<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Firebox - Subscription Services — WatchGuard Community</title>
        <link>https://community.watchguard.com/watchguard-community/</link>
        <pubDate>Sat, 11 Apr 2026 20:34:41 +0000</pubDate>
        <language>en</language>
            <description>Firebox - Subscription Services — WatchGuard Community</description>
    <atom:link href="https://community.watchguard.com/watchguard-community/categories/firebox-security-services/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>application rdp portal framerate issues</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4557/application-rdp-portal-framerate-issues</link>
        <pubDate>Fri, 20 Mar 2026 12:17:53 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>Abertay</dc:creator>
        <guid isPermaLink="false">4557@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hi,</p>

<p>We are looking into using the Watchguard app portal as our RDP gateway and its all working, but the framerate is very bad. <br />
On a blank desktop you dont notice it too much, but run a webgl test like 'fishtank' and it looks like its managing 5FPS when the render speed on the device is showing 60FPS.<br />
I've tried this via an M690 and an M4800 and both are the same.<br />
Native Windows RDP still isnt amazing , but its at least double the framerate and doesnt lock the browser up preventing you from clicking anything.<br />
Is there any way to tune this in Watchguard?<br />
I've tried running 256 colours, but it doesnt help.</p>

<p>ps. Its not network. We have 10Gb/s and the client tested at 900Mb/s. Latency is good too and we've tried three clients on different subnets.<br />
Client CPU is running about 10% and pleny of RAM.</p>

<p>thanks.</p>
]]>
        </description>
    </item>
    <item>
        <title>Missing feature keys</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4558/missing-feature-keys</link>
        <pubDate>Sat, 21 Mar 2026 15:33:38 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>Eugene</dc:creator>
        <guid isPermaLink="false">4558@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hello team,<br />
I wonder if anyone can help me. I inherited a pair of M760 devices from the organization that went out of business. The person who used to manage them left the country and since they used company email addresses to login to their support portal there's no way to get their feature keys. Providing I know their S/N is there a way to retrieve feature keys ? What happens when I do factory reset ?</p>
]]>
        </description>
    </item>
    <item>
        <title>subscriptions stopped updating</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4548/subscriptions-stopped-updating</link>
        <pubDate>Sun, 08 Mar 2026 12:11:00 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>Steve_E</dc:creator>
        <guid isPermaLink="false">4548@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hello</p>

<p>locally managed M270 +fw 12.11.8</p>

<p>fsm dashboard says subsciptions outdated going on awhile</p>

<p><a href="https://services.watchguard.com" rel="nofollow">https://services.watchguard.com</a> from a web browser says healthy</p>

<p>log says</p>

<p>2026-03-08 06:54:00 sigd Server response code for register: 502 <br />
2026-03-08 06:54:00 sigd register failed <br />
2026-03-08 06:54:00 sigd URL string for update status report: <a href="https://services.watchguard.com/ServiceJoined/ServiceJoined.asmx/RegisterResultJoined" rel="nofollow">https://services.watchguard.com/ServiceJoined/ServiceJoined.asmx/RegisterResultJoined</a><br />
2026-03-08 06:54:00 sigd POSTDATA for update status report: sSerialNumber=xxx&amp;sApplianceVersionNumber=12.11.8&amp;sModelNumber=M270&amp;sServiceType=AVService&amp;sResultCode=5</p>

<p>manual update button on fsm sometimes works</p>

<p>Are there other update servers to try?</p>

<p>Is this worth a shot?  Do you use it? Does it cost extra?</p>

<p><a href="https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/services/botnet/botnet_updates_c.html" rel="nofollow">https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/services/botnet/botnet_updates_c.html</a></p>

<p>WatchGuard offers Offline Signature Updates that enable you to download the latest signatures for these services directly from WatchGuard, and then use a script to manually install these files on your Fireboxes.</p>
]]>
        </description>
    </item>
    <item>
        <title>WebBlocker Exceptions not applying</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4545/webblocker-exceptions-not-applying</link>
        <pubDate>Fri, 06 Mar 2026 14:33:06 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>bhx90</dc:creator>
        <guid isPermaLink="false">4545@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hi,</p>

<p>I'm using WebBlocker to restrict Internet Access from my servers so in the WebBlocker Action I'm denying all categories and using Exceptions to allow traffic when needed.</p>

<p>Using pattern matching seems to work as expected but when I use Exact Match the exception is still blocking the traffic.</p>

<p>For example, I have an exception to allow enterpriseregistration.windows.net, but in the logs I can see the following:</p>

<p>ProxyHTTPSReq<br />
HTTPS Request<br />
disp=Deny<br />
pri=6<br />
policy=HTTPS-proxy-GSA-00<br />
protocol=https/tcp<br />
src_ip=10.10.8.3<br />
src_port=49890<br />
dst_ip=20.190.159.67<br />
dst_port=443<br />
src_intf=PROD-SERVERS<br />
dst_intf=External<br />
rc=548<br />
proxy_act=HTTPS-Client.Standard-GSA.3<br />
msg=HTTPS Request<br />
pr=https/tcp<br />
sent_bytes=199<br />
update_time=2026-03-06 14:10:18<br />
log_type=tr<br />
geo_dst=IRL<br />
rcvd_bytes=6112<br />
sig_vers=18.410<br />
wgc_cluster_id=442545<br />
action=drop<br />
msg_id=2CFF-0000<br />
app_id=0<br />
tag_name=ProxyHTTPSReq<br />
sni=enterpriseregistration.windows.net<br />
app_cat_id=0<br />
sn=C03B035EDEB47<br />
device_name=SZF-M590-PRI<br />
2CFF-0000</p>

<p>Can anyone offer some advice to get this working?  Also any general best practise advice around exceptions would also be welcome.</p>
]]>
        </description>
    </item>
    <item>
        <title>Newly Registered Site</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4520/newly-registered-site</link>
        <pubDate>Tue, 03 Feb 2026 20:18:07 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>morpheus27</dc:creator>
        <guid isPermaLink="false">4520@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>I have M270 device running v12.11.6 OS. WebBlocker blocks access to the following host. I checked their whois record. It was registered 28 years ago (in 1998). Why?</p>

<p>Reason: Category 'Newly Registered Websites' denied by WebBlocker policy 'Default-WebBlocker'.</p>

<p>Please contact your administrator for assistance.<br />
More Details:<br />
Method: GET<br />
Host: www.employerslawyer.com<br />
Path: /</p>

<p>Domain: employerslawyer.com<br />
Registered On: 1998-02-25<br />
Expires On: 2027-02-24<br />
Updated On: 2026-01-09</p>
]]>
        </description>
    </item>
    <item>
        <title>WebBlocker - classification of websites</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4496/webblocker-classification-of-websites</link>
        <pubDate>Mon, 12 Jan 2026 09:53:05 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>Fire_Smith</dc:creator>
        <guid isPermaLink="false">4496@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hello,</p>

<p>I have a question about the web blocker and the classification of websites. I am currently seeing an increase in miscategorization. In my case, this often affects small German company websites. I suspect that this is due to the use of AI, and I am wondering how this happens. Here are two examples:</p>

<p>www.pflanzenpoint-schuster.de Reason: Category “Sex” denied by WebBlocker policy “ITS-WebBlocker”   <img src="https://community.watchguard.com/resources/emoji/grimace.png" title=":#" alt=":#" height="20" /> only plants</p>

<p>www.havelwolle-naturkleidung.de Reason: Category “Nudity” denied by WebBlocker policy “ITS-WebBlocker”. <img src="https://community.watchguard.com/resources/emoji/grimace.png" title=":#" alt=":#" height="20" /> they want to sell things against nudity</p>

<p>The sites appear to have been incorrectly categorized based on a few keywords.</p>

<p>This needs to be improved urgently. Has anyone else experienced something similar?</p>
]]>
        </description>
    </item>
    <item>
        <title>Botnet service/Gmail getting blocked</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4493/botnet-service-gmail-getting-blocked</link>
        <pubDate>Tue, 06 Jan 2026 13:22:53 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>QCW_TM</dc:creator>
        <guid isPermaLink="false">4493@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hello all! Last week, I had one of our locations report problems with access Gmail, all other Google Workplace sites and services were fine, just Gmail was down. Digging around for awhile, I eventually found this is the logs:</p>

<p>2025-12-31 09:19:07 Deny 192.168.150.65 142.251.41.133 https/tcp 52709 443 Public Wifi Comcast blocked sites 52 127 (HTTPS-proxy-00)  proc_id="firewall" rc="101" msg_id="3000-0173" tcp_info="offset 8 S 2585186209 win 61690" flags="SR" duration="0" sent_pkts="1" rcvd_pkts="0" sent_bytes="52" rcvd_bytes="0" botnet="destination" geo_dst="USA"   Traffic</p>

