Monitor BOVPN over WireGuard

Applies To: Locally-managed Fireboxes

Some of the features described in this version of Fireware Help are only available to participants in the WatchGuard Beta program. If a feature described in this topic is not available in your version of Fireware, it is a beta-only feature.

After you configure a WireGuard branch office virtual private network (BOVPN) between Fireboxes, you can monitor peer status and verify that traffic passes between the local and remote networks. For more information about WireGuard BOVPN behavior and limitations, go to About BOVPN over WireGuard.

WireGuard does not use Internet Key Exchange (IKE) or Phase 1 and Phase 2 negotiation. Peers authenticate with public keys. The Firebox establishes WireGuard communication when you send traffic through the tunnel. You might have to generate traffic before peer status, handshake information, and route activity appear.

Monitor Tunnel Status

You can monitor the current status of a WireGuard BOVPN on the VPN Statistics page in Fireware Web UI. To view the status and any VPN diagnostic messages if a VPN tunnel connection fails, select a tunnel.

Because WireGuard establishes communication when you send traffic, generate traffic before you evaluate peer statistics and route activity.

From Fireware Web UI:

  1. Select System Status > VPN Statistics.
    The VPN Statistics page opens.
  2. Select the Branch Office VPN tab.
  3. From the drop-down list, select WireGuard Tunnels.

Screenshot of the VPN Statistics page

  1. In the Tunnels list, select a WireGuard tunnel.
  2. Verify that the tunnel status shows that the tunnel is established.
  3. Verify that the Last Handshake Time shows a recent handshake.
  4. To confirm that the Firebox sends and receives traffic through the tunnel, review the sent and received traffic statistics.

The Rekey Tunnel options on the VPN Statistics page do not apply to BOVPN over WireGuard. WireGuard rotates session keys as part of the protocol.

Firebox System Manager (FSM) and WatchGuard System Manager (WSM) show WireGuard tunnel status on the Front Panel and Device Status tabs. For more information about VPN status in FSM, go to VPN Tunnel Status and Subscription Services.

From WSM:

  1. Select the Device Status tab.
  2. Select the Firebox to examine.
  3. Expand the WireGuard tunnel entry for the Firebox.
    The tunnel status and details appear.
  4. Verify that the tunnel status shows that the tunnel is established.
  5. Verify that the Last Handshake Time shows a recent handshake.
  6. To confirm that the Firebox sends and receives traffic through the tunnel, review the sent and received traffic statistics.

From FSM:

  1. From WSM, select the Device Status tab.
  2. Select the Firebox to examine.
  3. Select Tools > Firebox System Manager.
    Firebox System Manager opens with the Front Panel tab selected.
  4. In the Firebox Status area, expand the WireGuard tunnel.
    The tunnel status and details appear.
  5. Verify that the tunnel status shows that the tunnel is established.
  6. Verify that the Last Handshake Time shows a recent handshake.
  7. To confirm that the Firebox sends and receives traffic through the tunnel, review the sent and received traffic statistics.
  8. (Optional) To verify the networks associated with the peer, expand the Allowed Resources node.

In Firebox System Manager, the rekey options that appear when you right-click do not apply to BOVPN over WireGuard. WireGuard rotates session keys as part of the protocol.

If the tunnel is not established, verify the public key, endpoint address, UDP listening port, and preshared key settings on both Fireboxes. Make sure that upstream firewalls allow UDP traffic on the configured WireGuard port.

Verify Routes

WireGuard uses allowed resources to determine which networks are reachable through each peer. When you configure allowed resources, the Firebox adds routes for those networks to the WireGuard interface.

From Fireware Web UI:

  1. Select System Status > Routes.
  2. Verify that routes for the configured allowed resources show in the routing table.
  3. Verify that the routes use the WireGuard interface.

From WSM:

  1. Select the Device Status tab.
  2. Select the Firebox to examine with FSM.
  3. Select Tools > Firebox System Manager.
    Firebox System Manager opens with the Front Panel tab selected.
  4. Select the Status Report tab.
  5. Scroll down to the Routes section.
  6. Verify that routes for the configured allowed resources show in the routing table.
  7. Verify that the routes use the WireGuard interface.

If the expected routes do not appear, verify the allowed resources configuration for the peer. For more information, go to Read the Firebox Route Tables.

Review Log Messages

To identify configuration or connectivity issues, review Firebox log messages.

Scan for log messages related to:

  • WireGuard peer connectivity and handshakes
  • Invalid public keys or public keys that are not the same
  • Preshared keys that are not the same
  • Routing issues
  • Denied traffic

From Fireware Web UI:

  1. Select System Status > Log Messages.
  2. Review log messages related to WireGuard activity.

From WSM:

  1. Select the Device Status tab.
  2. Select the Firebox to examine with FSMr.
  3. Select Tools > Firebox System Manager.
    Firebox System Manager opens with the Front Panel tab selected.
  4. Select the Traffic Monitor tab.
  5. Review log messages related to WireGuard activity.

For more information about how to read log messages, go to Read a Log Message.

Related Topics

About BOVPN over WireGuard

Configure BOVPN over WireGuard

Read the Firebox Route Tables

Read a Log Message

Monitor and Troubleshoot BOVPN Tunnels