Add an Access Point to WatchGuard Cloud

Applies To: WatchGuard Cloud-managed Access Points (AP130, AP230W, AP330, AP332CR, AP430CR, AP432)

To manage a WatchGuard access point with WatchGuard Cloud, you must add the access point to your WatchGuard Cloud account as a cloud-managed device. If you have multiple new access points, you can add these devices to WatchGuard Cloud at one time.

For Service Providers, you can add multiple access points to a Subscriber account with a shared Access Point Site configuration for faster initial configuration and setup before device installation.

Before You Begin

Before you add access points to WatchGuard Cloud, make sure that:

About Replacement (RMA) Access Points

If your access point hardware fails during the warranty period, WatchGuard might replace it with an RMA (Return Merchandise Authorization) device of the same model. When you exchange an access point for an RMA replacement, WatchGuard Customer Care transfers the license from the original device serial number to the new device serial number.

When you add replacement access points to WatchGuard Cloud, these devices are identified by a Replacement label in the Add Device page.

When you add a replacement access point, WatchGuard Cloud automatically applies the configuration used by the original access point, except the device password that you configure when you add the replacement device. When you connect the replacement device and the access point comes online, the original access point becomes inactive in WatchGuard Cloud. You can then remove the original device from WatchGuard Cloud.

For more information, go to Add a Replacement (RMA) Access Point to WatchGuard Cloud.

You must add replacement devices to WatchGuard Cloud separately from new access points.

Required Ports

The access points use TCP port 443 to connect to WatchGuard Cloud.

Access points must also be able to connect to these destinations:

  • *.watchguard.io for product activation and feature key updates
  • *.watchguard.com for WatchGuard Cloud registration and connections
  • Access points must be able to resolve DNS queries with the DNS server the device receives from DHCP.
  • Access points must initially be able to connect to *.pool.ntp.org on NTP port 123 (TCP/UDP) for the default access point time synchronization servers, and for any custom NTP servers set for the device.

If you set up an access point behind a firewall that performs inspection on HTTPS traffic, you must add *.watchguard.io to the content inspection exception / bypass list to enable the access point to receive a feature key from WatchGuard servers. On the WatchGuard Firebox, this is enabled by default for cloud-managed Fireboxes in WatchGuard Cloud.

Related Topics

About WatchGuard Cloud

Manage the Access Point Device Configuration

Monitor Access Points