop-down list, select WPA2-Enterprise.
  5. From the EAP Method drop-down list, select EAP-TLS.
  6. From the Policy drop-down list, select Default.
  7. From the Wireless Vendor drop-down list, select WatchGuard.
  8. From the RADIUS Vendor drop-down list, select SecureW2.
  9. Click Create.
    The Network Profiles page appears. This process may take several minutes.

Screenshot of SecureW2, Create Network Profiles page

  1. Select AAA Management > AAA Configuration.
  2. Note the RADIUS Authentication Port, Primary IP Address, and the Shared Secret.

You will use this information in the WatchGuard Cloud configuration.

Screenshot of SecureW2, AAA Configuration page

WatchGuard Cloud Configuration

For detailed information on Wi-Fi in WatchGuard Cloud deployment, see Get Started with Wi-Fi in WatchGuard Cloud.

Access points can have two different types of settings:

  • Device-level settings — Settings that you apply individually to each access point.

  • Access point site settings — Access point sites enable you to create SSID settings and apply them to multiple access points that subscribe to the site.

Configure SecureW2 RADIUS Information for EAP-TLS in WatchGuard Cloud

  1. Log in to your WatchGuard Cloud account. If you have a Service Provider account, you must select a subscriber account from the Account Manager.
  2. Select Configure > Authentication Domains.
  3. Click Add Authentication Domain.
  4. In the Domain Name text box, type a domain name.
  5. Click Next.
  6. In the Add servers section, select RADIUS.
  7. From the Type drop-down list, select Host IPv4.
  8. In the IP Address text box, type the Primary IP Address of the RADIUS server from SecureW2.
  9. In the Port text box, type the authentication port number for the RADIUS server from SecureW2.
  10. In the Shared secret text box, type the shared secret from the SecureW2 RADIUS server.
  11. In the Confirm shared secret text box, type the shared secret from the SecureW2 RADIUS server.

Screenshot of the Add Authentication Domain page in WatchGuard Cloud

  1. Click Save to save the Authentication Domain settings.
  2. Click Done.

Configure the Authentication Domain and SSID Settings for an Access Point (Device Level Configuration)

To configure Authentication Domain and SSID settings for a single access point at the device level configuration:

  1. From WatchGuard Cloud, select Configure > Devices.
  2. Select your Access Point.
  3. Select Device Configuration.
  4. In the Authentication tile, click Domains.
  5. Click Add Authentication Domain.
  6. From the Select an existing Authentication Domain drop-down list, select the domain you created in the previous section.
  7. From the RADIUS Server drop-down list, select the RADIUS server.

Screenshot of the Add Authentication Domain page in WatchGuard Cloud

  1. Click Save to save the Authentication Domain settings.
  2. Click Back to return to the configuration settings.
  3. Click SSIDs.
  4. Click Add SSID.
  5. In the SSID Name text box, type the SSID name.
  6. Select the Broadcast SSID check box.
  7. From the SSID Type drop-down list, select Private.
  8. From the Radio drop-down list, select 2.4 GHz and 5 GHz.
  9. From the Security drop-down list, select WPA2 Enterprise.
  10. From the Authentication Domain drop-down list, select the domain you created in the previous section.
  11. In the Network section, select Bridged.

Screenshot of the Add SSID page in WatchGuard Cloud

  1. Click Save.
  2. Click Schedule Deployment.
  3. Select Deploy changes now.
  4. In the Description text box, type a description for the deployment.

Screenshot of the Schedule Deployment page in WatchGuard Cloud

  1. Click Deploy.

Configure the Authentication Domain and SSID Settings for an Access Point Site

To configure Authentication Domain and SSID settings and apply the configuration to multiple access points with an Access Point Site:

  1. From WatchGuard Cloud, select Configure > Access Point Sites.
  2. Click Add Site.
  3. In the Name text box, type a name for the site.
  4. Click Add.

Screenshot of the Access Point Site configuration page in WatchGuard Cloud

  1. In the Authentication tile, click Domains.
  2. Click Add Authentication Domain.
  3. From the Select an existing Authentication Domain drop-down list, select the domain you created in the previous section.
  4. From the RADIUS Server drop-down list, select the RADIUS server.

