WatchGuard Firebox IKEv2 Always On VPN.

WG Firebox device supports IKEv2 Always On VPN — partly. With the built‑in Windows IKEv2 client, the Firebox firewall supports Microsoft Always On VPN user tunnels using MS‑CHAPv2 authentication (username and password). This tunnel starts automatically after Windows login. However, Firebox does not support certificate authentication, which is required for Microsoft Always On VPN device…

Recommended IKEv2 IPsec Encryption Settings (Best Practice)

The following IKEv2 IPsec encryption values represent the best‑practice configuration I currently use and recommend: BOVPN Phase 1: BOVPN Phase 2: Why GCM? It is strongly recommended to migrate to GCM‑based algorithms. In most environments, 128‑bit GCM provides more than sufficient security. Compared to CBC, GCM128 offers stronger practical security than CBC256, and it is…

How to configure certificates with Firebox IKEv2 VPN.

By default, a WatchGuard firewall uses its own self‑signed certificate for IKEv2. Important: WatchGuard does not support user certificates for IKEv2 login! The certificate is used only to encrypt the connection between the IKEv2 client and the firewall, so the username and password can be sent securely — similar to how HTTPS works on websites.…

How to configure Freeradius authentication with Firebox IKEv2 and on-prem Active Directory users.

If you cannot use Microsoft Windows NPS for RADIUS authentication with Firebox IKEv2 and on‑prem Active Directory users, you can use FreeRADIUS on Linux instead. In this guide, you install Ubuntu, join it to Active Directory, and install the latest FreeRADIUS. FreeRADIUS will authenticate AD users with MS‑CHAPv2. Environment example: If you need help installing…

Close