<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The ranting of an IT Professional &#187; WatchGuard</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-rant/tag/watchguard/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-rant</link>
	<description></description>
	<lastBuildDate>Mon, 19 Sep 2011 18:30:04 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Incompatibility on Site to site VPN tunnels between Watchguards and Cisco ASA&#8217;s</title>
		<link>http://itknowledgeexchange.techtarget.com/it-rant/incompatibility-on-site-to-site-vpn-tunnels-between-watchguards-and-cisco-asas/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-rant/incompatibility-on-site-to-site-vpn-tunnels-between-watchguards-and-cisco-asas/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 16:09:44 +0000</pubDate>
		<dc:creator>Jason Tramer</dc:creator>
				<category><![CDATA[ASA]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[WatchGuard]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-rant/incompatibility-on-site-to-site-vpn-tunnels-between-watchguards-and-cisco-asas/</guid>
		<description><![CDATA[I have been working with a client with multiple sites and up until recently they have been using Watchguards at all sites. Recently we have been switching out some of the Watchguard for Cisco ASA&#8217;s but there have been a ton of site to site VPN issues. For example, a tunnel goes down, so you [...]]]></description>
				<content:encoded><![CDATA[<p>I have been working with a client with multiple sites and up until recently they have been using Watchguards at all sites. Recently we have been switching out some of the Watchguard for Cisco ASA&#8217;s but there have been a ton of site to site VPN issues. For example, a tunnel goes down, so you re-key it, it doesn&#8217;t come back up, but if you recreate then tunnel on the watchguard side with the exact same settings everything works fine. What is the point of having a Standard if companies aren&#8217;t following it. Yeesh.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-rant/incompatibility-on-site-to-site-vpn-tunnels-between-watchguards-and-cisco-asas/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Improvements in Watchguard 11 quick setup wizard</title>
		<link>http://itknowledgeexchange.techtarget.com/it-rant/improvements-in-watchguard-11-quick-setup-wizard/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-rant/improvements-in-watchguard-11-quick-setup-wizard/#comments</comments>
		<pubDate>Fri, 11 Sep 2009 13:37:19 +0000</pubDate>
		<dc:creator>Jason Tramer</dc:creator>
				<category><![CDATA[11 XTM]]></category>
		<category><![CDATA[DHCP]]></category>
		<category><![CDATA[quick setup wizard]]></category>
		<category><![CDATA[WatchGuard]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-rant/improvements-in-watchguard-11-quick-setup-wizard/</guid>
		<description><![CDATA[One thing that Watchguard did well in there new software version was to include the option to enable DHCP as part of the quick setup wizard. Here is why this is great. Previously you would start up your watchguard in safe mode and hook your computer to it. You would then get an IP address [...]]]></description>
				<content:encoded><![CDATA[<p>One thing that Watchguard did well in there new software version was to include the option to enable DHCP as part of the quick setup wizard. Here is why this is great. Previously you would start up your watchguard in safe mode and hook your computer to it. You would then get an IP address from it (10.0.0.2) which you could use to start your quick setup wizard. You would then configure the internal interface with the IP you would actually want and the reboot the watchguard. However previously DHCP was always off meaning you would then have to go and manually configure an IP address on your machine to match what you configured the internal interface as if you wanted to continue. Needless to say this was a pain in the butt.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-rant/improvements-in-watchguard-11-quick-setup-wizard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Upgrading to Watchguard Fireware 11</title>
		<link>http://itknowledgeexchange.techtarget.com/it-rant/upgrading-to-watchguard-fireware-11/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-rant/upgrading-to-watchguard-fireware-11/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 18:52:36 +0000</pubDate>
		<dc:creator>Jason Tramer</dc:creator>
				<category><![CDATA[10.2]]></category>
		<category><![CDATA[11]]></category>
		<category><![CDATA[firebox]]></category>
		<category><![CDATA[Fireware]]></category>
		<category><![CDATA[Upgrade]]></category>
		<category><![CDATA[WatchGuard]]></category>
		<category><![CDATA[XTM]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-rant/upgrading-to-watchguard-fireware-11/</guid>
		<description><![CDATA[In reviewing the release notes on the site and speakign to a watchguard rep the best upgrade path to the new fireware XTM version 11 is by first upgrading your existing firebox to version 10.2.9 and then upgrading to 11. Upgrading directly from any version below 10.2.9 is not recommended and could cause the upgrade [...]]]></description>
				<content:encoded><![CDATA[<p>In reviewing the release notes on the site and speakign to a watchguard rep the best upgrade path to the new fireware XTM version 11 is by first upgrading your existing firebox to version 10.2.9 and then upgrading to 11.</p>
<p>Upgrading directly from any version below 10.2.9 is not recommended and could cause the upgrade to cause the fireware image to become corrupted</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-rant/upgrading-to-watchguard-fireware-11/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fireware 11 has been released!</title>
		<link>http://itknowledgeexchange.techtarget.com/it-rant/fireware-11-has-been-released/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-rant/fireware-11-has-been-released/#comments</comments>
