Guest access – WatchGuard Firebox

In this topic, you will learn how to configure the built-in wireless interface of a locally managed WatchGuard™ Firebox to work together with the Portnox™ Cloud captive portal for guest user authentication.

Before you begin configuring your guest SSID, you must configure the guest network in Portnox Cloud and note down the values of the fields: IP (for walled garden) and Captive Portal URL. In the Shared secret field, enter a value of 1 to 32 characters. You will enter the same value on the Firebox.

Important:
This guide gives general instructions for integrating Portnox Cloud with specific third-party devices. We try to provide useful examples for common models, but settings can differ between manufacturers, models, and environments. Because of this, we cannot guarantee these steps will work in every case. For questions or problems with RADIUS setup – which is an industry standard and not specific to Portnox – or with device-specific settings and troubleshooting, we recommend checking the device manufacturer’s documentation and contacting their support team. Portnox Support can help when possible, but detailed setup of third-party devices is usually best handled by the manufacturer. We also recommend updating your NAS device firmware to the latest version, as old firmware can cause issues.
Important:
All values in this configuration are examples. Make sure to adjust the configuration to your individual profile names, RADIUS server addresses, ports, and keys by replacing the values that are presented as underlined italics.
Important:
This topic applies only to Fireboxes managed locally in Fireware Web UI. Fireboxes managed in WatchGuard Cloud do not support external captive portals, so you cannot use them with the Portnox Cloud captive portal.
Important:
Before you start, save a backup of the current Firebox configuration. In Fireware Web UI, select System > Configuration File, and click on the Download the Configuration File link.
Note:
This configuration was tested in Fireware Web UI with a Firebox T115-W running Fireware 2026.2.3. The capabilities and the user interface on other versions of the platform may differ.

Create the guest SSID

In this section, you will enable a wireless access point for guests, configure a network for it, and configure an open SSID.

  1. Log in to Fireware Web UI with your administrative credentials.
  2. If the screen is locked, click on the lock icon at the top of the screen (Click the lock to make changes).

    The screens stay unlocked until you lock them again.

  3. In the left-hand side menu, select the Network > Wireless option.

  4. On the Wireless screen, activate the Enable Wireless checkbox and select the Enable wireless access points option.

  5. Click on the CONFIGURE button next to any access point that you do not use yet.
  6. On the Configure Network for Access Point screen, activate the Enable Access Point checkbox. Then, on the Network tab, configure the network:

    1. Leave the Interface Name (Alias) field at its default value, or enter a different name.

      The Firebox uses this name only to identify the access point interface.

    2. In the Interface Type field, select the Trusted option.
    3. In the IP Address fields, enter the IP address of the Firebox in this network and the netmask length.

      For example, enter 10.9.57.1 and 24.

      Note:
      The subnet must not overlap with any other network on the Firebox.
    4. In the field below the IP Address fields, select the DHCP Server option.
    5. In the Address Pool section, click on the ADD button, and add a range of addresses from the network subnet.

      For example, for the 10.9.57.1/24 network, add the range from 10.9.57.100 to 10.9.57.200.

  7. Click on the Wireless tab.
  8. Configure the SSID:

    1. Activate the Broadcast SSID checkbox.
    2. In the Radio field, select the bands that broadcast this SSID, as required.
    3. In the Network Name (SSID) field, enter the network name that guests see when they search for Wi-Fi networks.
    4. In the Security field, select the Open option.
  9. Click on the RETURN TO MAIN PAGE button.
  10. On the Wireless screen, click on the SAVE button.

Result: You created an open guest SSID. Until you assign the hotspot to it, guests can connect to it without authentication.

Configure the external guest authentication hotspot

In this section, you will configure the Firebox to redirect guests to the Portnox™ Cloud captive portal.

  1. In the left-hand side menu, select the Authentication > Hotspot option.

  2. Click on the External Guest Authentication tab, and configure the hotspot:

    1. Activate the Enable External Guest Hotspot checkbox.
    2. In the Shared Secret and Confirm fields, enter the Shared secret value that you entered in the guest network configuration in Portnox Cloud.
    3. In the Authentication URL and Authentication Failure URL fields, paste the Captive Portal URL that you obtained when you configured the guest network in Portnox Cloud.
    4. In the Walled Garden section, add every address from the IP (for walled garden) field that you obtained when you configured the guest network in Portnox Cloud. For each address, click on the ADD button, in the Add Walled Garden Sites dialog, leave the Host IPv4 option selected in the Choose Type field, enter the address in the Host IPv4 field, and click on the OK button.

      Warning:
      The NAS device must be able to communicate with the walled garden IP addresses at all times. If this communication is blocked in any way, the captive portal will not work, and guest devices will be unable to connect to the network. Before you proceed, verify that all firewalls, ACLs, and any other security measures that could interfere with this communication are configured to explicitly allow the walled garden IP addresses.

Result: You configured the external guest authentication hotspot. Do not click on the SAVE button yet. Fireware Web UI does not save the hotspot until you assign it to an interface.

Assign the hotspot to the guest SSID

In this section, you will assign the external guest authentication hotspot to the access point of the guest SSID, and save the hotspot configuration.

  1. In the Hotspots tab, in the Interfaces section, activate the checkbox next to the access point interface of the guest SSID.
    Important:
    Activate only the checkbox of the guest access point. If you also select another interface, for example, Internal, all users on that network will have to authenticate in the captive portal.
  2. Click on the SELECT HOTSPOT button, and select the External Guest Authentication option. Then, click on the SAVE button.

    Result: The HOTSPOT column of the access point shows External Guest Authentication.

Result: You configured an open SSID that redirects guests to the Portnox Cloud captive portal for authentication.