Watchguard Cyberark Integration Guide
Watchguard Cyberark Integration Guide
Guide Type
Documented Integration WatchGuard or a Technology Partner has provided documentation demonstrating
integration
Guide Details
WatchGuard provides integration instructions to help our customers configure WatchGuard products to work
with products created by other organizations. If you need more information or technical support about how to
configure a third-party product, see the documentation and support resources for that product.
This document describes the steps to integrate CyberArk Enterprise Password Vault (EPV) with your
WatchGuard Firebox. With a custom SSH plug-in from CyberArk, the CyberArk administrator can periodically
change the passphrase of the Firebox Admin user.
Configuration
To complete this integration, you must first deploy CyberArk software (see the Platform and Software section
above). CyberArk software deployment requires knowledge of Windows server, WCF, and IIS. Make sure
Central Policy Manager and Password Vault web access are hosted on the same server, while Privileged
Session Manager and Vault Server are each on a dedicated server.
3. On the Accounts tab, click Add Accounts. Note that, to successfully add an account, you must first
request and receive a customized plug-in from CyberArk. Once you have this plug-in and it is correctly
installed, you can complete the account information as described below.
If the account has been set up correctly, it will look like this:
1. Double-click the user name to open the Account Details page for your account.
3. An RDP connection to the Firebox is made. If the connection is successful, you will see this:
3. In Password Management, you can select how often to change the passphrase. The default is 2 days.