<p>If I disable the Botnet Detection, everything works 100%. If I turn it back on, it blocks it again but once in awhile it might let it squeak through for just a second or two. I just disabled botnet detection for now and was going to tackle it when I had time.</p>

<p>But today, a second site had the same issue, I disabled botnet detection and back up and running! I have 13 different Watchguard devices, these are the only two having issues.</p>

<p>All the Watchguards are at the latest firmware.<br />
All the Watchguards have the latest Botnet definitions.<br />
It doesn't matter what interface it's on either, the Public Wifi, any Trusted networks, etc.</p>

<p>I haven't dug in yet, but wanted to ask around and see if anyone has run into this.</p>

<p>Thanks in advance!</p>
]]>
        </description>
    </item>
    <item>
        <title>Local webblocker failover</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4388/local-webblocker-failover</link>
        <pubDate>Wed, 03 Sep 2025 03:01:08 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>Steve_E</dc:creator>
        <guid isPermaLink="false">4388@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>I use a local webblocker server with a hot spare.</p>

<p>I dont see a way to auto failover if the the working vm is unavailable.</p>

<p>Is there a way?</p>
]]>
        </description>
    </item>
    <item>
        <title>Access Portal proxy Exchange and RDWeb</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/3903/access-portal-proxy-exchange-and-rdweb</link>
        <pubDate>Fri, 19 Jul 2024 14:16:49 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>schwarzenbek</dc:creator>
        <guid isPermaLink="false">3903@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hello everyone,</p>

<p>we are testing Access Portal to secure the access to our hosted services like OWA (Outlook on the Web) and RDweb and we would like to add AuthPoint for MFA later. <br />
But there are several problems we are encounting with this solution. Maybe someone here can help before I am submitting a ticket with the Watchguard support.<br />
1. Forwarding user credentials from the Access Portal to OWA is not working. The user has to reenter their credentials in the OWA login screen after they already have successfully authenticated into Access Portal.<br />
2. ActiveSync is not working. The Traffic Monitor shows something like " ...user was rejected or user doesn't exist". In my understanding request to /Microsoft-Server-ActiveSync should be bypassed from Access Portal. <br />
3. The new RDWeb HTML5 Client is not working. Does the reverse proxy in Access Portal even supports websocket connections?</p>

<p>Currently we are using Nginx as reverse proxy for all those services and it works without any problems. But Access Portal + AuthPoint looks like a good solution for easily implementing MFA for some webservices.</p>
]]>
        </description>
    </item>
    <item>
        <title>Any way to request new webblocker categories?</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4434/any-way-to-request-new-webblocker-categories</link>
        <pubDate>Mon, 20 Oct 2025 14:26:49 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>AP_ILS</dc:creator>
        <guid isPermaLink="false">4434@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>I work for a school and students are constantly trying to watch movies and tv shows from sites streaming content illegally and there doesn't seem to be a category for it.</p>
]]>
        </description>
    </item>
    <item>
        <title>Can&#39;t apply license renewal on Firebox T25 - Web UI blank, CLI commands fail</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4436/cant-apply-license-renewal-on-firebox-t25-web-ui-blank-cli-commands-fail</link>
        <pubDate>Wed, 22 Oct 2025 12:44:54 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>JMAD</dc:creator>
        <guid isPermaLink="false">4436@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hey everyone, I'm stuck trying to renew the license on a WatchGuard Firebox T25 and could really use some help.</p>

<p>The problem:<br />
•   License expired 2 days ago (Oct 21, 2025)<br />
•   Purchased new license/Feature Key<br />
•   Device shows as "Disconnected" in WatchGuard Cloud (cloud.watchguard.com)<br />
•   Can access device locally via LAN IP through web interface (<a href="https://IP:8080)" rel="nofollow">https://IP:8080)</a><br />
•   Device is in production with 2 ISPs connected</p>

<p>Current Configuration:<br />
•   Model: Firebox T25<br />
•   Firmware: 12.11.4.B719894 (just updated from 12.11.3)<br />
•   Current expired license shows as: ****CD7 (expires 10-21-2025_20:03)</p>

