Configure BOVPN over WireGuard

Applies To: Locally-managed Fireboxes

Some of the features described in this version of Fireware Help are only available to participants in the WatchGuard Beta program. If a feature described in this topic is not available in your version of Fireware, it is a beta-only feature.

In Fireware v2026.4 or higher, you can configure a WireGuard branch office virtual private network (BOVPN) tunnel between Fireboxes. WireGuard uses a peer-based configuration model. Each Firebox endpoint includes a local WireGuard interface and one or more peer definitions. When you create the WireGuard interface, the Firebox generates a public and private key pair. The Firebox stores the private key securely and shows the public key in the UI. To establish a WireGuard tunnel, configure each Firebox with the public key of the remote peer.

For more information about BOVPN over WireGuard, go to About BOVPN over WireGuard.

BOVPN over WireGuard Configuration Workflow

To create a WireGuard BOVPN tunnel between two Fireboxes, complete the configuration in this order:

  1. On each Firebox, enable WireGuard and configure a unique Interface Address for the local WireGuard interface.
  2. On each Firebox, add a peer tunnel to the remote Firebox. When you configure the peer tunnel, paste the public key from that remote Firebox, and specify the endpoint address and UDP listening port for that remote Firebox.
  3. On each Firebox, add allowed resources for the private networks behind the remote Firebox.
  4. Save the configuration on both Fireboxes.
  5. Send traffic between the private networks to initiate the tunnel, then verify peer status and routes.

On each Firebox, allowed resources are the networks behind the remote Firebox. Do not add only the local networks as allowed resources.

This example shows settings for a site-to-site WireGuard BOVPN between two Fireboxes. Use these values as a guide when you configure each peer. The WireGuard Interface Address on each Firebox must be a unique host IP address that does not conflict with any other interface network on that Firebox. The peer Interface Address must be in a different network from the local WireGuard Interface Address.

Setting Site A Firebox Site B Firebox
External interface IP address 203.0.113.2 198.51.100.2
Trusted network 192.0.1.0/24 192.1.1.0/24
WireGuard Interface Address 10.10.10.1 10.10.20.1
Listening Port 442 442
Peer Endpoint Address 198.51.100.2 (Site B) 203.0.113.2 (Site A)
Peer Interface Address 10.10.20.1 (Site B) 10.10.10.1 (Site A)
Peer UDP Port 442 442
Peer Public Key Local public key from Site B Local public key from Site A
Allowed Resources 192.1.1.0/24 (Site B trusted network) 192.0.1.0/24 (Site A trusted network)

Make sure that upstream firewalls and the ISP for each site allow UDP traffic on the WireGuard listening port. If a Firebox is behind NAT, make sure that UDP traffic on that port is forwarded to the Firebox.

Enable BOVPN over WireGuard

Configure the Tunnel on the Peer Firebox

Repeat the tunnel configuration on the peer Firebox. Use the Site A and Site B example values in the Before You Begin section as a guide:

  • Enable WireGuard and configure a unique Interface Address for the local WireGuard interface.
  • Use the public key from the first Firebox as the peer public key.
  • Configure the endpoint address and UDP listening port of the first Firebox.
  • Configure the Peer Interface Address with the WireGuard Interface Address of the first Firebox. This address must be in a different network from the local WireGuard Interface Address.
  • Configure allowed resources for the private networks behind the first Firebox (the remote networks from this Firebox).
  • If you use a pre-shared key, use the same pre-shared key on both Fireboxes.

After you configure the tunnel on both Fireboxes, send traffic between the networks included in the allowed resources to initiate the tunnel. For more information about how to monitor BOVPN status and traffic, go to Monitor BOVPN over WireGuard.

Edit or Delete a Tunnel

To add or edit an allowed resource for update tunnel settings for an existing tunnel, you can edit the tunnel settings. You can also delete tunnels.

Verify the WireGuard Tunnel

After you complete the configuration on both Fireboxes, verify that the tunnel is established and routes traffic as expected.

  1. Verify that the peer status shows that the tunnel is established, or that the Last Handshake Time shows a recent handshake.
  2. Verify that routes for the configured allowed resources show in the routing table. To view routes, select System Status > Routes. For more information, go to Read the Firebox Route Tables.
  3. Send traffic between computers on the local and remote networks that are included in the allowed resources to initiate and test the tunnel.
  4. Verify that traffic reaches the remote network and that return traffic reaches the local network.
  5. Review Firebox log messages for denied traffic, routing issues, or WireGuard handshake errors if connectivity fails. For more information, go to Read a Log Message.

For detailed instructions, go to Monitor BOVPN over WireGuard.

Related Topics

About BOVPN over WireGuard

Monitor BOVPN over WireGuard

Read the Firebox Route Tables

Read a Log Message