Add a Cloud-Managed FireCluster

Applies To: Cloud-managed Fireboxes

You can manage a FireCluster in WatchGuard Cloud.

To add a cloud-managed FireCluster, use one of these methods:

  • Method 1 — Add two Fireboxes with factory-default settings as a cloud-managed FireCluster.
  • Method 2 — Change a locally-managed active/passive FireCluster to cloud management.

You cannot change a cloud-managed Firebox to a cloud-managed FireCluster member directly. You must first remove the device from cloud management so that it is locally managed, configure a locally-managed cluster, add the FireCluster to WatchGuard Cloud as a locally-managed cluster with visibility, and then change the FireCluster to cloud management. For more information, go to Change a Cloud-managed Firebox to a Cloud-managed FireCluster Member.

After you add a cloud-managed FireCluster, you can manage the configuration only in WatchGuard Cloud. You cannot manage the FireCluster with WatchGuard System Manager, Fireware Web UI, or the Command Line Interface (CLI).

Cloud-managed FireClusters use active/passive mode. You cannot add a cloud-managed FireCluster in active/active mode.

Change a Cloud-managed Firebox to a Cloud-managed FireCluster Member

To change a single cloud-managed Firebox to a cloud-managed FireCluster member, you must:

  1. Remove the device from cloud management so that it is locally managed.
  2. Configure a locally-managed cluster.
  3. Add the FireCluster in WatchGuard Cloud as a locally-managed cluster with visibility, and then change the FireCluster to cloud management.

The deployment history of a cloud-managed Firebox is no longer available after you add the device to a cloud-managed FireCluster. This means that when you complete the configuration of a cloud-managed FireCluster, you cannot revert to earlier deployment versions of the cloud-managed Firebox.

For information about how FireCluster works, see About FireCluster in WatchGuard Cloud.

Before You Begin

Before you add a cloud-managed FireCluster, learn about requirements and plan your configuration. For information about FireCluster requirements, see Before You Configure a Cloud-Managed FireCluster in WatchGuard Cloud.

Both Fireboxes must run Fireware v12.8.2 or higher (or v12.5.11 or higher for T30, T35, T50, M200, and M300 Fireboxes).

Method 1 — Add a New Cloud-Managed FireCluster

If you have two Fireboxes that you have not yet configured as a FireCluster, use the method described in this section. Both Fireboxes must have factory-default settings.

If you previously added a locally-managed FireCluster to WatchGuard Cloud for visibility, use Method 2.

Add the FireCluster

Configure the Connection to WatchGuard Cloud (Static IP Address)

If you selected the static IP address option in the Add Device Wizard, you must connect locally to one of the Fireboxes to configure a connection between the Firebox and WatchGuard Cloud. Use one of these methods:

  • Web Setup Wizard — Manually specify the connections settings in the Web Setup Wizard, which is part of the local operating system on the Firebox.
  • USB drive — Download and save a preconfigured connection settings file to a USB drive. The Firebox uses the file to automatically configure the connection settings. The USB drive must be formatted with the FAT or FAT32 file system. If the USB drive has more than one partition, Fireware only uses the first partition.

Complete the Cable Configuration

After you add the FireCluster, complete the cable configuration:

  1. Remove the interface 1 cable from your computer.
  2. Connect the interface 1 cable to your network equipment. For information about cabling and network topology, see Connect the Hardware for a Cloud-Managed FireCluster.

Verify the Connection to WatchGuard Cloud

After you complete the cable configuration, verify the FireCluster connection to WatchGuard Cloud. For more information, see the Device Summary page.

Screen shot of the Device Summary page for a Firebox with FireCluster status

Only the cluster master connects to WatchGuard Cloud. The status of the cluster master is Connected. The status of the backup master is Never Connected or Not Connected.

Method 2 — Change a Locally-Managed FireCluster to a Cloud Management

If you previously added a locally-managed FireCluster to WatchGuard Cloud for visibility, you can change the FireCluster to cloud management.

After you change the management type and deploy the change, the cloud-managed configuration replaces the locally-managed configuration on the Firebox. You can no longer locally manage the FireCluster in WatchGuard System Manager or Fireware Web UI.

Manage the FireCluster

After you add a cloud-managed FireCluster, you can:

Related Topics

About FireCluster in WatchGuard Cloud

Change the FireCluster Management Type

Remove a FireCluster from WatchGuard Cloud

Configure an RMA Replacement for a Cloud-Managed FireCluster Member

Copy Configuration Settings from a Cloud-Managed Device