Access Point System Integrity Checks

Applies To: WatchGuard Cloud-managed Access Points (AP130, AP330, AP332CR, AP430CR, AP432)

In access point firmware v2.1 and higher, access points use a cryptographic signature to verify the integrity of the device each time the access point boots, and the integrity of a firmware upgrade file before each upgrade. Integrity checks make sure that system files are valid and have not been corrupted.

After you upgrade to an access point firmware version that includes system integrity checks, you cannot downgrade to a firmware version that is not signed by WatchGuard.

System Integrity Check

Each time the access point boots, it uses a cryptographic key to verify the integrity of the system files.

If an access point shuts down because an integrity check fails:

  • The access point reboots into failsafe mode
  • The LED indicators on the access point flash alternating blue and red every second to indicate the device is in failsafe mode
  • The access point does not broadcast wireless SSIDs or pass wireless traffic
  • You cannot connect to the access point Web UI or Command Line Interface (CLI) to view the status
  • You must contact WatchGuard Support to replace the device

Firmware Integrity Check

When you select a firmware upgrade file to install, the access point examines the file to make sure it contains a cryptographic signature. If the signature is present, the access point uses the public key from the previously installed firmware image to verify the upgrade file. If the access point cannot verify the signature, or if the signature is not present, the access point cancels the upgrade.

Access point firmware v2.0.28 is the minimum firmware version required to validate higher versions of firmware upgrade files that require firmware integrity checks.

If your access point runs a firmware version lower than v2.0.28 and you upgrade directly to v2.1 or higher from WatchGuard Cloud, the device will upgrade twice, first to v2.0.28 and then to the selected firmware version automatically. It might take additional time for the firmware upgrade to complete.

Related Topics

Reboot an Access Point

Flash LEDs on an Access Point

Update Access Point Firmware