Troubleshoot FireCloud

Applies To: FireCloud Internet Access, FireCloud Total Access

Some of the features described in this help topic are only available to participants in the WatchGuard Beta program. To try adding the network resources in FireCloud, join the WatchGuard Beta test community.

This topic describes common problems and solutions for FireCloud.

Installation Issues

If you experience issues when you try to run the WatchGuard Agent MSI file:

  • Make sure that your computer does not have Panda Endpoint Security products installed. You cannot install the WatchGuard Connection Manager on computers that have Panda Endpoint Security products installed. The WatchGuard Connection Manager is only compatible with WatchGuard Endpoint Security products. If you have Panda Endpoint Security products and want to try FireCloud, contact your WatchGuard sales representative and ask about migration to WatchGuard Endpoint Security.

The WatchGuard Connection Manager has been automatically removed from your computers, but the WatchGuard Agent remains installed. When you attempt to install the Connection Manager again, the installation is successful but the Connection Manager is not installed.

  • When your FireCloud license or trial expires, the WatchGuard Agent uninstalls the WatchGuard Connection Manager on all devices associated with your account. When your account becomes licensed again, the WatchGuard Agent automatically installs the WatchGuard Connection Manager.

The WatchGuard Connection Manager does not support Windows servers or computers that use ARM processors.

Connection Issues

FireCloud access rules do not apply to traffic when you connect to your corporate network or you are behind a firewall, and the Connection Manager status is yellow or red.

  • By default, FireCloud uses UDP port 4500 to communicate with WatchGuard points of presence (PoP). You can also configure FireCloud to use UDP ports 51280, 443, or 53.
  • When your computer is connected to FireCloud, your firewall configuration affects how your traffic is handled.
    • If the configured FireCloud communication port is open when connected to your corporate network, the connection manager continues to pass traffic through FireCloud.
    • If the configured FireCloud communication port is blocked when connected to your corporate network, the client connection to FireCloud fails to open and the client passes traffic as it normally does when connected to the corporate network. However, the WatchGuard Connection Manager continually attempts to connect to the FireCloud PoP while behind the firewall.
  • If your computer is behind a firewall, we recommend that you have port 4500 open. FireCloud uses this port for communication.

FireCloud does not work when you are behind a Firebox. The Connection Manager appears to establish a tunnel, but no traffic passes and the Connection Manager icon becomes red.

  • If your computer is behind a Firebox with Application Control enabled (default configuration), Application Control blocks WireGuard, which causes FireCloud to not work. You must configure an Application Control action on the Firebox to allow WireGuard. Use these settings to configure the Application Control action on your Firebox:
    • Application: WireGuard VPN Protocol (in the Tunneling and Proxy Services category)
    • Set the Action for All Behaviors: Allow

The Connection Manager fails to connect to FireCloud and shows error message 1005. You might also see a message in the log file that says Invalid issuer in the Assertion/Response. In this scenario, if you have configured Entra ID as your FireCloud identity provider, go to Configure > FireCloud > Authentication and make sure that the Identity Provider ID value has a slash (/) at the end.

If the Connection Manager has a delay before it starts or establishes the tunnel, we recommend that you add these exceptions to your antivirus software:

  • /Applications/WatchGuardConnectionManager.app/
  • /Applications/WatchGuardConnectionManager.app/Contents/Resources/WatchGuardConnectionManagerHelper
  • /Library/WatchGuard/
  • ~/Library/Group Containers/3TS3WLH98A.com.watchguard.connectionmanager/
  • System Extension: com.watchguard.connectionmanager.network-extension

If you have configured FireCloud to use port 53 for the Connection Manager and either your mobile carrier or an upstream security device on Wi-Fi restricts port 53 to only DNS traffic, then the Connection Manager will fail to connect the connection status is Unhealthy or the Connection Manager will show an error message that the port is blocked. In this scenario, we recommend that you either configure FireCloud to select the port automatically, or to use a port other than port 53.

If you use Skype for Business and FireCloud, client to client file transfers will fail when both clients are connected to FireCloud. To resolve this issue, you must add your Skype for Business Audio/Video Edge IP address to a tunnel bypass.

Connections to Private Resources

When you configure access rules, we recommend that you only add each group to a single access rule. If a group belongs to multiple access rules, FireCloud only applies the access rule with the highest priority. This can prevent access to private resources if an access rule with private resources has a lower priority than another access rule for the same groups.

For example, you configure two access rules in FireCloud:

  • Access Rule 1
    • Groups: Remote_USA, Remote_EMEA
    • Settings: Allow users to manually disconnect from FireCloud is enabled
    • Security Services: All services enabled with the default settings
    • Resources: None
  • Access Rule 2
    • Groups: Remote_USA
    • Settings: None
    • Security Services: None
    • Resources: SQL and RDP resources added
  • Default Access Rule
    • Groups: Remote_USA
    • Settings: None
    • Security Services: All services enabled with the default settings
    • Resources: None

In this example, users in the Remote_USA group do not have access to any private resources. For users in the Remote_USA group, FireCloud only applies Access Rule 1 because it is has the highest priority.

If users cannot access hosts on an internal network or subnet:

  • Make sure that you have added a network resource on the correct Gateway. If network resource does not appear in the Type drop-down list, make sure that your Virtual Gateway is version 1.5.0 or higher.
  • Make sure that you have added the network resource to the applicable access rule
  • Make sure that routing and firewall rules on your network allow traffic from the Gateway to the target network.

If users cannot access domain resources that require Kerberos authentication, make sure that you have added a Kerberos Authentication resource on the Gateway and included that resource and the related private resources in the access rule. For more information, go to Add Resources in FireCloud.

Contact Support

If you experience problems with FireCloud, and cannot find the information you need in this topic, contact Support Information.

When you contact technical support, you will be asked for basic information about your FireCloud devices and FireCloud account. Make sure you have this information ready:

  • Description of the problem.
  • Screenshots of the error or affected configuration.
  • Run PSInfo to collect and save a .7Z file with support-related information about the affected computer. For more information, go to Get Started with PSInfo.
  • Enable support access for your WatchGuard Cloud account. For more information, go to Support Access to WatchGuard Cloud Accounts.

Related Topics

Troubleshoot WatchGuard Endpoint Security Software Installation Errors

WatchGuard Agent MSI Install Issues with WatchGuard Endpoint Security

Log Search (FireCloud)

About the FireCloud Usage Report