<p>What I've Tried:<br />
1.  Web Interface (System → Subscriptions): <br />
    - Page loads initially but then goes blank/white<br />
        - Tried multiple browsers (Chrome, Firefox, Edge) including incognito mode<br />
        - Cleared cache, accepted SSL certificates<br />
        - Problem persists even after firmware upgrade to 12.11.4</p>

<ol start="2"><li><p>WatchGuard System Manager (WSM): <br />
     - Get error: "Permissions error. Please login with the 'status' user name and password<br />
    for readonly access"<br />
    - Using correct admin credentials that work fine on web interface<br />
    - Authentication method set to "Firebox-DB"</p></li>
<li><p>CLI via PuTTY (SSH to LAN IP): <br />
    - Tried from WG# prompt: <br />
    * license feature-key add [KEY] → "Invalid input detected at '^' marker"<br />
    * feature-key add [KEY] → "Invalid input detected at '^' marker"<br />
    * license add → "Invalid input detected at '^' marker"<br />
    - Tried from WG(config)# prompt: <br />
    * feature-key add [KEY] → "Invalid input detected at '^' marker"<br />
    * license feature-key add [KEY] → "Invalid input detected at '^' marker"<br />
    - Verified with show feature-key that current license is there and automatic <br />
    synchronization is enabled</p>

<ul><li>The command feature-key exists but only has automatic-synchronization option, no <br />
add subcommand</li>
</ul></li>
<li><p>Other attempts: <br />
    - Updated firmware from 12.11.3 to 12.11.4 hoping to fix web UI issue<br />
    - Verified device has internet connectivity (both ISPs active)<br />
     - Checked System → Management Server (enabled for WatchGuard Cloud)<br />
     - Tried direct URLs like /subscriptions.html, /license_upload.html - all blank</p></li>
</ol><p>Network Status:<br />
     • Device is online with 2 ISPs connected<br />
     • Can access web interface locally via LAN IP<br />
     • Cannot reach device from WatchGuard Cloud<br />
     • Firewall policies seem correct (Firebox-to-External allowed)</p>

<p>Questions:<br />
    1.  What's the correct CLI syntax to add a feature key on Fireware 12.11.4?<br />
    2.  Why would the Subscriptions page go blank after initial load?<br />
    3.  Is there an alternative method to import the license (XML file upload, config file edit, etc.)?<br />
   4.   Could the expired license be blocking certain management functions?</p>

<p>Any help would be greatly appreciated! This device is in production and I need to get the license renewed ASAP.</p>

<p>Thanks in advance!</p>
]]>
        </description>
    </item>
    <item>
        <title>Botnet Detection is blocking Facebook today - 8/12/25</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4372/botnet-detection-is-blocking-facebook-today-8-12-25</link>
        <pubDate>Tue, 12 Aug 2025 16:31:15 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>Chaospinhead</dc:creator>
        <guid isPermaLink="false">4372@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Firebox T15-T80's<br />
FW 12.11.3</p>

<p>Apparently facebook is classified as a botnet through the current definitions.  Had half a dozen tickets from 6 different customers today had to turn botnet detection off to get facebook to work again.</p>

<p>I tried to exclude but didn't spend much time on it and it didn't work "entirely".  It worked but it was very slow, had to shut it off totally to get it to work normally.  Hope this is fixed soon!</p>
]]>
        </description>
    </item>
    <item>
        <title>Access Portal will not load, page times out</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4366/access-portal-will-not-load-page-times-out</link>
        <pubDate>Thu, 31 Jul 2025 20:24:25 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>jesse</dc:creator>
        <guid isPermaLink="false">4366@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hello,<br />
 This just started yesterday and wouldn't you know the guy who set it up went on vacation.  It's been working for a couple months and I called him and he said he made no recent changes. At first I thought it might be an issue with the interface it was being served on and so I changed it in DNS to use a different internet connection and it still doesn't load. I do not see anything on the WatchGuard Firebox that specifies what IP address or interface to use for serving the Access Portal. I tested watching the traffic monitor while I attempted a connection from my mobile phone and it gave me an error: 2025-07-31 11:54:38 Member1 Deny SOURCE DESTINATION http/tcp 4949 80 ATT-FO Firebox Denied 64 53 (Unhandled External Packet-00) proc_id="firewall" rc="101" msg_id="3000-0148" tcp_info="offset 11 S 3930871744 win 65535" geo_src="USA" geo_dst="USA" duration="0" sent_bytes="64" rcvd_bytes="0"</p>

