Automatically enabled when you configure WatchGuard permissions in your agent workflow.
What It Does
- Pick the client’s WatchGuard Cloud account by name from the accounts you manage
- Read a Firebox’s or access point’s state, offline since, uptime, public IP, model, serial and firmware
- Read the Firebox Executive and Security dashboard reports
- Read BOVPN tunnels, firewall policies, networks, SD-WAN, users and schedules of a cloud-managed Firebox
- Read, add and remove Firebox and FireCloud exceptions: blocked sites, WebBlocker, botnet, file, IPS, geolocation and HTTPS
- Deploy saved exceptions or configuration to named Fireboxes, and read the deployment’s result
- Find a computer in WatchGuard Endpoint Security (EPDR, EDR, EPP, Panda Aether) and read its protection, security events, risks and missing patches
- Isolate a computer, stop the isolation, reboot it or scan it
- Read ThreatSync incidents and act on them: isolate, end a process, quarantine a file, block an address, set the status, add comments
- Read accounts, licences, allocations and contracts
- Send an AuthPoint test push and read its result
How the agent handles a Firebox offline alert
The agent finds the account for the ticket’s company and lists its devices. It matches the Firebox name or serial number in the alert to a device and reads its state. When the Firebox is online and its uptime started after the alert, it writes when the Firebox came back. When it is still offline, it writes since when and the last public IP. What happens to the ticket next follows your instructions.Permission Groups
Access Profiles
Safety Controls
How to Configure
1
Connect WatchGuard
Save your WatchGuard Cloud API credential in the Neo Dashboard under the Networking integrations category. See Connecting WatchGuard to Neo.
2
Configure permissions
In your agent workflow’s Integrations tab, choose an access profile or set each permission group by hand.
