WatchGuard Access Point Configuration
WatchGuard’s current-generation Wi-Fi 6 access points (AP130, AP230W, AP330, AP332CR, AP430CR, AP432) are managed centrally from WatchGuard Cloud rather than from a Firebox. The central organizational concept is the Access Point Site: a reusable bundle of wireless settings (SSIDs, radio settings, device settings, and more) that is applied to every access point subscribed to the site. Sites let a subscriber account push identical wireless configurations to many APs at once, instead of configuring each device individually.
Access Point Sites are only available for WatchGuard Cloud–managed Wi-Fi 6 APs. Older Wi-Fi 5 APs managed by Wi-Fi Cloud or by a Gateway Wireless Controller on a Firebox cannot use sites — those are configured from the Firebox side instead (see watchguard-firebox-configuration).
Creating and deploying a site
From a subscriber account in WatchGuard Cloud:
- Select Configure > Access Point Sites and click Add Site.
- Give the site a name and description; the configuration page opens.
- In the Wi-Fi Networks tile, click Add SSID, specify the SSID settings, and click Add.
- Save. The wireless network appears on the site’s SSIDs page.
A single access point supports up to 8 SSIDs total, counting both site-provided and device-level SSIDs.
Beyond SSIDs, a site can carry: radio settings, device settings (NTP servers, device LEDs, recurring reboots), network interface settings, advanced settings (Airspace Monitoring, syslog, SNMP), authentication domains, Private Pre-Shared Key (PPSK), Access Point VPN, and Captive Portal.
Configuration changes do not take effect until the site is deployed — deployment can be immediate or scheduled. After deploying, subscribe access points to the site; each AP can subscribe to only one site, but a site can have many subscribed APs, and every redeployment pushes the site’s settings to all of them.
Site vs. device configuration conflicts
When a site is applied to an AP that already has a device-level configuration, the site SSIDs are merged into the device configuration and conflicts are resolved deterministically:
- A site SSID with the same name as an existing device SSID wins — the duplicate device SSID becomes inactive.
- NAT settings on a site SSID that conflict with a device’s static IP address cause the conflicting configuration to become inactive.
- If the combined site + device SSIDs exceed the 8-SSID maximum, SSIDs are applied in alphabetical order (site first, then device) and the overflow is dropped.
- Inactive SSIDs are removed from the device on the next deployment.
On a subscribed AP, site-managed SSIDs appear with a lock icon in WatchGuard Cloud — they cannot be edited at the device level; you must edit and redeploy the site.
Sources
- WatchGuard — About Access Point Sites
- WatchGuard — Add an Access Point Site
- WatchGuard — Configure Access Point SSID Settings
Related
- watchguard-firebox-configuration — Firebox-side management: VLANs, policies, and the Gateway Wireless Controller for older APs
- wi-fi — SSID/BSSID/ESSID terminology used throughout AP configuration
- vlans — SSIDs are typically mapped onto VLAN segments upstream