Configure a Firebox External Network

Applies To: Cloud-managed Fireboxes

For a cloud-managed Firebox, an external network specifies settings for how the Firebox connects to a network that is not protected by the Firebox, such as the Internet. External network settings specify which interfaces connect to the external network and how the Firebox gets an external IP address.

To maintain a connection to WatchGuard Cloud, the Firebox configuration must have a valid external network and DNS server.

If a change to the Firebox configuration or external network causes the Firebox to lose the connection to WatchGuard Cloud, you can use the Web UI on the Firebox to recover the connection. For more information, see Recover the Firebox Connection to WatchGuard Cloud.

An External network is in the External zone. It is a member of the built-in alias Any-External. For more information about aliases, see Configure Firebox Aliases.

Edit or Add an External Network

By default, a cloud-managed Firebox has one external network. You can edit the default external network and add additional networks.

To open the Networks configuration, from WatchGuard Cloud:

  1. Select Configure > Devices.
  2. Select the cloud-managed Firebox.
  3. Click Device Configuration.
  4. Click the Networks tile.
    The Networks configuration page opens.

Screen shot of the Networks tiles on the Networks configuration page

To edit an External network, from WatchGuard Cloud:

  1. On the Networks page, click the tile of the external network to edit.
    The network configuration page opens.
  2. Configure the network settings, as described in the next section.
  3. To save configuration changes to the cloud, click Save.

To add an External network, from WatchGuard Cloud:

  1. At the top of the Networks page, click Add Network.
  2. From the drop-down list, select Add External Network.
    The Add External Network page appears.

  1. In the Name text box, type a name for the network.
  2. Configure other network settings as described in the next section.
  3. To save configuration changes to the cloud, click Save.

Configure Network Settings (IPv4)

In the Network tab, you can configure the network IPv4 address, VLAN settings, and associated interfaces.

Configure Network Address Settings

For an External network, you can assign a static IP address, or you can configure the Firebox to use DHCP or PPPoE to get an IP address.

Configure VLAN Settings

You can configure any Firebox network as a virtual local area network (VLAN). When you enable VLAN for an external network, all interfaces associated with the network are configured to handle tagged VLAN traffic by default. You can edit each interface to change whether it handles tagged or untagged VLAN traffic for this network.

For more information, see Configure Firebox VLANs.

Configure Network Interfaces

In the network settings, you select which Firebox interfaces are associated with the network.

When you add an External network, the lowest numbered available interface is automatically associated with the network.

In the settings for a network, the Interfaces section shows which interfaces are currently associated with the network, and which are available.

Screen shot of the Interfaces settings for a network

The interface icon color indicates interface status in relation to this network.

White interface icon Interface is associated with another network
Blue interface icon Interface is associated with this network
Gray interface icon. Interface is available to associate with this network

To see associated networks for an interface, point to View Networks for the interface.

By default, all interfaces are associated with a network. Before you can associate an interface with a different network, you must remove that interface from the network it was previously associated with.

If you associate more than one interface with a network, network traffic is bridged between all associated interfaces.

To configure the interface settings for a network, from WatchGuard Cloud:

  1. In the tile for an associated or available interface, click .

  1. Select one of these options:
  • No Traffic — Remove the interface from this network.
  • Add Network Traffic — Add the interface as the first interface associated with this network.
  • Bridged Network Traffic — Add this interface to a network that already has another associated interface or SSID.

For a VLAN, the interface options are Untagged VLAN or Tagged VLAN. For more information, see Configure Firebox VLANs.

Configure IPv6

On the IPv6 tab, you can enable IPv6 for the network, add one or more IPv6 addresses to the configuration, and configure other IPv6 settings.

In Fireware v12.9.2 or higher, you can use an IPv6 static address to configure an interface when you have a link-local address as the default gateway.

For information about IPv6 address formats, see About IPv6.

To enable IPv6, from WatchGuard Cloud:

  1. Select the IPv6 tab.
  2. Select Enable IPv6.
  3. Click Add Static IPv6 Address.
    The Add Static IPv6 Address dialog box opens.
  4. In the IP Address text box, type an IPv6 address and prefix length.
  5. Click Add.
  6. To add more IPv6 addresses, repeat Steps 3–5.
  7. To edit an IPv6 address, click it.
  8. (Optional) To automatically assign an IPv6 link-local address to this interface, select IP Address Autoconfiguration.
  9. (Optional) To enable DHCPv6 clients to request an IPv6 address, select DHCPv6 Client. By default, DHCPv6 clients use a four-message exchange (solicit, advertise, request, reply).
  10. (Optional) To enable DHCPv6 clients to use a two-message exchange (solicit, reply) to request an IPv6 address, select Rapid Commit.
  11. (Optional) To enable DHCPv6 clients to request an IPv6 prefix, select Enable DHCPv6 Client Prefix Delegation.
  12. (Optional) To enable DHCPv6 clients to use a two-message exchange (solicit, reply) to request a prefix, select Rapid Commit.
  13. Enter the Default Gateway.
  14. Enter the Hop Limit, which is the number of network segments a packet can travel over before a router discards the packet. The default value is 64.
  15. Enter the DAD Transmits, which is the number of Duplication Address Detection transmits for this link. The default value is 1.

Screen shot of the IPv6 configuration for an external network

Configure Link Monitoring

On the Link Monitoring tab, you can enable link monitoring. When link monitoring is enabled, the Firebox sends traffic to a link monitor target to test network connectivity.

For more information, see Configure Firebox Network Link Monitoring.

Configure Dynamic DNS

On the Dynamic DNS tab, you can enable dynamic DNS (DDNS) and configure a connection to a DDNS service provider. WatchGuard Cloud supports several DDNS service providers.

For more information, see Configure Dynamic DNS.

Configure Advanced Settings

On the Advanced tab you can configure these network settings:

  • Web UI Access
  • Ping
  • MAC Access Control
  • Secondary Networks

For more information, see Configure Advanced Network Settings.

Related Topics

About Firebox Networking Settings