Print topic

Known Issues and Limitations

These are known issues for Fireware XTM v11.4 and all management applications. Where available, we include a way to work around the issue.

General

WatchGuard System Manager

Workaround
Make sure that Windows XP compatibility mode is not enabled on the WSM v11.x executable file. To verify, locate the wsm.exe file in Windows Explorer. Right-click on the executable file, select Properties, and click the Compatibility tab.

Workaround
Connect to the Management Server from WSM. Select the managed device and select Update Device. Select the radio button Reset server configuration (IP address/ Hostname, shared secret).

Workaround
Exit the WatchGuard Server Center before you start the uninstall WSM. You can then uninstall WatchGuard System Manager successfully.

Web UI

WatchGuard Server Center

Command Line Interface (CLI)

Proxies

Workaround
You can use the H.323 protocol instead of SIP.

Workaround
1. Edit your HTTP proxy policy.
2. Click View/Edit proxy.
3. Select the Allow range requests through unmodified check box.
4. Save this change to your XTM device.

Workaround
Configure the PBX to send the Contact header with an IP address, not a domain name.

Security Subscriptions

Networking

Workaround
1. If your computer is directly connected to the XTM 2 Series device during the Web Setup Wizard, use a static IP address on your computer.
2. Use a switch or hub between your computer and the XTM 2 Series device when you run the Web Setup Wizard.

Multi-WAN

Authentication

Centralized Management

FireCluster

Workaround
Connect directly to your XTM devices and verify that the cluster is enabled. If the cluster is disabled, connect directly to your XTM device with Policy Manager and load the cluster configuration onto your device. When the cluster is enabled, connect directly to it with Firebox System Manager with its management IP address and use the Cluster > Tools > Join command. This may cause the device to reboot.

Workaround
Do not use any of the default IP addresses as the Primary or Backup cluster interface IP address.

Logging and Reporting

Workaround
Open Windows Task Manager and kill the process. From the WatchGuard System Manager installation dialog, click Retry. The installation should continue successfully. You may need to manually start the C:\WINDOWS\system32\wbem\wmiprvse.exe later.

Mobile VPN

Workaround
Increase the rekey byte count.

Workaround
To upgrade your Mobile VPN with SSL client from v11.2.1 to v11.3, use your web browser to connect to https://<IP address of a Firebox or XTM device>/sslvpn.html. You can then download and install the new client software. Or, you can download the client software from the Software Downloads page and email it your users to install on their computer.

Branch Office VPN

Workaround
If you use multi-WAN and have problems with your branch office VPN tunnels failing to negotiate with their remote peers, you must open your multi-WAN configuration and select Configure adjacent to your chosen multi-WAN configuration mode. Make sure that the appropriate interfaces are included in your multi-WAN configuration.

Workaround
Do not use Any for the Local or the Remote part of the tunnel route. Change the Local part of your tunnel route. Type the IP addresses of computers behind the Firebox that actually participate in the tunnel routing. Contact the administrator of the remote IPSec peer to determine what that device uses for the Remote part of its tunnel route (or the Remote part of its Phase 2 ID).

Give us feedback  •   All product documentation  •   Knowledge Base