Creating VPN with SSL on a Watchguard

Creating VPN with SSL on a Watchguard

The following is a high level review of how to activate and connect to a VPN with SSL on your Watchguard. Your network configuration may vary from these default settings. This configuration is useful to have remote users connect to your office network from home. Computers that connect in this way will behave as if they are on the office network. This means that if your server is on the same office network, users would connect to the server using it's local/private IP. If your server is in a hosted environment, you could connect to the public address of the server. 


  1. Log into your Watchguard. You will need the following
    1. Private or Public IP of the Watchguard
      1. You can find the private IP of the Watchguard device by running cmd in windows and entering ipconfig. The default gateway address is likely the private IP address of the Watchguard
      2. The Public IP address will likely be the Public IP address of your office. The Watchguard has a list of addresses that can access this public gateway. If the Public IP you are connecting from is not in that list of IP addresses, Contact DAKCS to see if we can assist.
    2. Once you can see the gateway, You will need your Admin Credentials.


  2. From the dashboard, Navigate to VPN> Mobile VPN with SSL 

  3. Check the 'Activate Mobile VPN with SSL' box


  4. Select the following values
    1. As a customer you are responsible for determining the most appropriate settings since this will have a direct effect on 
      how your machines traffic is monitored and routed. The settings listed below offer only 1 solution that may not meet 
      your needs!
    2. Primary: Public IP of your office
    3. method to send traffic through the VPN tunnel: Routed VPN traffic
    4. click the button to 'allow access to all Trusted, Optional, and custom networks'


    5. Virtual IP Address Pool: You can find this from the Watchguard dashboard under NETWORK> Interfaces> the IPv4 address for the Trusted interface


  5. Click the DNS/WINS tab, enter the following addresses, and click add
    1. If you have a specific DNS you would like to use, you may. We have listed google's public DNS below. 
    2. 8.8.8.8
    3. 8.8.4.4

    4. Click SAVE

  6. Add a VPN user
    1. From the dashboard, navigate to AUTHENTICATION> Servers> Firebox-DB

    2. In the 'Firebox Users' section, Click Add
    3. Fill out the form as follows.
      1. As a customer you are responsible for determining the most appropriate settings since this will have a direct effect on 
        how your machines traffic is monitored and routed. The settings listed below offer only 1 solution that may not meet 
        your needs!
      2. Session Timeout: 8 hours (default value)
      3. Idle Timeout: 30 Minutes (default value)
      4. Leave 'enable login limits for each user or group' un-selected
      5. Click Ok
      6. Click Save


  7.  Download the VPN client onto the computer that needs to connect remotely
    1. From the computer that needs to connect remotely go to the following web address and login with the user account you created


    2. Download and install the vpn client for widows. You can add a desktop icon and launch the application at the end of the install.


    3. Fill out the following in the client
      1. Server: the Public IP address of your office
      2. User name: the user name you created
      3. Password: the password for the user you just created
      4. you may have the client remember your password as well. 
      5. If it asks if you want to proceed say yes
      6. After a moment you should get a notification that the VPN is connected


  8. Repeat from section 6 as needed for additional users. 


    Your network configuration may vary from these default settings. The help menu in the Watchguard device is a great resource as well. DAKCS is happy to answer any questions.