Device Feedback

Device feedback helps WatchGuard to troubleshoot and secure our services, assess the threat landscape, and comply with our legal obligations (such as export control rules). It is also used to improve our products and features. It can include information about how your Firebox is used and issues you encounter with your Firebox, but does not include any information about your company or any company data that is sent through the Firebox. Because of this, device feedback is technical in nature and mainly consists of non-identifiable information. All device feedback that the Firebox sends to WatchGuard is encrypted.

The Firebox sends three types of device feedback data to WatchGuard:

Basic Device Feedback

Your Firebox sends this basic device feedback data to WatchGuard each time the device reboots:

  • Firebox serial number
  • Firebox device model
  • IP address
  • Country
  • Fireware version
  • Fireware build number
  • Firebox uptime since the last restart
  • Hash of the device MAC address
  • Whether advanced device feedback is enabled (Fireware v12.4 or higher)

You cannot disable basic device feedback. If you clear the Send Advanced Device Feedback to WatchGuard check box, the Firebox continues to send basic device feedback data to WatchGuard.

Firebox Cloud devices do not send basic device feedback data to WatchGuard unless advanced device feedback is enabled.

Advanced Device Feedback (Optional)

When you create a new configuration file for your Firebox your Firebox is configured to send advanced device feedback to WatchGuard.

If you do not want to send advanced device feedback to WatchGuard, you can disable it at any time. To disable advanced device feedback on your Firebox, clear the Send Advanced Device Feedback to WatchGuard check box.

When the Send Advanced Device Feedback to WatchGuard check box is enabled, the Firebox sends advanced feedback data to WatchGuard in a compressed file once every six days and each time the device reboots. To conserve space on the Firebox, the advanced feedback data is removed from the Firebox after it is sent to WatchGuard.

Advanced device feedback data includes the following information:

Threat Telemetry (Optional)

When you create a new configuration file for your Firebox or upgrade your Firebox to Fireware v12.11 or higher, by default, your Firebox is configured to send threat telemetry data to WatchGuard. The WatchGuard security team uses that threat telemetry data to research and investigate the threats the Firebox detects and analyze the current threat landscape. WatchGuard then uses the anonymous aggregated data to showcase threat detection trends in the WatchGuard quarterly Internet Security Report and on the WatchGuard Cybersecurity Hub page.

This feature is only available for Fireboxes that run Fireware v12.11 or higher.

If you do not want to send threat telemetry data to WatchGuard, you can disable this feature. To disable threat telemetry feedback on your Firebox, clear the Send Threat Telemetry to WatchGuard check box.

When the Send Threat Telemetry to WatchGuard check box is enabled, the Firebox sends threat telemetry data to WatchGuard in a compressed file daily and each time the device reboots. To conserve space on the Firebox, threat telemetry data is removed from the Firebox after it is sent to WatchGuard.

Threat telemetry data can include the following information for threats detected by the security services enabled on the Firebox:

  • Incident time
  • Security service that detected the incident
  • Proxy policy that handled the traffic
  • Source IP address
  • Destination IP address
  • Type of virus detected
  • Threat level
  • Signature ID
  • MD5 value

The threat telemetry data sent to WatchGuard depends on the security service that detected the threat.