Overview
WatchGuard Firebox Cloud brings the protection of WatchGuard's leading Firebox UTM appliances to public cloud environments and enables organizations to extend their security perimeter to protect business critical assets in Amazon Web Services. Under the AWS shared responsibility model security in the cloud falls to the customer. For this reason, it is crucial that administrators take every step possible to defend their data and deflect cyber criminals. Firebox Cloud can quickly and easily be deployed to protect a Virtual Private Cloud (VPC) from attacks such as Botnets, cross-site scripting, SQL injection attempts, and other intrusion vectors.
Highlights
- The WatchGuard Firebox Cloud AMI was built specifically to run within the AWS environment and provides a streamlined User Interface that removes elements that are not relevant to AWS but still provides all the necessary WatchGuard security services.
- Small to medium businesses and distributed enterprises with portions of their infrastructure running in the cloud can streamline their configuration and maintenance efforts by extending their security perimeter with Firebox Cloud.
- Utilize WatchGuard Cloud as the centralized management hub for multiple Firebox Cloud instances offering streamlined visibility alongside all other WatchGuard security solutions.
Details
Unlock automation with AI agent solutions

Features and programs
Financing for AWS Marketplace purchases
Pricing
Free trial
| Dimension | Cost/hour | 
|---|---|
| c5.large  Recommended | $0.35 | 
| t2.micro AWS Free Tier | $0.35 | 
| t3.micro AWS Free Tier | $0.35 | 
| m6i.large | $0.35 | 
| m4.2xlarge | $1.50 | 
| m5.2xlarge | $1.50 | 
| m5.xlarge | $0.75 | 
| m6i.4xlarge | $3.00 | 
| m4.xlarge | $0.75 | 
| m6i.2xlarge | $1.50 | 
Vendor refund policy
Refunds are not supported on hourly instances of Firebox Cloud, but you may cancel your subscription at any time.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Additional details
Usage instructions
Use your web browser to connect to the Firebox Cloud Web UI at https://<public_ip_or_dns>:8080. The default admin password is set to the instance ID of the Firebox Cloud instance. For more information, please see the Firebox Cloud Deployment Guide, or Fireware Help.
Resources
Vendor resources
Support
Vendor support
Online support is recommended for non-critical issues and lets you provide detailed updates on the status of your issue, as well as an option to upload troubleshooting documents to help resolve your case more quickly. Phone support is recommended for critical network failure situations, and for anyone who does not have access to the online support submittal page. Please have your WatchGuard appliance serial number readily available when you call for support. You can also contact us at support@watchguard.com .
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products


Customer reviews
Makes defining policies simpler but lacks performance and modern features
What is our primary use case?
My experience with WatchGuard Firebox has been that it operates similar to other firewall services available in the market, such as Palo Alto and Fortinet, however, it does not provide the same level of throughput and features.Â
We are using it as a firewall, enabling geofencing, creating policies to allow or block traffic, and setting up site-to-site VPN connections on the box. WatchGuard Firebox is deployed on-premises, as it is a hardware box.
What is most valuable?
The most valuable features of WatchGuard Firebox include everything that a firewall should support, however, they do not quite reach the mark compared to offerings in the market.Â
It does support features such as tunnel and policy creation, enabling geofencing and similar functionalities. WatchGuard Firebox simplifies my job through the policies we can define. When we create a policy, it simplifies our workflow, which helps with our overall efficiency.
What needs improvement?
I hear complaints that the LAN network is slow. It is also difficult to diagnose issues if any devices get compromised; for example, if someone hacks our system, it becomes hard to trace who made changes or accessed the firewall. While it is user-friendly for configuration, troubleshooting is challenging, and they need to improve their system to be more competitive.
For how long have I used the solution?
I have been using WatchGuard Firebox for five years and only for one customer.
What do I think about the stability of the solution?
The stability of WatchGuard Firebox is good. That said, performance does vary. Our on-site team has reported feelings of slowness at times. When we verified up to the firewall, it worked fine, but there are issues with traffic hitting the firewall, which could indicate performance problems related to throughput.Â
Since we are using an old firewall, that may be part of the issue. I am not sure how the new devices perform.
What do I think about the scalability of the solution?
