Quick Start — Set Up WatchGuard EDR Core
Applies To: Locally-managed Fireboxes
WatchGuard EDR Core includes the WatchGuard Agent and protection software installed on endpoints, as well as an Endpoint Security management UI in WatchGuard Cloud to manage security for the devices on your IT network.
To get started with WatchGuard EDR Core, complete these high-level steps:
- Step 1: Activate a Total Security Suite License
- Step 2: Allocate Endpoints (Service Providers Only)
- Step 3: Configure Pre-Deployment Settings
- Step 4: Deploy the WatchGuard Agent
- Next Steps — Configure Settings
EDR Core includes EDR and adds XDR capabilities via ThreatSync. For information on ThreatSync, go to About ThreatSync.
Step 1: Activate a Total Security Suite License
To get started with EDR Core, make sure you have an active Total Security Suite license for your Firebox and a WatchGuard Cloud account.
- If you do not have a WatchGuard account, create one at https://accountmanager.cloud.watchguard.com/create-account.
-
Activate your Total Security Suite subscription at www.watchguard.com.
For more information, go to Activate a Device or Service at WatchGuard.com.
Step 2: Allocate Endpoints (Service Providers Only)
When you activate a Total Security Suite license, the EDR Core license and available endpoints appear in the Inventory page in WatchGuard Cloud.
- Log in to your WatchGuard Cloud account.
-
Allocate endpoint licenses to your managed accounts.
For more information, go to Allocate Endpoints.
Step 3: Configure Pre-Deployment Settings
The WatchGuard EDR Core installation process consists of a series of steps that depend on the status of the network at the time of deployment and the number of computers and devices you want to protect. Before you deploy the WatchGuard Agent, we recommend that you complete these steps to plan the installation of WatchGuard EDR Core:
- Identify Unprotected Devices
- Verify Minimum Requirements for Target Devices
- Determine Computer Default Settings
Identify Unprotected Devices
Identify the physical and virtual Mac, Android, iOS, Windows, or Linux computers and devices you want to protect with Endpoint Security.
Verify that you have purchased enough licenses for the unprotected devices. Endpoint Security allows you to install the WatchGuard Agent even when you do not have enough licenses for all the computers you want to protect. Computers without a license still show information such as installed software and hardware on the computer details page, but are not protected.
For more information, go to Unmanaged Computers Discovered List .
Verify Minimum Requirements for Target Devices
Make sure that the computers and devices you want to protect meet the minimum installation requirements. For information on requirements, go to Installation Requirements in the Release Notes.
WatchGuard EDR Core requires access to multiple Internet-hosted resources. Make sure these URLs and ports are open to allow communication with the WatchGuard servers.
For more information on URLs and port access, go to WatchGuard Cloud URLs and Network Access Requirements.
Determine Computer Default Settings
When the client software is installed on the computer or device, Endpoint Security applies the group security settings to the computer or device. During installation, you select a target group for the computer with the required network settings. If the network settings for the selected group differ from the settings specified during installation, the installation settings apply.
For more information, go to Best Practices — Installation Tips for Endpoint Groups and Settings.
Configure the group organization and define settings before you deploy the WatchGuard Agent.
For more information about the different types of groups, and specific instructions, go to Manage Computers and Devices in Groups in Endpoint Security.
To add a group:
- In WatchGuard Cloud, select Configure > Endpoint Security.
- Select Computers.
- From the left pane, select
My Organization. - Next to the group in which you want to add a group, click
.
- Select Add Group.
The Add Group dialog box opens.
- Type a Name for the group.
- Click Add.
To configure settings from WatchGuard Cloud, you must first create a settings profile. For more information, go to Best Practices — Installation Tips for Endpoint Groups and Settings.
To create a settings profile:
- In WatchGuard Cloud, select Configure > Endpoint Security.
- Select Settings.
- From the left pane, select the type of security settings you want to create a profile for.
- In the upper-right corner, click Add.
The Add Settings page opens.
The Add Settings page shows different options for Endpoint Security Elite, 360, Prime, Basic, WatchGuard EDR and EDR Core.
- In the Name text box, type a new name for the settings profile.
- In the Description text box, type a description of the profile.
For example, you might describe the security needs addressed in the settings. - Expand each section and configure the settings. (missing or bad snippet)
- When you have configured all the settings, click Save.
For more information, go to Best Practices — Installation Tips for Endpoint Groups and Settings.
Step 4: Deploy the WatchGuard Agent
For accounts with more than one WatchGuard product license (for example, an Endpoint Security product license and a FireCloud license), the Configure > Agent Deployment page in WatchGuard Cloud is useful to centrally configure product deployment behavior for endpoint groups and endpoints. For more information, go to Configure WatchGuard Agent Deployment in WatchGuard Cloud.
Deploy the WatchGuard Agent to computers and devices in your organization with the correct network settings. The deployment strategy depends on the number of devices to protect, the devices with an WatchGuard Agent already installed, and the company network architecture, including whether there is a mobile device management solution in use.
For more information, go to the appropriate installation procedure for your scenario and platform:
- Download the WatchGuard Agent Installer for Endpoint Security Products
- Install the Endpoint Software Locally
- Install the Endpoint Security Software on Windows Computers and Servers
- Install the Endpoint Security Software on Mac Computers
- Install the Endpoint Security Software on Linux Computers
- Install the WatchGuard Mobile Security App on Android Devices
- Install the WatchGuard Mobile Security App on iOS Devices
- Install the Endpoint Software Remotely (Windows Computers)
- Deploy the Endpoint Software with Centralized Tools (Windows Computers)
- Install the Endpoint Software on Virtual Environments with a Template or Gold Image (Windows Computers)
Next Steps — Configure Settings
You can create as many settings profiles as necessary to manage network security for different types of computers and devices. General settings enable you to review user activity, configure computer and network settings, configure computer maintenance, and schedule email alerts.
For information on available settings, go to:
In this section, we provide recommendations for these settings profiles:
After you create a settings profile, you assign it to one or more computers or computer groups. You can assign settings profiles manually (directly) or automatically through inheritance from a group to subgroups, computers, and devices. When you assign a settings profile to a group, Endpoint Security applies the security settings immediately to all of the computers and devices in the group. For more information, go to Assign a Settings Profile.
Workstations and Servers Settings
Configure security settings profiles to define how Endpoint Security protects the workstations and servers on your network against threats, malware, and network attacks.
Alerts
In the General settings of a workstations and servers settings profile, you can configure local alerts to show on Windows, Mac, and Linux computers when Endpoint Security denies content. For example, it could be useful to add contact information for users to follow up. For more information, go to About Alerts and Configure Email Alerts.
Per-Computer Settings
On the Per-Computer Settings page, you create settings profiles that specify how often to install protection software updates on workstations and servers. You can also define settings to prevent tampering and unauthorized uninstallation of the protection software.
Automatic Updates
By default, automatic updates for Endpoint Security software is enabled. You can schedule these updates to occur when they will not interfere with other updates or backups. For more information, go to Configure Updates.
Avoid Endpoint Security updates at the same time as Windows updates. Windows updates will take precedence and could cause the Endpoint Security update to fail.
Anti-Tamper Password
Configure security against tampering to make sure that only authorized users can disable or uninstall Endpoint Security with a password. For information on how to set the anti-tamper password, go to Configure Security Against Tampering (Windows and Linux computers).
Endpoint Security Installation Plan