Print topic

Known Issues and Limitations

These are known issues for Fireware XTM v11.3.2 and all management applications. Where available, we include a way to work around the issue.

General

Workaround
Do not use the "-" character as the first character in your status or configuration passphrase.

Upgrade Issues

Workaround
Add the DNS suffix and second DNS entries again after you upgrade to v11.x.

WatchGuard System Manager

Workaround
Make sure that Windows XP compatibility mode is not enabled on the WSM v11.x executable file. To verify, locate the wsm.exe file in Windows Explorer. Right-click on the executable file, select Properties, and click the Compatibility tab.

Workaround
Connect to the Management Server from WSM. Select the managed device and select Update Device. Select the radio button Reset server configuration (IP address/ Hostname, shared secret).

Workaround
Exit the WatchGuard Server Center before you start the uninstall WSM. You can then uninstall WatchGuard System Manager successfully.

Web UI

WatchGuard Server Center

Workaround
You can either upgrade your gateway Firebox or XTM device to WSM v11.3.2, or do not add the gateway Firebox device information when you run the v11.3.2 Management Server Setup Wizard.

Command Line Interface (CLI)

Logging and Reporting

Multi-WAN

Networking

Workaround
1. If your computer is directly connected to the XTM 2 Series device during the Web Setup Wizard, use a static IP address on your computer.
2. Use a switch or hub between your computer and the XTM 2 Series device when you run the Web Setup Wizard.

Firebox X Edge e-Series Wireless

FireCluster

Workaround
Do not use any of the default IP addresses as the Primary or Backup cluster interface IP address.

Authentication

Proxies

Workaround
You can use the H.323 protocol instead of SIP.

Security Subscriptions

Mobile VPN with SSL

Workaround
To upgrade your Mobile VPN with SSL client from v11.2.1 to v11.3, use your web browser to connect to https://<IP address of a Firebox or XTM device>/sslvpn.html. You can then download and install the new client software. Or, you can download the client software from the Software Downloads page and email it your users to install on their computer.

Mobile VPN with IPSec

Workaround
Increase the rekey byte count.

Branch Office VPN

Workaround
If you use multi-WAN and have problems with your branch office VPN tunnels failing to negotiate with their remote peers, you must open your multi-WAN configuration and select Configure adjacent to your chosen multi-WAN configuration mode. Make sure that the appropriate interfaces are included in your multi-WAN configuration.

Workaround
Do not use Any for the Local or the Remote part of the tunnel route. Change the Local part of your tunnel route. Type the IP addresses of computers behind the Firebox that actually participate in the tunnel routing. Contact the administrator of the remote IPSec peer to determine what that device uses for the Remote part of its tunnel route (or the Remote part of its Phase 2 ID).

Give us feedback  •   All product documentation  •   Knowledge Base