In terms of scalability, WatchGuard Firebox rates as five out of ten. When I log into the firewall, the user interface and features compared to newer firewalls are not up to the mark, which includes functionalities such as filtering, web filtering, threat protection, user identity, and UTM features that need improvement.
How are customer service and support?
My experience with WatchGuard's technical support has been that it was hard to get them on the call initially. Finally, we connected with someone, and I would rate their support as eight or nine out of ten once we were able to speak with them. The challenge is getting them on the line.
How would you rate customer service and support?
Positive
How was the initial setup?
My role in the initial setup and deployment of WatchGuard Firebox is limited to supporting the existing infrastructure for one customer, as I haven't been involved with any new implementations.
What's my experience with pricing, setup cost, and licensing?
IÂ don't handle the pricing aspect of the solution.Â
What other advice do I have?
WatchGuard Firebox is only deployed in one location within my customer's organization, and at the other locations, we are using Meraki and FortiGate. We plan to replace WatchGuard Firebox soon. My impression of the spam blocking capabilities of WatchGuard is not very favorable, as I don't think it is very capable. I haven't noticed effective web ratings or IPS signatures, which may be due to managing an older OS; I'm not certain about the performance of the newer versions. I am not aware of whether the transition to faster ports on WatchGuard Firebox supports maintaining productivity levels during peak usage times. Based on my experience, I would rate WatchGuard Firebox as five out of ten overall.
Which deployment model are you using for this solution?
Comprehensive support experience and notable cost-effectiveness, but management complexity needs addressing
What is our primary use case?
I actually use the host ransomware prevention feature of WatchGuard Threat Detection and Response , and we haven't had issues with that. This is currently maintained by our partner in the WatchGuard management. We are a town hall, but there is an enterprise provider that is currently managing all the WatchGuard Threat Detection and Response installation.
I am not familiar with the automated remediation tools in WatchGuard Threat Detection and Response and how they help in reducing manual intervention because this is managed by our provider.
I have not yet utilized the cloud sandboxing feature in WatchGuard Threat Detection and Response.
What is most valuable?
The centralized visibility and control of endpoints in WatchGuard Threat Detection and Response helps coordinate cybersecurity, but this is managed by another tool that is installed in our PCs. It is installed and configured, but we don't use it because the main feature is with the EDR. It is configured but not used as a model per se.
What needs improvement?
I would like to improve WatchGuard Threat Detection and Response, but I don't manage it directly. The main problem that WatchGuard Threat Detection and Response has is that they use several tools to do the same tasks, and they are sometimes very complicated to use and very slow.
For example, we had Palo Alto deployed 10 years ago, and there were many things that were better managed by Palo Alto than the tools we currently have in WatchGuard Threat Detection and Response. The main concern is about managing tools and having a unified management model for managing the firewalls and response. They have many web interfaces that do many things, but they don't have one tool that does all the things that a firewall should do.
For how long have I used the solution?
I have been working with WatchGuard Threat Detection and Response for about three years.
What was my experience with deployment of the solution?
The deployment for WatchGuard Threat Detection and Response took about three months because we deployed many components around the system. Previously, we had Palo Alto, and we changed all the structures to WatchGuard Threat Detection and Response. We changed VPN, detection mode for several things such as HTTP navigation, and many other products. The final substitution took about one month. The most delayed deployment was the VPN because we have around 1,000 users.
How are customer service and support?
The technical support of WatchGuard Threat Detection and Response is generally helpful. We have had two issues related to the VPN, and we experienced 24/7 activity from their team. Their support was very powerful as they responded very quickly and stayed online with us for two days.
However, when we find something strange in the firewall, such as access issues or configuration changes, the WatchGuard team has to recompile some new features or make a new deployment to our installation to solve the problem. This was not the case with Palo Alto. They are very powerful in this sector, but they have some issues in the way they manage the firewall system.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Two years after the deployment, we have found that WatchGuard Threat Detection and Response is more difficult to manage than Palo Alto and Fortinet. Our biggest concern is not about price but about management.
How was the initial setup?
The installation and implementation process of WatchGuard Threat Detection and Response was handled as a part-time job by one person.
What's my experience with pricing, setup cost, and licensing?
