WatchGuard Access Point Configuration

WatchGuard’s current-generation Wi-Fi 6 access points (AP130, AP230W, AP330, AP332CR, AP430CR, AP432) are managed centrally from WatchGuard Cloud rather than from a Firebox. The central organizational concept is the Access Point Site: a reusable bundle of wireless settings (SSIDs, radio settings, device settings, and more) that is applied to every access point subscribed to the site. Sites let a subscriber account push identical wireless configurations to many APs at once, instead of configuring each device individually.

Access Point Sites are only available for WatchGuard Cloud–managed Wi-Fi 6 APs. Older Wi-Fi 5 APs managed by Wi-Fi Cloud or by a Gateway Wireless Controller on a Firebox cannot use sites — those are configured from the Firebox side instead (see watchguard-firebox-configuration).

Creating and deploying a site

From a subscriber account in WatchGuard Cloud:

  1. Select Configure > Access Point Sites and click Add Site.
  2. Give the site a name and description; the configuration page opens.
  3. In the Wi-Fi Networks tile, click Add SSID, specify the SSID settings, and click Add.
  4. Save. The wireless network appears on the site’s SSIDs page.

A single access point supports up to 8 SSIDs total, counting both site-provided and device-level SSIDs.

Beyond SSIDs, a site can carry: radio settings, device settings (NTP servers, device LEDs, recurring reboots), network interface settings, advanced settings (Airspace Monitoring, syslog, SNMP), authentication domains, Private Pre-Shared Key (PPSK), Access Point VPN, and Captive Portal.

Configuration changes do not take effect until the site is deployed — deployment can be immediate or scheduled. After deploying, subscribe access points to the site; each AP can subscribe to only one site, but a site can have many subscribed APs, and every redeployment pushes the site’s settings to all of them.

Site vs. device configuration conflicts

When a site is applied to an AP that already has a device-level configuration, the site SSIDs are merged into the device configuration and conflicts are resolved deterministically:

  • A site SSID with the same name as an existing device SSID wins — the duplicate device SSID becomes inactive.
  • NAT settings on a site SSID that conflict with a device’s static IP address cause the conflicting configuration to become inactive.
  • If the combined site + device SSIDs exceed the 8-SSID maximum, SSIDs are applied in alphabetical order (site first, then device) and the overflow is dropped.
  • Inactive SSIDs are removed from the device on the next deployment.

On a subscribed AP, site-managed SSIDs appear with a lock icon in WatchGuard Cloud — they cannot be edited at the device level; you must edit and redeploy the site.

Sources

  • watchguard-firebox-configuration — Firebox-side management: VLANs, policies, and the Gateway Wireless Controller for older APs
  • wi-fi — SSID/BSSID/ESSID terminology used throughout AP configuration
  • vlans — SSIDs are typically mapped onto VLAN segments upstream