Screen shot of the Add Authentication Domain page in an Access Point Site in WatchGuard Cloud

  1. Click Save to save the Authentication Domain settings.
  2. Click Back to return the site configuration settings.
  3. Click SSIDs.
  4. Click Add SSID.
  5. In the SSID Name text box, type the SSID name.
  6. Select the Broadcast SSID check box.
  7. From the SSID Type drop-down list, select Private.
  8. From the Radio drop-down list, select 2.4 GHz and 5 GHz.
  9. From the Security drop-down list, select WPA2 Enterprise.
  10. From the Authentication Domain drop-down list, select the domain you created in the previous section.
  11. In the Network section, select Bridged.

Screenshot of the Add SSID page in an Access Point Site in WatchGuard Cloud

  1. Click Save.
  2. Click Schedule Deployment.
  3. Select Deploy changes now.
  4. In the Description text box, type a description for the deployment.
  5. Click Deploy.
  6. Click Close.
  7. Click Back to return to the site configuration settings.
  8. Select the Subscribed Devices tab.

Screenshot of the Subscribed Devices page in an Access Point Site in WatchGuard Cloud

  1. Click Select Devices.
  2. Select the access points to subscribe to the site.
  3. Click Save.

Configure the WatchGuard Firebox for SecureW2 Access to Active Directory

SecureW2 connects to Active Directory at its public IP address 52.41.166.6 on port 389. You can also use port 636 for secure access.

  1. Log in to your WatchGuard Firebox.
  2. From Fireware Web UI, select Firewall > SNAT > Add.
  3. In the Name text box, type a name for the SNAT configuration.
  4. For Type, select Static NAT.
  5. In the SNAT Members section, click Add.
  6. From the IP Address or Interface drop-down list, select Any-External, External, or a public IP address.
  7. From the Choose Type drop-down list, select Internal IP Address.
  8. In the Host text box, type the private address of the Active Directory server.

Screenshot of the Add SNAT configuration page on a Firebox

  1. Click OK to add the member.
  2. Click Save.
  3. Select Firewall > Firewall Policies > Add Policy.
  4. Select Custom then Click Add.

Screenshot of the Add Firewall Policy page on a Firebox

  1. Type a Name and Description.
  2. Select Packet Filter.
  3. Add TCP port 389.

Screenshot of the Add Policy Template page on a Firebox

  1. Click Save. You are redirected to the Select a policy type page with your new custom policy selected in the drop-down list.
  2. Click Add Policy to continue with the policy creation.
  3. In the From field, remove Any-Trusted.
  4. Click Add.
  5. From the Member type drop-down list, select Host IPv4.
  6. Type the SecureW2 public IP address 52.41.166.6.
  7. Click OK.
  8. In the To field, remove Any-External.
  9. Click Add.
  10. From the Member type drop-down list, select Static NAT.
  11. Select the SNAT configuration you created in the previous section.
  12. Click OK.

Screenshot of the Policy Configuration page for Active Directory on a Firebox

  1. Click Save.

Create a Wi-Fi Authentication Group in Active Directory

A Security Group is created in the Active Directory to connect the user to the SecureW2 Authentication Policies, User Role Policies, and Enrollment Policies.

  1. From Windows Server 2019, open Server Manager.
  2. Select Tools > Active Directory Users and Computers.
  3. Expand the domain and right-click Users, then select New > Group.
  4. In the Group name text box, type the name of the security group associated with the users.
  5. In the Group name (pre-Windows 2000) text box, type the same name.
    This text box might already be pre-defined with the correct name.
  6. In the Group scope section, select Global.
  7. In the Group type section, select Security.

Screenshot of the Active Directory server, New Group page

  1. Click OK.
  2. Double-click the name of the new security group.
  3. Select the Members tab.
  4. Click Add.
  5. Type the full name of each user.
  6. Select Check Names to verify, then click OK to submit.

Screenshot of the Active Directory server, Check Names page

  1. Click OK.

Configure SecureW2 for Active Directory Queries

  1. From the SecureW2 Management Portal, select Identity Management > Identity Providers.
  2. Click Add Identity Provider.
  3. Type a Name and Description.
  4. From the Type drop-down list, select LDAP.
  5. Click Save.

Screenshot of SecureW2, Identity Provider Name, Description, and Type configuration page

  1. In the Subject Name Attribute text box, type the subject name attribute.
    • sAMAccountName — Use this attribute deploy a simple user name login.
    • userPrincipalName — Use this attribute for the format [email protected].

