Quick Start — Set Up FireCloud

Applies To: FireCloud Internet Access

FireCloud is a beta product that is only available to participants in the WatchGuard FireCloud Beta program. To try FireCloud Internet Access, join the WatchGuard Beta test community.

This quick start topic reviews the general steps to configure and test FireCloud. This guide introduces FireCloud, reviews the basic components of FireCloud, and helps you get set up.

FireCloud is a fully-managed, cloud-based firewall-as a-service that protects your remote users against Internet-based security threats. You configure FireCloud in WatchGuard Cloud, and users connect to the service with the WatchGuard connection manager. While the users are connected to FireCloud, they are protected and can safely use their computer and browse the Internet.

Here is a high level overview of the steps in this quick start guide:

  1. Enable the FireCloud beta toggle.
  2. Activate a FireCloud license or start a trial.
  3. Configure FireCloud authentication settings.
    1. Configure an Identity Provider
    2. (SAML Only) Provide FireCloud Information to Your Identity Provider (SAML Only)
    3. (Optional) Control Access to FireCloud
  4. Review the default settings.
  5. Download and install the connection manager.
  6. Connect to FireCloud with the connection manager.
  7. (Optional - Service Providers Only) Create and deploy FireCloud templates.

Enable the FireCloud Beta Toggle

To get started, you must enable the FireCloud beta toggle for your account.

To enable the FireCloud beta toggle:

  1. Go to cloud.watchguard.com and log in.
  2. If you have a Service Provider account, select an account from Account Manager.
  3. Select Administration > Beta Features.
    The Beta Features page opens.
  4. Enable the FireCloud Internet Access beta toggle.

Screenshot of the FireCloud Internet Access beta toggle.

Activate a FireCloud License or Start a Trial

Before you begin, you must purchase and activate a FireCloud license or start a FireCloud trial.

If you have not already purchased a FireCloud license, we recommend that you start a free FireCloud trial in WatchGuard Cloud. For detailed steps to start a trial, go to Manage Trials – Service Providers or Manage Trials – Subscribers. All trial licenses are valid for 30 days, and can be renewed for another 30 days to a maximum of 60 days.

Screenshot of the FireCloud trials list.

We recommend that you extend your trial now to get the full 60 days. You can only extend the trial once within 30 days of the trial start date, and only before the trial expires.

If you have a WatchGuard Cloud Service Provider account and want to use FireCloud for your own account, after you activate a FireCloud license you must allocate the users to your Subscriber account. For detailed steps, go to Allocate FireCloud Users.

Configure Authentication Settings

Before you can configure FireCloud, you must set up an identity provider. An identity provider is an external system that you use to manage and authenticate your FireCloud users and groups. This is how FireCloud knows what users and groups are authorized, and how the users are authenticated when they connect to FireCloud.

Configure an Identity Provider

To configure an identity provider for FireCloud:

  1. Log in to WatchGuard Cloud and select Configure > FireCloud.
  2. Select the type of identity provider to use and enter the required information:
  3. Click Save.

You only have to configure an identity provider the first time you set up FireCloud. To edit the settings for your identity provider, or change to a new identity provider, go to the Configure > FireCloud > Authentication.

Provide FireCloud Information to Your Identity Provider (SAML Only)

If you configure a SAML identity provider, FireCloud generates a certificate that you can provide to your identity provider. This certificate gives your identity provider the information to identify FireCloud and makes sure that your identity provider responds only to valid authentication requests sent by FireCloud. You can download this certificate from the FireCloud Authentication page.

Screenshot of the FireCloud authentication page with the FireCloud certificate.

We recommend that you import the FireCloud certificate to your identity provider and enable signature verification.

Your identity provider might have a different name for signature verification. For example, Okta calls this setting SAML Signed Request and Entra ID calls it Verification Certificates.

If you select to use AuthPoint as your identity provider, you must also create a SAML resource in AuthPoint for FireCloud, and you must add the SAML resource to your existing authentication policies or add new authentications policies for the SAML resource.

Control Access to FireCloud

If you have connected FireCloud to an identity provider that has more users than will actually use FireCloud, you can control access to FireCloud so that only some users can connect to the service and consume a user license. To do this, you can disable the default FireCloud access rule and configure access rules for only the user groups that you want to have access to FireCloud. Users that do not have an access rule cannot connect to the FireCloud service and consume a license. For more information, go to FireCloud Access Rules.

You can also provide the FireCloud connection manager to only the end-users that you want to use the service.

Review the Default Settings

By default, FireCloud has all security services enabled with default configurations, and a default access rule is in place to specify which security services apply to user traffic. This means that you can deploy and use FireCloud immediately, but we recommend that you review the default settings.

Download and Install the WatchGuard Connection Manager

For FireCloud to protect your users, they must have the WatchGuard Connection Manager installed on their device and use it to connect to FireCloud.

To download the WatchGuard Agent, used to install the WatchGuard Connection Manager:

  1. Log in to WatchGuard Cloud and go to Configure > FireCloud.
  2. Select Client Download.
    The Client Download page opens.

Screenshot of the Client Download page.

  1. Click Download Installer.
    The WatchGuard Agent installer download begins.
  2. Run the downloaded installer.
  3. Click Install.
  4. When the installation is complete, click Finish.

After the WatchGuard Agent is installed, the agent automatically downloads and installs the Connection Manager. When this is finished, the Connection Manager opens and you are prompted to enter your credentials to connect to FireCloud. You use the credentials for the user account in your identity provider.

Connect to FireCloud with the Connection Manager

While you are connected to FireCloud, you are protected and can safely use your computer and browse the Internet. After you connect to FireCloud for the first time, the agent keeps your session open and you remain connected even if you restart your computer.

If you disconnect from FireCloud, you must manually log in and connect again.

To connect to FireCloud:

  1. Open the WatchGuard Connection Manager.
  2. From the system tray, click the WatchGuard Connection Manager, then select Connect.

Screenshot of the login page for the WatchGuard Connection Manager.

  1. Enter your user name or email address, then click Next.

Screenshot of the login page for the WatchGuard Connection Manager.

  1. Enter your password.

    You see a success message when you are connected to FireCloud.
  2. Click Log In.

Create and Deploy FireCloud Templates (Optional — Service Providers Only)

For Service Providers, FireCloud templates provide a way to manage shared configuration settings for multiple accounts. In a FireCloud template, you can configure FireCloud access rules and services just as you would for your FireCloud account. You can then subscribe your managed accounts to the template so that those accounts inherit configuration settings from the template.

To learn more about FireCloud templates, go to About FireCloud Templates and Manage FireCloud Templates.

See Also

About FireCloud

About the FireCloud Usage Report

See and Manage Licensed FireCloud Users