Best Of
Re: Seeing past and current VPN statistics
In the Executive Summary -> Top Client list, you can select View All.
The resulting list will include VPN users. Then you can see info for a user by selecting that user's entry.
You can see the info for a specific VPN user in Dimension -> Per client reports -> Summary, where you need to enter a specific VPN user's IP addr or VPN connection name.
There is no way to see a complete list of just VPN users for the time period selected other than via the Executive Summary.
There is no info for the start time or end time of client VPN sessions.
Re: Seeing past and current VPN statistics
This page describes the tabs that you see on the Dimension main page:
About the Home Pages
https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/dimension/home_d.html
The VPNs tab is for Dimension Command: "From the VPNs page you can create and manage VPNs between the connected Fireboxes that Dimension manages."
Re: Set fixed IP with OpenVPN client
You can't reserve an IP for a client, but like Bruce mentioned, you can set a policy for that user or group.
See:
(About Mobile VPN with SSL Policies)
https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/mvpn/ssl/mvpn_ssl_policies.html
Even if this is for one user, I would suggest using a group for the policy. This is because usernames can be typed any way, such as 'james' 'James' or "JAMES." The group will always return the same way.
Re: Set fixed IP with OpenVPN client
For SSLVPN etc., you can assign them by user ID or by authentication group names, and have policies for those user IDs or group names.
For the IPSec client, you can create multiple Groups, and you can have a Group with a single Virtual IP addr - thus for a specific user with a known IP addr.
Support for L2TP is being removed in the future supposedly. IKEv2 is the new direction here.
Re: Seeing past and current VPN statistics
The Web UI VPN Statistics -> Mobile VPN tab will show connected client VPN sessions, but not session connection time nor utilization.
You can see current VPN client connections in WatchGuard System Manager (WSM) -> Firebox System Manager (FSM) -> Authentication List -> Mobile VPN Users, which will include session connection time but not utilization.
You should also be seeing client VPN info in Dimension.
To see utilization in Dimension, you need to have Logging enabled on policies which allow traffic. In this case for policies which allow client VPN session connections.
Re: Cloud Managed Firebox: Copy whole config from one firebox to another
Hello everyone,
just for your information: support told me, that this feature request is already been working on.
This is already being worked on and is filed under:
FCCM-5273: Copy Configuration in the Add Device Wizard
There are quite a few aspects that have to be addressed for this to function properly however Dev is making pretty good progress on this.
so let's wait for the devs
Greetings
Re: VPN Azure AD DS
Hello,
I managed to find the problem on my own.
It comes from the Mail Nickname, the client uses this option and not the UPN.
Re: Regular, short-term WiFi disconnect on AP130s (WatchGuard Cloud)
Hi @WillD The customer in this instance never let us know if they resolved the issue. If you're running into a similar issue, I'd suggest opening a support case so that our support team can help with any disconnect issues you might have.
Re: Traffic Mgmt Action per IP
My view is:
.When a TM instance shares 8 ips, does the max limit apply to the sum of the traffic coming from those 8 ips or is it per ip? - the sum of all IPs
. When a TM instance shares 8 ips and the traffic from one of the ips exceeds the max limit, does the traffic from other 7 ips also throttled/blocked? - potentially yes
. Maximum Instance has an upper limit of 256. Does that mean Watchguard can only handle 2048 ips? - so it seems - 256 x 8
Since we have 5000 active clients, what happens to the rest? - good question
Re: SNMP for Watchguard Cloud managed Fireboxes
I'm updating case for Sage who's unavailable now. The FCCM-5288: Ability to configure SNMP was originally filed but it was now replaced with a new FCCM-6329: SNMP in FCCM both were regarding to request the SNMP support for Cloud-managed Firebox. Currently we don't have ETA yet but we would tag the case with the new FCCM so you would get notified once it's resolved in the future release.