Screenshot of SecureW2, Identity Provider page

  1. Click Update.
  2. Edit the Identity Provider you created, then select the Connections tab.
  3. Click Add Connection.
  4. In the Name text box, type the name of the IDP connection.
  5. In the Hostname text box, type the public IP Address.
    In this example, we use the public IP address of the WatchGuard Firebox.
  6. In the Port text box, type 389. If the connection is secured with a certificate, select the TLS/SSL check box to change the port number to 636. Upload a server self-signed certificate for LDAP over SSL.
  7. Select Admin.
  8. In the Admin DN text box, type the administrator of the Active Directory server.
  9. In the Admin Password text box, type the password of the administrator account.
  10. To retrieve and select a Subject Base DN from the Active Directory, click Naming Contexts, then select or type the Subject Base DN.
  11. To retrieve and select a Group Base DN from the Active Directory, click Naming Contexts, then select or type the Group Base DN.
  12. In the Server timeout text box, type 30.

Screenshot of SecureW2, IDP Connection Configuration page

  1. Click Test Connection.

Screenshot of SecureW2, Test Connection page

  1. Click OK.
  2. Click Update.
  3. Select the Attribute Mapping tab.
  4. Click Add.
  5. In the Local Attribute text box, type displayName.
  6. From the Remote Attribute drop-down list, select USER_DEFINED, then in the adjacent text box, type displayName.

Screenshot of SecureW2, Local and Remote Attribute page

  1. Click Next.
  2. Click Add.
  3. In the Local Attribute text box, type upn.
  4. From the Remote Attribute drop-down list, select USER_DEFINED, then in the adjacent text box, type userPrincipalName.
  5. Click Next.
  6. Click Add.
  7. In the Local Attribute text box, type email.
  8. From the Remote Attribute drop-down list, select USER_DEFINED, then in the adjacent text box, type mail.
  9. Click Next.
  10. Select the Groups tab.
  11. Click Add.
  12. In the Local Group text box, type the local group name.
  13. In the Remote Group text box, type the group attribute received from IDP.
    This remote attribute is mapped to the local attribute. This value for Remote Group is case-sensitive.

Screenshot of SecureW2, Local and Remote Group settings page

  1. Click Next.
  2. Click Update.

Configure the SecureW2 Authentication Policy

The SecureW2 Authentication Policy defines the protocols that the JoinNow MultiOS uses to communicate with the devices and assign the Identity Provider.

  1. From the SecureW2 JoinNow MultiOS Management Portal, select Policy Management > Authentication.
  2. Click Edit on the auto-created Authentication Policy.
  3. Select the Settings tab.
  4. From the Identity Provider drop-down list, select the Identity Provider you created.
  5. Click Update.

Configure the SecureW2 User Role Policy

  1. From the SecureW2 JoinNow MultiOS Management Portal, select Policy Management > User Roles.
  2. Click Edit on the Default Role Policy 1.
  3. Select the Conditions tab.
  4. From the Identity Provider drop-down list, select the configured identity provider.

Screenshot of SecureW2, User Role Policy page

  1. Click Update.

Configure the SecureW2 Enrollment Policy

  1. From the SecureW2 JoinNow MultiOS Management Portal, select Policy Management > Enrollment.
  2. Select Edit on the Default Enrollment Policy 1.
  3. On the Conditions tab, from the User Role and Device Role drop-down list, select the default role and default device policies.

Screenshot of SecureW2, Enrollment Policy page

  1. Click Update.

Republish the SecureW2 Network Profile

  1. From the SecureW2 JoinNow MultiOS Management Portal, select Device Onboarding > Network Profiles.
  2. In the Functions column, click Re-publish.
  3. In the Name text box, type a name for the profile.

Screenshot of SecureW2, Republish Network Profile page

  1. Click OK.
    This process may take several minutes.
  2. In the Functions column, click View, and copy the URL. You will use the URL in the Test a Wireless Client section.

If you use a local identity provider, you can create the user directly on SecureW2 and you do not need to republish the network profile.

Test a Wireless Client

  1. Open a web browser, then go to the SecureW2 URL you retrieved in the Republish the SecureW2 Network Profile section.

Screenshot of the SecureW2 client configuration page

  1. Click JoinNow.
  2. Run the downloaded application. Click Next.
  3. Type the Username and Password. Click Next.

Screenshot of the WatchGuard login page after the SecureW2 connection

The user is automatically redirected to the EAP-TLS wireless connection.