I am satisfied with the licensing cost and pricing of WatchGuard Threat Detection and Response because we came from Palo Alto, which is a very expensive firewall. When we tried to renew the Palo Alto license, the cost was beyond any reasonable range. WatchGuard Threat Detection and Response seemed very powerful and appeared to be a good solution, as recommended by our partner. At that time, we had several options, including Fortinet.
What other advice do I have?
I have not seen any positive impact or benefits for my company from using WatchGuard Threat Detection and Response. On a scale of 1-10, I rate this solution a 7.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Positive experience with seamless communication and strong security features
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
How was the initial setup?
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
Offers comprehensive network security features with easy configuration
What is our primary use case?
We have all kinds of customers, including schools, colleges, institutes, and organizations. We do not work in a specific area, and we have a wide range of customers in various sectors.
What is most valuable?
The Firebox offers valuable features such as network security, URL filtering, UTM features, intrusion prevention and detection, and authentication. It also supports VPN, IPsec, and point-to-point communication. I did not encounter any problems after configuring threat detection and protection, intrusion prevention systems, and intrusion detection systems.
What needs improvement?
The only problem I have with Firebox is the grouping issue. When implementing a rule using a group of IPs, it is not possible to do that directly. I have to manually add all the IPs, and this is where I think WatchGuard should improve.
For how long have I used the solution?
I have been using this solution since 2016.
How are customer service and support?
The support system is similar to EPDR and EPP. They will register my case and either call me back, email me, or send me an article or key bulletin if things are sorted out.Â
Otherwise, they will take a remote session to resolve the issue. They have a centralized portal where I can get support for EPP and EPDR.
How would you rate customer service and support?
Neutral
How was the initial setup?
Setting up Firebox is not an easy task for everyone. To set up Firebox, one should have at least professional knowledge. Not everyone can do a Firebox setup because it is executed based on protocols.Â
One cannot simply pick up Firebox and go through a basic configuration. For Firebox setup, having knowledge equivalent to Cisco CCNA associate level plus professional level is essential.Â
Additionally, understanding basic routing and switching is necessary. Having knowledge of IPs and professional skills is crucial. Unlike Sophos, which is easy with a 'next' approach, configuring Firebox requires deep knowledge about protocols and how they work.
What other advice do I have?
My only issue with Firebox is the grouping issue. I recommend Firebox since this device will not let anyone down. If someone drives a Volkswagen, they may find it challenging to switch to another car. It is the same with WatchGuard; once someone adopts this device, they will likely not buy another. Â
I rate the overall solution a nine out of ten.
Improves security in the banking sector with a fast setup and helpful support
What is our primary use case?
I'm using it in the banking sector only. Basically, I'm using it for security and other purposes, including data loss prevention. Security is the main purpose in banks.
What is most valuable?
Nowadays, we are using small models for SD WAN also, depending on security purposes. Basically, we have received a good return on investment.
What needs improvement?
The basic problem is that for every firewall in India, there is a need for a one-year or two-year subscription. That is the main issue for all users. Particularly in India, the cost for renewal after three years is 75% of the hardware cost, which is a significant problem.
For how long have I used the solution?
I've been using VoiceBot for the last two years.
What do I think about the scalability of the solution?
It's scalable for us. If we're going for more concurrent users, we need to change the entire box. In that case, they provide a discount for replacing the old box. I think it involves seven or eight users.
How are customer service and support?
The technical support is good. Their distributor is in Mumbai, and they arrange everything about support. In case we need the same development PeerSpot or engineers on-site.
How would you rate customer service and support?
Neutral
How was the initial setup?
It depends on the company, however, it usually takes about two hours, not more than that. I have a team of specialists for this, consisting of three people.
What about the implementation team?
Only three or four people are involved. It relies on online support by remote access, not on-site visits.
What's my experience with pricing, setup cost, and licensing?
I don't know the current cost. It's all imported products. It's not assembled in India. It's expensive us here.
Which other solutions did I evaluate?
Currently, I'm using WatchGuard. I'm also using pfSense in some cases.
What other advice do I have?
The major problem is pricing and licensing loss. In India, the cost for renewal after three years is 75% of the hardware cost, which is a significant problem. Your review may be available to third parties and on third-party websites.
I'd rate the solution eight out of ten.