<p>I went ahead and made a rule to allow any to connect to the destination IP over port 80 and 443. that stopped it from a deny error but it still doesn't load the portal page an now I get no message at all in traffic monitor if I filter on the source IP of my mobile.</p>

<p>I have read through the page <a href="https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/services/access%20portal/access_portal_config.html" rel="nofollow">https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/services/access portal/access_portal_config.html</a><br />
 I do not see anything there that is helpful to correct this. I tried rebooting the firebox but that did not resolve anything. <br />
 Ideas what to look for are appreciated.<br />
 - Jesse.</p>

<p>*removed IP addresses from customer post - jc.</p>
]]>
        </description>
    </item>
    <item>
        <title>How to dictate which external interface for subscription services?</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4355/how-to-dictate-which-external-interface-for-subscription-services</link>
        <pubDate>Thu, 24 Jul 2025 11:47:06 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>CraigS</dc:creator>
        <guid isPermaLink="false">4355@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>How can I define which external interface the WG subscription services (WebBlocker, DNSWatch, etc.) use? It appears that the services use the lowest numbered external interface, so when the Internet went down on that port, users were getting WebBlocker deny messages because the service was not accessible. In the case of another outage, I'd like to quickly define which external port to utilize for the services. Multi-WAN is set to routing mode.</p>

<p>We were running 12.11.2 at the time, but have since updated to 12.11.3</p>
]]>
        </description>
    </item>
    <item>
        <title>Logmein app control blocks gotowebinar</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4327/logmein-app-control-blocks-gotowebinar</link>
        <pubDate>Thu, 05 Jun 2025 19:21:22 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>phanaaekIT</dc:creator>
        <guid isPermaLink="false">4327@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>This seems to have been an issue for a while now.  If you block logmein in app control, you can no longer join or register for gotowebinar meetings.  FB 12.11.2  App Control 18.370</p>
]]>
        </description>
    </item>
    <item>
        <title>whitelisting a domain</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4291/whitelisting-a-domain</link>
        <pubDate>Thu, 01 May 2025 19:34:29 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>tantony</dc:creator>
        <guid isPermaLink="false">4291@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>A software we use keep showing the activation website is being blocked on port 443.  But I'm able to access the website on https (443).  How can I whitelist that domain on WG so I can try activating it again?  I have some domains and IPs in blocked sites, but the website its trying to activate is not on there.  Do I add the website on blocked sites exception?</p>
]]>
        </description>
    </item>
    <item>
        <title>MSSP device</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4280/mssp-device</link>
        <pubDate>Wed, 23 Apr 2025 10:30:31 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>MTLTD</dc:creator>
        <guid isPermaLink="false">4280@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hi all, is there a way to tell if a firebox is subject to a MSSP agreement?  I have recently picked up a new customer who bought a Firebox online with an expired license.  When I tried to apply a new term based license I found I couldn't ( after the license purchase was processed by WG! ) because it was a MSSP box.<br />
I have checked the existing feature key etc but nothing stands out and the serial check doesn't show it either.</p>
]]>
        </description>
    </item>
    <item>
        <title>Looks like Firmware 12.11.1 Geo-location is broken</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4239/looks-like-firmware-12-11-1-geo-location-is-broken</link>
        <pubDate>Thu, 20 Mar 2025 12:25:55 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>alankevinr1946</dc:creator>
        <guid isPermaLink="false">4239@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>We have only allowed UK to access the RDS server, since we upgraded to 12.11.1 this is now become vulnerable and geo-location is now allowing countries through that was once blocked</p>
]]>
        </description>
    </item>
    <item>
        <title>Access Portal with Authpoint - returning to Login page</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4231/access-portal-with-authpoint-returning-to-login-page</link>
        <pubDate>Sun, 16 Mar 2025 22:24:13 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>EAGSYN</dc:creator>
        <guid isPermaLink="false">4231@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>I am trying to setup up Authpoint MFA on the Access Portal on my T45. I've primarily followed this:</p>

<p><a href="https://www.watchguard.com/help/docs/help-center/en-US/Content/Integration-Guides/AuthPoint/access-portal-saml_authpoint.html" rel="nofollow">https://www.watchguard.com/help/docs/help-center/en-US/Content/Integration-Guides/AuthPoint/access-portal-saml_authpoint.html</a></p>

