WatchGuard VPN

WatchGuard site-to-site and mobile VPN configurations.

WatchGuardVPNIPsecNetworkingFirewall

Branch Office VPN (BOVPN)

Site-to-site IPsec tunnels between WatchGuard devices or third-party firewalls.

Configuration Steps

  1. Go to VPN > Branch Office VPN
  2. Add new gateway with peer IP and shared secret
  3. Configure Phase 1 settings (IKE version, encryption)
  4. Add tunnel with local and remote networks
  5. Configure Phase 2 settings (ESP encryption)
  6. Create Any policies for VPN traffic
SettingValue
IKE VersionIKEv2 (preferred)
Phase 1 EncryptionAES-256
Phase 1 HashSHA-256
DH GroupGroup 14 or higher
PFSEnable with same DH group

Mobile VPN

Remote user VPN options for secure access.

VPN Types

TypeBest For
SSL VPNBrowser-based access, no client install
IKEv2Native client support (Windows, macOS, iOS)
IPSecLegacy compatibility, WatchGuard client
L2TPWide device support (legacy)

Authentication

  • Local Firebox users
  • RADIUS (integrates with AD)
  • LDAP/Active Directory directly
  • AuthPoint MFA (recommended)

Troubleshooting

Common Issues

  • Tunnel won't establish:
    • Verify PSK matches on both ends
    • Check Phase 1/2 settings match
    • Ensure UDP 500/4500 is open
  • Traffic not passing:
    • Verify tunnel routes are correct
    • Check for overlapping subnets
    • Review BOVPN-Allow policies
  • Intermittent drops:
    • Enable DPD (Dead Peer Detection)
    • Check for NAT-T issues
    • Review lifetime settings