About BOVPN over WireGuard

Applies To: Locally-managed Fireboxes

Some of the features described in this version of Fireware Help are only available to participants in the WatchGuard Beta program. If a feature described in this topic is not available in your version of Fireware, it is a beta-only feature.

WireGuard is a lightweight, open-source VPN protocol that simplifies the creation and management of secure tunnels. Unlike VPN protocols such as IPSec and OpenVPN, WireGuard uses a simpler yet secure architecture that is easier to deploy and maintain.

When your Firebox runs Fireware v2026.4 or higher, you can configure a branch office virtual private network (BOVPN) tunnel that uses WireGuard for secure communication between endpoints. The Firebox implements the WireGuard tunnel as a virtual interface. The tunnel uses UDP and a configurable port.

Each WireGuard tunnel uses a public and private key pair to authenticate peers. Unlike an IPSec BOVPN tunnel, WireGuard does not use Phase 1 or Phase 2 negotiations and does not require proposal selection.

BOVPN over WireGuard is a Firebox-to-Firebox branch office VPN option that uses key-based peer authentication and a configurable UDP port. For networks that cannot pass IPSec traffic and that also cannot allow WireGuard UDP traffic, use BOVPN over Transport Layer Security (TLS) instead.

When to Use BOVPN over WireGuard

We recommend BOVPN over WireGuard when these conditions are true:

  • All endpoints are Fireboxes that run Fireware v2026.4 or higher.
  • A simpler Firebox-to-Firebox BOVPN than IPSec is preferred.
  • Your network allows UDP traffic on the configured WireGuard listening port.
  • You want to configure a site-to-site tunnel or a hub-and-spoke topology where each spoke peer points to the hub.

For more information about IPSec BOVPN tunnels, go to About Manual IPSec Branch Office VPNs. For more information about BOVPN over TLS, go to About Branch Office VPN over TLS.

Requirements

To configure a BOVPN tunnel over WireGuard:

  • You must have at least two Fireboxes that run Fireware v2026.4 or higher.
  • The Internet service provider (ISP) for each endpoint must allow UDP traffic on the configured WireGuard port.
  • Each endpoint must use a WireGuard key pair. You can optionally configure a preshared key.
  • Both endpoints must use compatible tunnel configuration settings.

Limitations

BOVPN over WireGuard has these limitations:

  • Third-party WireGuard endpoints are not supported. Both endpoints must be Fireboxes that run Fireware v2026.4 or higher.
  • Active multi-WAN failover and failback for WireGuard tunnels are not supported. If the primary WAN connection fails, WireGuard can reconnect over an available interface (passive failover).
  • BOVPN network address translation (NAT) options that apply to IPSec BOVPN tunnels do not apply to WireGuard tunnels.

Tunnel Configuration Options

BOVPN over WireGuard uses a peer-based configuration model. On each Firebox, you enable a WireGuard virtual interface and add one or more peers. Each peer configuration includes the remote endpoint address, UDP port, peer public key, and allowed resources. Optionally, you can configure a pre-shared key.

Fireware supports these common WireGuard BOVPN topologies:

Site-to-site (two Fireboxes)

Configure a WireGuard interface and one peer on each Firebox. Exchange public keys between the Fireboxes and define allowed resources for the networks that must communicate through the tunnel.

Hub-and-spoke

Configure the hub Firebox with a WireGuard interface and a peer for each spoke. Configure each spoke Firebox with a WireGuard interface and a peer that points to the hub. Allowed resources on each peer determine which networks can send traffic through that tunnel.

Unlike BOVPN over TLS, WireGuard does not use Client mode or Server mode. Each Firebox is both a WireGuard endpoint and a peer to the remote Firebox.

For detailed instructions about how to configure a WireGuard BOVPN, go to Configure BOVPN over WireGuard.

Policies

When you save a WireGuard BOVPN configuration that includes allowed resources, the Firebox automatically creates these policies:

  • WireGuard-BOVPN-Allow.in
  • WireGuard-BOVPN-Allow.out

These policies allow traffic between the local and remote networks that you specify as allowed resources for the WireGuard tunnel.

The WireGuard-BOVPN-Allow.in and WireGuard-BOVPN-Allow.out policies are specific to BOVPN over WireGuard. They are separate from the BOVPN-Allow.in and BOVPN-Allow.out policies used by IPSec BOVPN and BOVPN over TLS.

Global VPN Settings

Global VPN settings do not apply to BOVPN over WireGuard. WireGuard uses a separate configuration model with static key pairs, predefined peer configurations, and UDP transport only. It does not use IPSec or TLS VPN negotiation settings.

BOVPN Rekey Tunnel

The Rekey Tunnel options on the VPN Statistics page do not apply to BOVPN over WireGuard. WireGuard uses static key pairs and automatically rotates session keys as part of the protocol. WireGuard does not support manual rekey operations or key lifetime configuration.

License

BOVPN over WireGuard shares the SSL VPN Users license with Mobile VPN with SSL and Management Tunnel with SSL.

Related Topics

Configure BOVPN over WireGuard

Monitor BOVPN over WireGuard

Manual Branch Office VPN Tunnels

About Branch Office VPN over TLS

Branch Office VPN (Video)