background image

Mobile VPN with IPSec client for Windows and Mac

There are several available files to download.

Shrew Soft Client

l

Shrew Soft Client 2.2.2 for Windows

- No client license required.

WatchGuard IPSec Mobile VPN Clients

The current WatchGuard IPSec Mobile VPN Client is version 12.10. There are no updates with this release.

l

WatchGuard IPSec Mobile VPN Client for Windows (32-bit), powered by NCP

- There is a

license required for this premium client, with a 30-day free trial available with download.

l

WatchGuard IPSec Mobile VPN Client for Windows (64-bit), powered by NCP

- There is a

license required for this premium client, with a 30-day free trial available with download.

l

WatchGuard IPSec Mobile VPN Client for Mac OS X, powered by NCP

- There is a license

required for this premium client, with a 30-day free trial available with download.

WatchGuard Mobile VPN License Server

l

WatchGuard Mobile VPN License Server (MVLS) v2.0, powered by NCP

- Click

here

for more

information about MVLS.

Upgrade Notes

In addition to new features and functionality introduced in Fireware v11.12, there were other changes that affect
the functionality of several existing features in ways that you need to understand before you upgrade to v11.12
or higher. In this section, we review the impact of some of these changes. For more information, see the

What's

New in Fireware v11.12

presentation or

Fireware Help

.

TCP port 4100 now used for firewall user authentication only

Beginning with Fireware v11.12, TCP port 4100 is used only for firewall user authentication. In earlier
versions, a WatchGuard Authentication policy was automatically added to your configuration file when
you enabled Mobile VPN with SSL. This policy allowed traffic over port 4100 and included the alias Any-
External in the policy From list. In Fireware v11.12, when you enable Mobile VPN with SSL, this policy
is no longer created. When you upgrade to Fireware v11.12, the External alias will be removed from your
WatchGuard Authentication policy, even if you had manually added the alias previously and regardless
of whether Mobile VPN with SSL is enabled. If you upgrade with Policy Manager, you must manually
reload the configuration from the Firebox after the upgrade completes to avoid adding the alias back with
a subsequent configuration save (since Policy Manager is an offline configuration tool).

The Mobile VPN with SSL authentication and software download pages are no longer accessible at port
4100. See Fireware Help for more information.

Setup Wizard Default Policies and Settings

You use the Web Setup Wizard or WSM Quick Setup Wizard to set up a Firebox with a basic
configuration. Beginning with Fireware v11.12, the setup wizards now configure policies and enable
most Subscription Services to provide better security by default. The setup wizards:

Upgrade Notes

12

WatchGuard Technologies, Inc.

Summary of Contents for Firebox 1500

Page 1: ...oviding several minor feature enhancements For more information on the bug fixes and enhancements in this release see the Enhancements and Resolved Issues section With this release we re also proud to...

Page 2: ...icate If you use the CLI to regenerate these certificates after you upgrade you must redistribute the new Proxy Authority certificate to your clients or users will receive web browser warnings when th...

Page 3: ...can use your existing feature key If you do not have a feature key for your device you can log in to the WatchGuard website to download it Note that you can install and use WatchGuard System Manager...

Page 4: ...s provided by third party companies remain in English Fireware Web UI The Web UI will launch in the language you have set in your web browser by default WatchGuard System Manager When you install WSM...

Page 5: ...or information on WatchGuard Dimension see the Dimension Release Notes Single Sign On Agent Includes Event Log Monitor Single Sign On Client Single Sign On Exchange Monitor1 Terminal Services Agent2 M...

Page 6: ...lient for Mac powered by NCP Authentication Support This table gives you a quick view of the types of authentication servers supported by key features of Fireware Using an authentication server gives...

Page 7: ...N client Mobile VPN with IPSec for Android devices Mobile VPN with SSL for Windows 4 4 Mobile VPN with SSL for Mac Mobile VPN with SSL for iOS and Android devices Mobile VPN with L2TP 6 Mobile VPN wit...

Page 8: ...ave WatchGuard System Manager client software only installed If you install WatchGuard System Manager and WatchGuard Server software Minimum CPU Intel Core or Xeon 2GHz Intel Core or Xeon 2GHz Minimum...

Page 9: ...install WSM v11 12 1 or to upgrade WatchGuard System Manager from an earlier version to WSM v11 12 1 Fireware OS If your Firebox is running Fireware v11 10 or later you can upgrade the Fireware OS on...

Page 10: ...XTM 8 Series XTM_OS_XTM8_11_12_1 exe xtm_xtm8_11_12_1 zip Firebox M500 Firebox_OS_M400_M500_11_12_1 exe firebox_M400_M500_11_12_1 zip XTM 5 Series XTM_OS_XTM5_11_12_1 exe xtm_xtm5_11_12_1 zip Firebox...

Page 11: ...his release l WG Authentication Gateway_11_11_1 exe SSO Agent software required for Single Sign On and includes optional Event Log Monitor for clientless SSO l WG Authentication Client_11_11 msi SSO C...

Page 12: ...hat s New in Fireware v11 12 presentation or Fireware Help TCP port 4100 now used for firewall user authentication only Beginning with Fireware v11 12 TCP port 4100 is used only for firewall user auth...

Page 13: ...ault policies and services that the setup wizards configure depend on the version of Fireware installed on the Firebox and on whether the Firebox feature key includes a license for subscription servic...

Page 14: ...rocess l We recommend you use Fireware Web UI to upgrade to Fireware v11 12 1 You can also use Policy Manager if you prefer l We strongly recommend that you save a local copy of your Firebox configura...

Page 15: ...ng CA and the Windows CryptoAPI was unable to download it To resolve this error you can download and install the certificate from Symantec Back Up Your WatchGuard Servers It is not usually necessary t...

Page 16: ...ou have already installed Fireware v11 12 1 on your computer you must run the Fireware v11 12 1 installer twice once to remove v11 12 1 software and again to install v11 12 1 Upgrade to Fireware v11 1...

Page 17: ...the Gateway Wireless Controller Summary tab select Manage Firmware to download the latest AP firmware to the Firebox again You cannot install the AP firmware on a Firebox that uses Fireware v11 4 x o...

Page 18: ...orted version the upgrade is prevented If you try to schedule an OS update of managed devices through a Management Server the upgrade is also prevented If you use the Fireware Web UI to upgrade your d...

Page 19: ...atchGuard servers are running Downgrade from Fireware v11 12 1 to Fireware v11 x If you use the Fireware Web UI or CLI to downgrade from Fireware v11 12 1 to an earlier version the downgrade process r...

Page 20: ...e resolves kernel crashes on Firebox T70 M200 and M300 devices configured in drop in mode 92760 92677 l The Turkish timezone settings have been adjusted to eliminate timezone changes throughout the ye...

Page 21: ...when Gateway AV signatures are manually updated in Firebox System Manager 90792 Proxies and Services l The Firebox now includes the host IP address when it sends data to the WebBlocker Websense datab...

Page 22: ...sites list in Fireware Web UI 90621 l Failed authentication attempts from WatchGuard System Manager for the status user now produce a log message log in attempt was rejected invalid credentials 92445...

Page 23: ...upported for v11 x releases For information on how to start and use the CLI see the Command Line Reference Guide You can download the latest CLI guide from the documentation web site at http www watch...

Page 24: ...Technical Assistance Release Notes 24...

Reviews: