> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# WatchGuard API

> Check a Firebox or access point after an offline alert, read and change Firebox exceptions and policies, and read and act on WatchGuard Endpoint Security and ThreatSync for each client you manage in WatchGuard Cloud

The common use is a WatchGuard Cloud alert that a Firebox's cloud connection went offline or came back online: the agent checks the Firebox and writes whether it is back and since when it was down.

<Info>
  Automatically enabled when you configure WatchGuard permissions in your agent workflow.
</Info>

## What It Does

* Pick the client's WatchGuard Cloud account by name from the accounts you manage
* Read a Firebox's or access point's state, offline since, uptime, public IP, model, serial and firmware
* Read the Firebox Executive and Security dashboard reports
* Read BOVPN tunnels, firewall policies, networks, SD-WAN, users and schedules of a cloud-managed Firebox
* Read, add and remove Firebox and FireCloud exceptions: blocked sites, WebBlocker, botnet, file, IPS, geolocation and HTTPS
* Deploy saved exceptions or configuration to named Fireboxes, and read the deployment's result
* Find a computer in WatchGuard Endpoint Security (EPDR, EDR, EPP, Panda Aether) and read its protection, security events, risks and missing patches
* Isolate a computer, stop the isolation, reboot it or scan it
* Read ThreatSync incidents and act on them: isolate, end a process, quarantine a file, block an address, set the status, add comments
* Read accounts, licences, allocations and contracts
* Send an AuthPoint test push and read its result

For AuthPoint, Neo reaches only the Authentication API: a token unlock, resync or reassignment, or a user change, stays in the AuthPoint console. Locally managed Fireboxes show their status, reports and exceptions; their policies and VPN stay on the device.

## How the agent handles a Firebox offline alert

The agent finds the account for the ticket's company and lists its devices. It matches the Firebox name or serial number in the alert to a device and reads its state. When the Firebox is online and its uptime started after the alert, it writes when the Firebox came back. When it is still offline, it writes since when and the last public IP. What happens to the ticket next follows your instructions.

## Permission Groups

| Group | Access levels | Covers |
| - | - | - |
| Firebox Devices and Reports | Disabled, Read Only | Fireboxes, FireClusters and access points: status, offline since, uptime; the dashboard reports |
| Firebox Exceptions | Disabled, Read Only, Read / Write | Firebox and FireCloud exceptions |
| Firebox Configuration | Disabled, Read Only, Read / Write | Firewall policies, BOVPN tunnels, certificates, networks, users, templates, deployments |
| Endpoint Security | Disabled, Read Only, Read / Write | Devices, protection, security events, risks, patches, tasks; isolate, reboot, scan |
| ThreatSync and NDR | Disabled, Read Only, Read / Write | ThreatSync incidents, actions and comments; NDR assets and Smart Alerts |
| Accounts and Licensing | Disabled, Read Only, Read / Write | Accounts and managed accounts, operators, activations, allocations, contracts, invoices |
| AuthPoint Authentication | Disabled, Read Only, Read / Write | Push and its status, OTP and QR code checks, the authentication policy for a user |

## Access Profiles

| Profile | What runs on its own | What asks a technician |
| - | - | - |
| **Read Only** | Every read | No write is allowed |
| **Helpdesk** | Every read | Every write |
| **IT Admin** | Isolating, scanning and rebooting endpoints, ThreatSync containment and incident updates, AuthPoint push | Exceptions, Firebox configuration and account changes, and every write under Safety Controls |
| **Full Automation** | Every write except those below | Only the writes below |

## Safety Controls

| Control | Behavior |
| - | - |
| **Exceptions** | A Firebox exception follows the access profile, and reaches the Firebox only through a deployment, which always asks. A FireCloud exception that lets traffic through or skips a scan always asks a technician, and so does removing a FireCloud blocked-site entry |
| **Firebox configuration** | Firewall policy, BOVPN, certificate and template changes, and disabling global exceptions, always ask a technician |
| **Deployments** | Every deployment always asks a technician, and it must name its Fireboxes |
| **Endpoints** | Every endpoint action must name its devices. Uninstalling protection and moving devices to another security configuration always ask a technician |
| **ThreatSync** | Undoing an isolation or a block always asks a technician |
| **Accounts** | Operator changes, deallocations, purchase orders and contract suspend or cancel always ask a technician |
| **Right account** | A call to a client's devices, configuration, endpoints or incidents names that client's account id; a call for an account your credential does not manage is refused. Operator calls name the client's account in the body or the query; order and activation calls name no account and run in your own WatchGuard Cloud account |
| **Refused** | Neo does not delete a WatchGuard Cloud account, create a partner account, read Azure access credentials, check a user's password, or send a ThreatSync batch |

## How to Configure

<Steps>
  <Step title="Connect WatchGuard">
    Save your WatchGuard Cloud API credential in the Neo Dashboard under the **Networking** integrations category. See [Connecting WatchGuard to Neo](/integrations/watchguard/connecting-to-neo).
  </Step>

  <Step title="Configure permissions">
    In your agent workflow's **Integrations** tab, choose an access profile or set each permission group by hand.
  </Step>
</Steps>

<Tip>
  Start with **Read Only**. Checking a Firebox after an offline alert needs only reads in WatchGuard; the note on the ticket is written with the PSA tools.
</Tip>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.