<p>I am to the point where I can choose Authpoint-SAML instead of Username and passphrase. I can enter my name, move to the password page, enter that and click the send Push. I receive the push on my phone and approve.</p>

<p>Then the page just moves back to the main login page. The URL then says:</p>

<p><a href="https://portal.mydomain.com/auth/login?errcode=501" rel="nofollow">https://portal.mydomain.com/auth/login?errcode=501</a></p>

<p>The logs up in the Cloud for Authpoint say the authentications are successful.</p>

<p>I thinking this is something not configured correctly on my Firebox, but I'm not sure.</p>

<p>Also, once I can get this working, how do you remove the option to use just a Name and Passphrase from the Access Portal main page?</p>

<p>Anyone have any suggestions?</p>
]]>
        </description>
    </item>
    <item>
        <title>Automatic feature key synchronization</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4233/automatic-feature-key-synchronization</link>
        <pubDate>Tue, 18 Mar 2025 13:45:16 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>ydekraoui</dc:creator>
        <guid isPermaLink="false">4233@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hi All</p>

<p>I would like to know please if anyone lately had problem with the automatic feature key synchronization. We just renewed a bunch of Firebox and it's all good on the Watchguard Cloud but this time unexpectedly the Firebox didnt not automatically retreive the new key feature as its used to do before.</p>

<p>I'll be waiting for your feedback.</p>

<p>Best regards</p>
]]>
        </description>
    </item>
    <item>
        <title>WebBlocker Cannot Block Some Website</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4234/webblocker-cannot-block-some-website</link>
        <pubDate>Thu, 20 Mar 2025 02:01:10 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>hrld</dc:creator>
        <guid isPermaLink="false">4234@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Good Day To Everyone,</p>

<p>I am just trying my luck if anyone can give me some hints or help.</p>

<p>There are websites that I cannot block. <br />
If I test the url, it will show as a category that is also "deny" in the webblocker options.<br /><img src="https://us.v-cdn.net/6029905/uploads/editor/as/h0ts9vejbuah.jpg" alt="" title="" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6029905/uploads/editor/as/h0ts9vejbuah.jpg 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6029905/uploads/editor/as/h0ts9vejbuah.jpg 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6029905/uploads/editor/as/h0ts9vejbuah.jpg 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6029905/uploads/editor/as/h0ts9vejbuah.jpg 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6029905/uploads/editor/as/h0ts9vejbuah.jpg 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6029905/uploads/editor/as/h0ts9vejbuah.jpg 2000w, https://us.v-cdn.net/6029905/uploads/editor/as/h0ts9vejbuah.jpg" sizes="100vw" /></p>

<p>I already added them to the exceptions as "deny" in which I already tried a lot of different text patterns.<br /><img src="https://us.v-cdn.net/6029905/uploads/editor/vn/l75bqwy2lz28.png" alt="" title="" srcset="https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=300, width=300/6029905/uploads/editor/vn/l75bqwy2lz28.png 300w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=600, width=600/6029905/uploads/editor/vn/l75bqwy2lz28.png 600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=800, width=800/6029905/uploads/editor/vn/l75bqwy2lz28.png 800w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1200, width=1200/6029905/uploads/editor/vn/l75bqwy2lz28.png 1200w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=1600, width=1600/6029905/uploads/editor/vn/l75bqwy2lz28.png 1600w, https://us.v-cdn.net/cdn-cgi/image/quality=80, format=auto, fit=scale-down, height=2000, width=2000/6029905/uploads/editor/vn/l75bqwy2lz28.png 2000w, https://us.v-cdn.net/6029905/uploads/editor/vn/l75bqwy2lz28.png" sizes="100vw" /></p>

<p>There are quite a lot of similar websites like this.<br />
Did I miss anything?</p>
]]>
        </description>
    </item>
    <item>
        <title>Access Portal - Reverse Proxy - OWA: Attachment size limited?</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4159/access-portal-reverse-proxy-owa-attachment-size-limited</link>
        <pubDate>Thu, 23 Jan 2025 15:13:22 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>VGBH</dc:creator>
        <guid isPermaLink="false">4159@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>It is not possible to open or download files larger than 2MB. We are using a on-premise Exchange Server.</p>

<p>For example:<br />
I want to open a PDF file. It is possible to open a PDF file smaller as 2 MB. A PDF file larger than 2MB does not open. I will see an unlimited loading bar. I can´t even Download the file.</p>