		<pubDate>Thu, 20 Aug 2009 13:33:18 +0000</pubDate>
		<dc:creator>Jason Tramer</dc:creator>
				<category><![CDATA[11]]></category>
		<category><![CDATA[12]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[Fireware]]></category>
		<category><![CDATA[known issue]]></category>
		<category><![CDATA[WatchGuard]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-rant/fireware-11-has-been-released/</guid>
		<description><![CDATA[So in the past I have criticized Watchguard a tad when they constantly give me the answer that my issue is a known bug and will be fixed in the next version &#8230; Well the next version is here! Fireware 11 has been released to the general public. I will get trying it out in [...]]]></description>
				<content:encoded><![CDATA[<p>So in the past I have criticized Watchguard a tad when they constantly give me the answer that my issue is a known bug and will be fixed in the next version &#8230;</p>
<p>Well the next version is here! Fireware 11 has been released to the general public. I will get trying it out in the coming days and reporting back here but a quick look in my IT crystal ball tells me that Watchguard will have indeed fixed all those little bugs which plagued my existence for so many months. Before Watchguard draws too much succor from my words I should also point out that my IT crystal ball tells me that I will be soon plagued with a ton of new bugs which won&#8217;t be fixed till version 12 comes out.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-rant/fireware-11-has-been-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watchguard MUVPN not working due to Mcafee firewall</title>
		<link>http://itknowledgeexchange.techtarget.com/it-rant/watchguard-muvpn-not-working-due-to-mcafee-firewall/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-rant/watchguard-muvpn-not-working-due-to-mcafee-firewall/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 20:45:07 +0000</pubDate>
		<dc:creator>Jason Tramer</dc:creator>
				<category><![CDATA[firewall]]></category>
		<category><![CDATA[mcaffee]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[WatchGuard]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-rant/watchguard-muvpn-not-working-due-to-mcafee-firewall/</guid>
		<description><![CDATA[I hate personal firewall products but none so much as I hate mcafee. I was testing a MUVPN and the tunnell just wouldn&#8217;t established. I turned that thing into swiss cheese, it shouldn&#8217;t have been blocking anything but the VPN tunnel STILL wouldn&#8217;t come up until I actually turned off the service. Gah it&#8217;s frustrating.]]></description>
				<content:encoded><![CDATA[<p>I hate personal firewall products but none so much as I hate mcafee. I was testing a MUVPN and the tunnell just wouldn&#8217;t established. I turned that thing into swiss cheese, it shouldn&#8217;t have been blocking anything but the VPN tunnel STILL wouldn&#8217;t come up until I actually turned off the service. Gah it&#8217;s frustrating.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-rant/watchguard-muvpn-not-working-due-to-mcafee-firewall/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>A review of the Cisco ASA 5505</title>
		<link>http://itknowledgeexchange.techtarget.com/it-rant/a-review-of-the-cisco-asa-5505/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-rant/a-review-of-the-cisco-asa-5505/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 18:28:59 +0000</pubDate>
		<dc:creator>Jason Tramer</dc:creator>
				<category><![CDATA[ASA5505]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[WatchGuard]]></category>
		<category><![CDATA[X10e]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-rant/a-review-of-the-cisco-asa-5505/</guid>
		<description><![CDATA[I deal with a lot of small business&#8217;s and branch offices and up until now we generally have been promoting the Watchguard X10e for their firewall needs. However I have recently been very impressed with the Cisco ASA 5505 for this business space. Its got great functionality, robustness and the price point is far cheaper [...]]]></description>
				<content:encoded><![CDATA[<p>I deal with a lot of small business&#8217;s and branch offices and up until now we generally have been promoting the Watchguard X10e for their firewall needs. However I have recently been very impressed with the Cisco ASA 5505 for this business space. Its got great functionality, robustness and the price point is far cheaper then I think most people might realize. For 10 user license pack CDW is retailing a unit a 414 dollars! For a Cisco partner such as my company we can usually do even better.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-rant/a-review-of-the-cisco-asa-5505/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watchguard Edge devices missing ping utility</title>
		<link>http://itknowledgeexchange.techtarget.com/it-rant/watchguard-edge-devices-missing-ping-utility/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-rant/watchguard-edge-devices-missing-ping-utility/#comments</comments>
		<pubDate>Mon, 12 Jan 2009 20:27:03 +0000</pubDate>
		<dc:creator>Jason Tramer</dc:creator>
				<category><![CDATA[Edge]]></category>
		<category><![CDATA[missing ping utlitly]]></category>
		<category><![CDATA[ping]]></category>
		<category><![CDATA[WatchGuard]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-rant/?p=57</guid>
		<description><![CDATA[The ability to ping from a firewall is a fantastic and some might say essential tool for troubleshooting network (in particular routing) issues. It is for this reason that pretty much every major commercial firewall product out there has this ability (even Sonicwalls). Yet for some reason the Watchguard Edge&#8217;s do not. Why this is [...]]]></description>
