WatchGuard FireCloud review: When VPNs are not enough
This modern alternative to outdated and poorly performing VPNs delivers sophisticated security features to remote workers via a smart cloud management portal
-
+
Volume discounts
-
+
Integral FWaaS
-
+
SWG and ZTNA services
-
+
Easy to deploy
-
+
Unified cloud management
-
+
PoPs improve performance
-
-
EPDR users may want to wait for FireCloud v2
VPNs (virtual private networks) have traditionally been the go-to solution for many businesses as they provide affordable, secure access to the corporate network for remote workers. There are numerous disadvantages, though, as their encryption processes can impact performance, they don't scale well with increased demand, some can be complex to configure, and few provide any endpoint protection services.
WatchGuard's FireCloud takes secure remote access to the next level and has all the acronyms you'll want to see as this SASE (secure access service edge) solution delivers FWaaS (firewall as a service), SWG (secure web gateway) and ZNTA (zero trust network access). Managed from the WatchGuard Cloud platform, it provides endpoint anti-malware, WatchGuard's APT, IPS, web content and application filtering, geolocation controls and facilities to present remote workers with secure access to private resources on the corporate network.
View Original
View Original
View Original
View Original
FireCloud is available in two versions with the Internet Access edition enabling the FWaaS and SWG components to protect remote workers from internet-based security threats. The Total Access edition adds application-level ZNTA and allows you to dish out VPN-free secure access to private resources.
A key feature of both editions is WatchGuard's globally distributed PoP (point of presence) network. Currently comprising fifteen PoPs, these increase performance as remote workers automatically connect to the nearest one which applies cloud-based security such as anti-malware, IPS and content filtering.
WatchGuard FireCloud review: Deployment
We reviewed FireCloud Total Access, and our first task from the WatchGuard Cloud portal was to configure an identity provider. We took the easy option by choosing the WatchGuard Cloud Directory as our authentication domain, but other options include WatchGuard's AuthPoint or third-party SAML 2.0 providers such as Microsoft Entra ID and Okta.
Users are imported or created from the portal's Directories and Domain Service page. We manually created our users by providing their names, a suitable username, and their email address, after which an invitation was sent out to each one requesting them to password-protect their account.
Make sure you configure the agent deployment settings correctly, as it defaults to installing WatchGuard's EPDR (endpoint protection, detection and response) and should be changed to FireCloud. You can then let your users install the Connection Manager agent, which asks for their login credentials, applies the assigned access rule policy, and routes their traffic through the nearest PoP.
We came across an issue as we also have EPDR activated in our cloud portal. Both this and FireCloud currently use the same agent install file, and even though we had the deployment set to FireCloud only, we found each client also appeared in our EPDR console as an unlicensed endpoint. It doesn't affect FireCloud operations, with WatchGuard advising us this is a known issue and is developing separate agent installers due to be released in FireCloud v2 in a few months.
WatchGuard FireCloud review: Access rules and security services
Access rules combine all FireCloud client security settings and, as with the Firebox appliances, all key services are presented in one page. These include web and application controls, which are both accessed from the content filtering section, with the former offering 166 URL categories that can be allowed or blocked.
App controls are equally extensive, with 1,275 predefined app and protocol signatures provided, and both services are applied to an access rule using one action policy. From the content scanning section, you can enable the gateway AV (GAV) and APT blocker services with the geolocation service using rule actions to determine which countries users may access.
Applied as global settings, the network blocking section covers botnet detection and IPS plus port and website restrictions. The tunnel bypass feature allows you to specify IP addresses and networks that sidestep the FireCloud security checks and go directly to the internet.
WatchGuard FireCloud review: Private resources
To allow remote users to access resources on the company network, you first need to define a FireCloud gateway. Three options are available, and if you use a WatchGuard Firebox appliance, you're in luck, as this already has the gateway service ready and waiting.
We used our Firebox T185 as a gateway, which took seconds to declare to FireCloud. The server gateway component can be installed on an existing Windows Server host, which makes it available as a single private resource. Or you have virtual gateways for Hyper-V, VMware, and Proxmox, which you use to declare multiple resources behind them.
Private resources are defined by providing their IP address and port ranges and assigning an FQDN (fully qualified domain name). This doesn't need to be resolvable, as it's used by clients to access the resource.
We created a private resource for the lab's Brother A3 business inkjet and, from our Windows 11 remote clients, manually added a PCL6 printer driver using its FQDN for the LPR port and had no problems printing to it. Likewise, with an RDP connection to one of the lab's Windows systems, as remote clients just entered the resource FQDN in their Windows RDP app.
WatchGuard FireCloud review: Cloud monitoring
The cloud portal offers plenty of monitoring services, with WatchGuard's Rai (Red AI) the star player. This gathers security feeds from all your cloud-managed WatchGuard products and presents them in one dashboard with AI-generated summaries for an at-a-glance view of your security posture.
FireCloud provides a usage report showing all devices and their connection status over customisable time periods. The security tab keeps you posted on areas such as attack, malware and APT activity, along with charts of blocking actions for apps, malware, users, URLs and destinations, with the geolocation map below showing the number of attempts to access banned countries, and the view can be changed to show specific users.
Move to the traffic tab, and you can see access charts for private resources, allowed apps, web and app categories, domains and users. For more specific information, you have the FireCloud log search facility which allows you to drill down deeper and see details on particular security services.
WatchGuard FireCloud review: Is it worth it?
FireCloud is available with volume discounts, so the more client licences you buy, the more you save. WatchGuard Online shows the Internet Access edition for one year starting at £70 per licence, excluding VAT, dropping to around £38 for more than 5,000. The Total Access edition starts at £108 per year for up to 50 licences, falling to £60 each for over 5,000.
True, FireCloud costs more than VPNs but is far better suited to modern hybrid working environments comprising office, remote and mobile workers that need to access a mix of on-premises and cloud applications. It neatly combines FWaaS, SWG and ZTNA services, and its integration with the WatchGuard Cloud portal makes it far easier to deploy and manage than complex and cumbersome VPNs.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Dave is an IT consultant and freelance journalist specialising in hands-on reviews of computer networking products covering all market sectors from small businesses to enterprises. Founder of Binary Testing Ltd – the UK’s premier independent network testing laboratory - Dave has over 45 years of experience in the IT industry.
Dave has produced many thousands of in-depth business networking product reviews from his lab which have been reproduced globally. Writing for ITPro and its sister title, PC Pro, he covers all areas of business IT infrastructure, including servers, storage, network security, data protection, cloud, infrastructure and services.
-
AMD pledges support for Oxford frontier AI research labNews The British Open-ended Learning and Discovery Lab (BOLD) will work on new learning algorithms, human-centered AI and embodied systems such as robots
By Emma Woollacott Published
-
Airbnb CEO Brian Chesky says companies need to start building useful AI productsNews The Airbnb chief called for better consumer AI tools to undercut backlash against the technology
By Nicole Kobie Published
-
Software teams should take a leaf out of manufacturers books when it comes to testing codeNews Software testers are struggling to keep up with the pace of code production. UiPath thinks it has the solution
By Ross Kelly Published