<p>With Word/Excel files:<br />
I can´t open this files in a browser, so the browser will ask me to download this files. Files larger than 2 MB can´t be downloaded.</p>

<p>It is possible to open and download this files, when I connect to OWA in LAN. The files are not broken. I tested it with several files.</p>
]]>
        </description>
    </item>
    <item>
        <title>Access Portal Remote Desktop Clients</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4104/access-portal-remote-desktop-clients</link>
        <pubDate>Tue, 10 Dec 2024 16:28:07 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>SFFC</dc:creator>
        <guid isPermaLink="false">4104@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>We have a RDSH farm with a connection broker and RD Web.</p>

<p>We have tested the Access Portal which is useful and we can connect to a RDSH server through the portal webpage.  We however cannot use the Access Portal webpage have to use the Microsoft Remote Desktop Client as we have some software which needs this application.</p>

<p>I like having something in front of the RD Web server.</p>

<p>Is there any way we can connect through the Access Portal using through the RD Client or will I have to use a reverse proxy and skip the Access Portal?</p>
]]>
        </description>
    </item>
    <item>
        <title>Firebox Crashed - Stating no Feature key installed</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4077/firebox-crashed-stating-no-feature-key-installed</link>
        <pubDate>Fri, 22 Nov 2024 16:40:42 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>RadFi</dc:creator>
        <guid isPermaLink="false">4077@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Came in this morning and my entire network was down. All machines were connected to the T25 with no network access. I always have a tab open that is connected to the firebox ui. I switched to that tab (wish i would have taken a snip) and the left menu bar was there but there was an error over the top of it saying there was no feature key installed on this box. There was more that i could not read because it was overlapping the menu. There were buttons which the labels for them i could not read, Yes, No and Cancel i think. All the lights on the box that are normally on were on but they were blinking once a second, coincidentally in the same pattern as one of my 2 switches. The other switch every light was on solid no blinking, and I only have about half of them being used. I had to reboot the firebox and when that came back up reset my second switch. All is back up and working. In case anyone is wondering yes we have a feature key full till 2026. I have made changes to it just the other day setting up Imap and Smpt policies for a new email server... This is my first box in production and it has been a tank for over a year now with no incident. I have never seen anything like this and am just trying to figure out what could cause this? Has anyone ever seen anything like this?</p>
]]>
        </description>
    </item>
    <item>
        <title>Geoloaction &amp; Authentication attempts</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4088/geoloaction-authentication-attempts</link>
        <pubDate>Fri, 29 Nov 2024 17:21:41 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>tolcheen</dc:creator>
        <guid isPermaLink="false">4088@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>M390 with 12.11 firmware.</p>

<p>I seem to have an issue with Geolocation and some watchguard functions like sslvpn, proxies for exchange and other websites. I've been getting a number of attacks lately on sslvpn and other inbound sites requiring authentication against our active directory. As an example, here is a blocked site hit from Romania from Dimension.<br />
    FWDeny, blocked sites (geolocation source), pri=4, disp=Deny, policy=WatchGuard-SSLVPN-00, protocol=https/tcp, src_ip=80.94.95.120, src_port=62928, dst_ip=50.174.117.145, dst_port=443, src_intf=2-Comcast-Fiber, dst_intf=Firebox, rc=101, pckt_len=52, ttl=114, pr_info=offset 8 S 3976651325 win 61690, duration=0; sent_bytes=52; rcvd_bytes=0, 3000-0173, geo_src=ROU; geo_dst=USA</p>

<p>My sslvpn log levels are set to Information (High), but everything else is default. At the same time, an active directory account was locked out. The IP address tried a number of different services, but all were blocked.Dimension doesn't show the account it tried</p>

<p>My big question is could the geolocation be allowing the authentication attempt, and then block the traffic? Can I raise up some log to capture it all in dimension or the cloud portal logs? Should I just open a ticket?</p>
]]>
        </description>
    </item>
    <item>
        <title>ThreatSync, Fireware Versions, Automatic Responses, and Automation Policies</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4058/threatsync-fireware-versions-automatic-responses-and-automation-policies</link>
        <pubDate>Thu, 07 Nov 2024 20:55:25 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>Paddleboat21</dc:creator>
        <guid isPermaLink="false">4058@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hi all, brand new ThreatSync user with a couple questions regarding it.  Hopefully you can help me avoid opening a new ticket!</p>

<p>First, the <a rel="nofollow" href="https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/WG-Cloud/ThreatSync/threatsync_actions_about.html">documentation says</a> "To send data to ThreatSync and receive actions, Fireboxes must run Fireware v12.9 or higher and be added to WatchGuard Cloud for logging and reporting or cloud management."  Yet I have cloud monitored Fireboxes still running 12.5 (updates are planned!) that are sending data to ThreatSync.  At that Fireware level, communication is only one way, correct?  Or is the documentation out of date?</p>

<p>Second, if I have an Incident with a description of "Malicious IP address was detected by the Firebox" and it also says the Automatic Response was "Connection Blocked by Firebox 'Mister_Firebox'" that means that the firebox itself blocked the IP address on Mister_Firebox and only that firebox, and that my ThreatSync automation policies had nothing to do with it, right?  Because if ThreatSync had blocked the IP, I would see it under Config -&gt; ThreatSync -&gt; IPs Blocked By ThreatSync.</p>

<p>Third (and final!), I have an automation policy with a risk range of 1-10, for incident type Malicious IP and device type "Firebox." It "preforms the following action" of Block Threat Origin IP.  Yet I also see several Incidents with Automatic Response type indicating the IP was blocked, but there's no corresponding entry in the IPs Blocked by ThreatSync.  If the firebox is always going to block the IP, under what circumstances would the Malicious IP automation policy even fire?  Perfect world, if the Malicious IP was blocked by one firewall, I'd like it to be blocked on all firewalls.</p>

<p>Bonus question!  Is there a way to make a new automation policy run on historical incidents?</p>

<p>Appreciate your help!</p>
]]>
        </description>
    </item>
    <item>
        <title>Update Feature Key on Managed Firebox (MSP no longer)</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4047/update-feature-key-on-managed-firebox-msp-no-longer</link>
        <pubDate>Thu, 31 Oct 2024 08:04:25 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>TwilightComputer</dc:creator>
        <guid isPermaLink="false">4047@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>We have a Firebox T80 that was managed by an MSP. This relationship has gone sour and we now find we cannot update the Feature key as it is "locked" to their management server.</p>

<p>How can I break that management link and enter the new Feature Key ?</p>
]]>
        </description>
    </item>
    <item>
        <title>Signature update failed</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4037/signature-update-failed</link>
        <pubDate>Thu, 24 Oct 2024 15:48:40 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>LewisAofM</dc:creator>
        <guid isPermaLink="false">4037@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hi - for the Gateway Antivirus signatures, I tried to update them through WSM and I am getting "The signature update failed: An error occurred when downloading the signature file (9)".  Any ideas?  Running an M290 on v12.10.4.B702217 with FSM version 12.10.4-B699520.  Right now it shows the installed version is 20241021.345 and I am trying to update to 20241024.445.</p>

<p>Thanks.</p>

<p>Lewis.</p>
]]>
        </description>
    </item>
    <item>
        <title>IPS subscription service</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/4006/ips-subscription-service</link>
        <pubDate>Tue, 08 Oct 2024 12:30:34 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>javipcn</dc:creator>
        <guid isPermaLink="false">4006@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>Hi Team!<br />
In terms of security audit, we need to know if IPS includes IDS functionality.<br />
Thanks in advance!!</p>
]]>
        </description>
    </item>
    <item>
        <title>Use  WebBlocker to Block Some Computers but not All ( IP Address)</title>
        <link>https://community.watchguard.com/watchguard-community/discussion/3888/use-webblocker-to-block-some-computers-but-not-all-ip-address</link>
        <pubDate>Wed, 10 Jul 2024 20:41:07 +0000</pubDate>
        <category>Firebox - Subscription Services</category>
        <dc:creator>ncharlie99</dc:creator>
        <guid isPermaLink="false">3888@/watchguard-community/discussions</guid>
        <description><![CDATA[<p>I want to restrict  by using WebBlocker certain IP addresses in my office.  That is, for my employees who waste time on the internet.   I have used Webblocker before, but most employees do not abuse the internet (some need full access) and I do not need to block everyone.  I just need to block certain computers  in my office from accessing the all the internet.</p>

<p>I do not see how Webblocker can do this.</p>

<p>Anyone have any ideas?<br />
Thanks</p>
]]>
        </description>
    </item>
   </channel>
</rss>