				<content:encoded><![CDATA[<p>The ability to ping from a firewall is a fantastic and some might say essential tool for troubleshooting network (in particular routing) issues. It is for this reason that pretty much every major commercial firewall product out there has this ability (even Sonicwalls). Yet for some reason the Watchguard Edge&#8217;s do not. Why this is I have no idea, I could speculate but it wouldn&#8217;t be very complimentary.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-rant/watchguard-edge-devices-missing-ping-utility/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SSO agent update for Watchguards</title>
		<link>http://itknowledgeexchange.techtarget.com/it-rant/sso-agent-update-for-watchguards/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-rant/sso-agent-update-for-watchguards/#comments</comments>
		<pubDate>Fri, 21 Nov 2008 20:52:45 +0000</pubDate>
		<dc:creator>Jason Tramer</dc:creator>
				<category><![CDATA[SSO]]></category>
		<category><![CDATA[WatchGuard]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-rant/sso-agent-update-for-watchguards/</guid>
		<description><![CDATA[So a couple days after I complain about Watchguard having a broken SSO agent they release an update! Perhaps they read my blog? In any case before all they had was an agent which gets installed on a server, now they have both an agent and client. The client runs in the background and facilitates [...]]]></description>
				<content:encoded><![CDATA[<p><!--[if gte mso 9]&gt;     Normal   0               false   false   false      EN-US   X-NONE   X-NONE                                                     MicrosoftInternetExplorer4                                                   --><!--[if gte mso 9]&gt;                                                                                                                                                                                                                                                                                                                                                                                                                                --> <!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> <!--[if gte mso 10]&gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;}  --><span></span></p>
<p class="MsoNormal"><span>So a couple days after I complain about Watchguard having a broken SSO agent they release an update! Perhaps they read my blog? In any case before all they had was an agent which gets installed on a server, now they have both an agent and client. The client runs in the background and facilitates the passing of credentials. I will implement this in the next few days and report on how it goes.</span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-rant/sso-agent-update-for-watchguards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSO agent known issue for Watchguard firewalls</title>
		<link>http://itknowledgeexchange.techtarget.com/it-rant/sso-agent-known-issue-for-watchguard-firewalls/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-rant/sso-agent-known-issue-for-watchguard-firewalls/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 16:52:39 +0000</pubDate>
		<dc:creator>Jason Tramer</dc:creator>
				<category><![CDATA[Fireware]]></category>
		<category><![CDATA[SSO]]></category>
		<category><![CDATA[WatchGuard]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-rant/sso-agent-known-issue-for-watchguard-firewalls/</guid>
		<description><![CDATA[After troubleshooting an issue with the SSO agent causing internet disconnections for users I have discovered from Watchguard tech support that this is a known issue. It will be fixed in the next update. There are no workarounds in place other than disabling the SSO agent.]]></description>
				<content:encoded><![CDATA[<p>After troubleshooting an issue with the SSO agent causing internet disconnections for users I have discovered from Watchguard tech support that this is a known issue. It will be fixed in the next update. There are no workarounds in place other than disabling the SSO agent.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-rant/sso-agent-known-issue-for-watchguard-firewalls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watchguard &#8211; Limitation when setting up High Availability</title>
		<link>http://itknowledgeexchange.techtarget.com/it-rant/watchguard-limitation-when-setting-up-high-availability/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-rant/watchguard-limitation-when-setting-up-high-availability/#comments</comments>
		<pubDate>Mon, 20 Oct 2008 21:10:05 +0000</pubDate>
		<dc:creator>Jason Tramer</dc:creator>
				<category><![CDATA[WatchGuard]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-rant/watchguard-limitation-when-setting-up-high-availability/</guid>
		<description><![CDATA[I don&#8217;t expect the various hardware and software out there to be perfect, really I don&#8217;t. However what I do expect is when there is a limitation or problem with a product that the vendor documents it somewhere. It is such a waste of my time to fight with an &#8220;issue&#8221; for hours on end [...]]]></description>
				<content:encoded><![CDATA[<p>I don&#8217;t expect the various hardware and software out there to be perfect, really I don&#8217;t. However what I do expect is when there is a limitation or problem with a product that the vendor documents it somewhere. It is such a waste of my time to fight with an &#8220;issue&#8221; for hours on end only to find out that it is a known issue. For example with the Watchguard Core&#8217;s. When setting up High Availability mode you have to set HA to run on one of the first 4 ports. If you set it on any of the latter ports it won&#8217;t work properly. No reason for this, it just won&#8217;t work.  While this can be a little annoying it really isn&#8217;t a huge deal IF you know about in advance. Given the fact that I couldn&#8217;t find documentation on this then hopefully this blog will save you the time that I lost.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-rant/watchguard-limitation-when-setting-up-high-availability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
