FireCloud Authentication Settings

Applies To: FireCloud Internet Access

FireCloud is a beta product that is only available to participants in the WatchGuard FireCloud Beta program. To try FireCloud Internet Access, join the WatchGuard Beta test community.

To configure FireCloud, you must set up an identity provider. An identity provider is an external system that you use to manage and authenticate your FireCloud users and groups. This is how FireCloud knows which users and groups are authorized, and how the users are authenticated when they connect to FireCloud.

Configure an Identity Provider in FireCloud

Before you can configure FireCloud policies, you must set up an identity provider to authenticate your FireCloud users and groups. You can use any identity provider that supports SAML, such as AuthPoint, Microsoft Entra ID (Azure Active Directory), or Okta.

To configure an identity provider in FireCloud:

  1. Log in to WatchGuard Cloud and select Configure > FireCloud.
  2. Select the type of identity provider to use and enter the required information:
  3. Click Save.

Provide FireCloud Information to Your Identity Provider (SAML Only)

If you configure a SAML identity provider, FireCloud generates a certificate that you can provide to your identity provider. This certificate gives your identity provider the information required to identify FireCloud and makes sure that your identity provider responds only to valid authentication requests sent by FireCloud. You can download this certificate from the FireCloud Authentication page.

Screenshot of the FireCloud authentication page with the FireCloud certificate.

We recommend that you import the FireCloud certificate to your identity provider and enable signature verification.

Your identity provider might have a different name for signature verification. For example, Okta calls this setting SAML Signed Request and Entra ID calls it Verification Certificates.

If you select to use AuthPoint as your identity provider, you must also create a SAML resource in AuthPoint for FireCloud, then add the SAML resource to your existing AuthPoint authentication policies or add new AuthPoint authentications policies for the SAML resource.

Control Access to FireCloud

If you connected FireCloud to an identity provider that has more users than will use FireCloud, you can control access to FireCloud so that only some users can connect to the service and consume a user license. To do this, you disable the default FireCloud access rule and configure access rules for only the user groups that you want to have access to FireCloud. Users that do not have an access rule cannot connect to the FireCloud service and consume a license.

You can also provide the FireCloud connection manager to only the end-users that you want to use the service.

Edit FireCloud Authentication Settings or Change Identity Provider

If you change your FireCloud identity provider, FireCloud deletes all your access rules because they no longer have any groups associated with them. FireCloud prompts you for confirmation before this happens.

The default access rule is not affected.

To edit the settings for your identity provider, or to change to a new identity provider, from WatchGuard Cloud:

  1. Select Configure > FireCloud.
  2. From the navigation menu, select Authentication.

Screenshot of the FireCloud authentication page with the optino to edit authentication settings highlighted.

  1. Click Edit Authentication Settings.
  2. Make your changes, then click Save.

Related Topics

Quick Start — Set Up FireCloud