Change a Locally-Managed Firebox to Cloud Management

Applies To: Locally-managed Fireboxes

This feature is only available to devices that are actively connected to WatchGuard Cloud as a locally-managed device. For information on how to add a new device to WatchGuard Cloud, see Add a Cloud-Managed Firebox to WatchGuard Cloud.

In WatchGuard Cloud, you can monitor live status, and see log messages and reports for locally-managed devices you add to WatchGuard Cloud. When a Firebox is cloud-managed, you manage the configuration in WatchGuard Cloud.

You can change a locally-managed Firebox to cloud management. If you currently manage the device configuration in WSM, Fireware Web UI, or the Command Line Interface, your configuration is replaced with the cloud-managed configuration. For information about the configuration features available in WatchGuard Cloud, see Firebox Monitoring and Configuration Features.

Before you deploy the cloud-managed configuration, we recommend that you use WSM or Fireware Web UI to create a backup image of the current locally-managed configuration. This enables you to restore it later if you want to remove the device from cloud management.

To change a locally-managed Firebox to cloud management, you must:

  • Create a backup image of the current locally-managed configuration
  • Change the device from locally-managed to cloud-managed
  • Configure the device in WatchGuard Cloud
  • Deploy the cloud-managed configuration

Change a Device from Local Management to Cloud Management

Before you change to cloud management, make sure that the Firebox is connected to WatchGuard Cloud as a locally-managed device. The Firebox must run Fireware v12.5.7 or Fireware v12.6.4 or higher. For more information about Fireware cloud-management requirements, see Fireware Requirements.

To change a device to cloud management:

  1. Log in to your WatchGuard Cloud account.
  2. For Service Provider accounts, from Account Manager, select My Account.
  3. Select Configure > Devices.
  4. Select the device you want to change.
    The Device Settings page opens.
  5. In the Cloud Management section, click Change to Cloud Management.
    The Add Device wizard opens.

  1. Enter a new name for the device, if required.
  2. Select an appropriate Time Zone for the device.
  3. Click Next.

  1. Select the Connection Type.
  2. Click Next.

  1. Set the Status and Admin passwords for WatchGuard Cloud management.
  2. Click Next.

  1. Make sure you have a backup configuration available.
    When you click Next, the local Status and Admin credentials update to the cloud-managed credentials you specified. You can no longer make configuration changes to the Firebox through WatchGuard Systems Manager (Policy Manager) or the Fireware Web UI.
  2. To configure the device in WatchGuard Cloud, click Next.
    The Device Configuration page opens.
  3. Review the default configuration and make changes as necessary.
    The local configuration remains in place until you deploy the cloud-managed configuration. Make sure to configure your internal interface, network settings, and VPN , if applicable, in the cloud-managed configuration before you deploy it. External interfaces are automatically configured.
  4. Deploy the configuration.
    For more information, see Manage Device Configuration Deployment.
    WatchGuard Cloud automatically creates a backup of the initial configuration. The new cloud-managed configuration replaces the locally-managed configuration on the Firebox.

You cannot subscribe the device to a configuration template until you deploy the first configuration from WatchGuard Cloud.

See Also

Manage the Firebox Configuration

Configure Cloud-Managed Fireboxes

Default Firewall Policies

Firewall Policies Best Practices

WatchGuard Cloud Features for Firebox Configuration (Knowledge Base article)