Back to Networking

WatchGuard VPN

Site-to-site and mobile VPN

Branch Office VPN (BOVPN)

Site-to-site IPsec tunnels between WatchGuard devices or third-party firewalls.

Configuration Steps

  1. 1. Go to VPN > Branch Office VPN
  2. 2. Add new gateway with peer IP and shared secret
  3. 3. Configure Phase 1 settings (IKE version, encryption)
  4. 4. Add tunnel with local and remote networks
  5. 5. Configure Phase 2 settings (ESP encryption)
  6. 6. Create Any policies for VPN traffic

Recommended Settings

SettingValue
IKE VersionIKEv2 (preferred)
Phase 1 EncryptionAES-256
Phase 1 HashSHA-256
DH GroupGroup 14 or higher
PFSEnable with same DH group

Mobile VPN

Remote user VPN options for secure access.

VPN Types

TypeBest For
SSL VPNBrowser-based access, no client install
IKEv2Native client support (Windows, macOS, iOS)
IPSecLegacy compatibility, WatchGuard client
L2TPWide device support (legacy)

Authentication

  • * Local Firebox users
  • * RADIUS (integrates with AD)
  • * LDAP/Active Directory directly
  • * AuthPoint MFA (recommended)

Troubleshooting

Common Issues

  • Tunnel won't establish:
    • * Verify PSK matches on both ends
    • * Check Phase 1/2 settings match
    • * Ensure UDP 500/4500 is open
  • Traffic not passing:
    • * Verify tunnel routes are correct
    • * Check for overlapping subnets
    • * Review BOVPN-Allow policies
  • Intermittent drops:
    • * Enable DPD (Dead Peer Detection)
    • * Check for NAT-T issues
    • * Review lifetime settings