Add a Cloud-Managed Firebox to WatchGuard Cloud

Applies To: Cloud-managed Fireboxes, Locally-managed Fireboxes

Some of the features described in this topic are available only to participants in the WatchGuard Cloud Beta program. If a feature described in this topic is not available in your version of WatchGuard Cloud, it is a beta-only feature.

To manage a Firebox configuration from WatchGuard Cloud, you must add the Firebox to WatchGuard Cloud as a cloud-managed device. You can manage a cloud-managed Firebox from WatchGuard Cloud only.

When you add a cloud-managed Firebox, you create a new configuration in WatchGuard Cloud through one of these methods:

For information about how to change an existing Firebox from local management to cloud management, go to Change a Locally-Managed Firebox to Cloud Management.

For best practices on how to change your locally-managed Firebox to cloud management, go to the Firebox Migration to Cloud Management Guide.

Caution: Do not reset a cloud-managed Firebox to factory-default settings as a general troubleshooting step. It rarely resolves issues and breaks the WatchGuard Cloud management connection. After you reset the Firebox, the device cannot reconnect because of a WatchGuard Cloud key mismatch. Recovery might require you to remove and re-add the device to WatchGuard Cloud, which can result in the loss of configuration and logs.

Before You Begin

Before you add a Firebox to WatchGuard Cloud, make sure that:

  • You have activated the Firebox in your WatchGuard account. For more information, go to Activate a WatchGuard Firebox.
  • The Firebox has a valid Standard Support license (Fireware v12.9 or higher) or a current Total Security Suite or Basic Security Suite subscription.
  • The Firebox is allocated to a Subscriber account (Service Providers only). For more information, go to Allocate Fireboxes.
  • The Firebox is connected to the network and has reliable access to the Internet.

Your operator role determines what you can see and do in WatchGuard Cloud. Your role must have the Devices permissions to view or configure this feature. For more information, go to Manage WatchGuard Cloud Operators and Roles.

To add a Firebox as a cloud-managed device, it must meet these requirements:

Add a Cloud-Managed Firebox to WatchGuard Cloud

When you add a Firebox to WatchGuard Cloud as a cloud-managed device, you configure the device name, time zone, external network settings, wireless settings, and device passwords. WatchGuard Cloud automatically configures other device settings with secure defaults.

To add a Firebox to WatchGuard Cloud as a cloud-managed device:

  1. Log in to your WatchGuard Cloud account.
  2. For Service Provider accounts, from Account Manager, select My Account.
  3. Select Monitor > Devices or Configure > Devices.
  4. Click Add Device.
    A list of activated Fireboxes opens.

    If the device is activated but does not appear in the list, make sure the Firebox is allocated to a Subscriber account if you are a Service Provider. For more information, go to Allocate Fireboxes.

  1. Select the Firebox you want to add, or click The Options menu icon then select Add Device.
    A confirmation dialog box opens.

Screenshot of the Add Device wizard with a Firebox selected

  1. Click Add Device.
    The Add Device to WatchGuard Cloud page opens.

Screen shot of the Add Device page with the Cloud Management option selected

  1. From the Device Management drop-down list, select Cloud-Managed, then click Next.
    The Cloud Management page opens.
  2. From the Configuration Type drop-down list, select one of these configuration types:
    • Create a New Configuration
    • Copy a Configuration from Another Cloud-Managed Firebox
    • Upload an .XML Configuration File

Screen shot of the Add Device wizard with the new or copy configuration selection

Firebox Default Configuration Settings

The initial configuration for a cloud-managed Firebox includes these settings:

Networks:

  • External (Interface 0) — IP address settings you configured
  • Internal (all other interfaces, bridged) — IP address 10.0.1.1/24
  • Guest (wireless, if supported and enabled) — IP address 10.0.1.2/24

Policies:

  • Outgoing — Allows outbound TCP, UDP, and Ping connections from the internal network to the external networks
  • Guest — Allows outbound TCP, UDP, and Ping connections from guest networks

Security Services:

  • Security Services are enabled in the default policies

After you add the cloud-managed Firebox, you can edit the configuration and deploy the updated configuration for the Firebox to download.

Connect the Firebox

Connect the Firebox to a network with reliable Internet access. The steps to set up and connect the Firebox depend on how the Firebox gets an IP address for the external interface.

To connect a Firebox that can use DHCP to get an IP address:

  1. Connect interface 0 to the network.
  2. Start the Firebox with factory-default settings.
    The Firebox automatically tries to connect to WatchGuard Cloud to download its configuration.

For steps to reset the Firebox to factory-default settings, go to Reset a Firebox.

If your Firebox cannot get an address through DHCP, you can use the Web Setup Wizard to configure connection settings, or you can use the connection settings file.

To use the Web Setup Wizard:

  1. Connect Firebox interface 0 to a network with Internet access.
  2. Start the Firebox with factory-default settings.
  3. Connect Firebox interface 1 to your computer.
  4. Open a web browser and go to https://10.0.1.1:8080.
  5. Log in with the user name admin and the passphrase readwrite.
  6. Select Cloud-Managed as the configuration method.
  7. Configure external network settings required for the Firebox to connect to your network.
    The Firebox uses these settings to connect to the local network, and then connects to WatchGuard Cloud to download its configuration.

For information about how to use the connection settings file to set up your Firebox, go to Use a USB Drive to Configure Interface Settings.

Automatic Fireware Upgrade

The minimum version of Fireware required for WatchGuard Cloud to deploy a configuration might be higher than the version currently installed on the Firebox. The minimum Fireware version required for cloud management is Fireware v12.5.7 (M Series) or Fireware v12.6.4 (T Series).

The first time the Firebox connects, WatchGuard Cloud determines whether your Firebox requires an upgrade before it can download the configuration. If an upgrade is required (for example, v12.5.4 to v12.5.6 or v12.6.1 to v12.6.3), WatchGuard Cloud automatically upgrades the Firebox to the latest Fireware version for cloud management. After the upgrade is complete, the Firebox connects to WatchGuard Cloud to download the configuration.

Verify the Firebox Status

After you connect the Firebox, verify the Firebox connection status and other summary information on the Device Summary page and Live Status page.

For more information, go to:

Related Topics

About the WatchGuard Cloud User Interface

Recover the Firebox Connection to WatchGuard Cloud

Add FireboxV to WatchGuard Cloud (Cloud-Managed)

Add Firebox Cloud to WatchGuard Cloud (Cloud-Managed)

(Video) Cloud-Managed Firebox: Configuration Overview

Get Started with Cloud-Managed Fireboxes

Copy Configuration Settings from a Cloud-Managed Firebox