Mushroom Networks Documentation

Mushroom Networks SD-WAN and WatchGuard UTM Configuration Guide

Configuration Setup Summary

The purpose of this document is to provide guidance to customers for service chaining Mushroom Networks’ multi-WAN SD-WAN solution with WatchGuard’s Next Generation Firewall and Unified Threat Management solution. 

 

Mushroom’s secure VLL (Virtual Leased Line) overlay tunnel will be set up between Mushroom’s Customer Premise Equipment (Truffle appliance) and Mushroom’s Cloud Relay (as an EC2 instance in the Amazon AWS cloud). Mushroom’s Cloud Relay will pass through all upstream traffic to WatchGuard’s Firebox Cloud instance (again hosted as an EC2 instance in the Amazon AWS cloud) providing UTM services such as Intrusion Prevention, Web Content Filtering, etc.

Network Diagram

pnesumzcjuhl4uhdrdvs7ffrrhh9ujoa zosnp zh7pkp7rgozhl6lofuhsa96wjn erir1agxk5l6hyrf8mfgbb7d aq77xi qnh0u4y5rd8yalxscexyr0o wvnukklrzg8ief54yeaxh3bg 34q



Installation Steps

  1. Firebox Cloud installation and configuration in AWS

 

Install and configure Firebox Cloud with trusted and external interface using the following procedure: https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/firebox_cloud/deploy_aws.html

 

Here is an example configuration screenshot for the configured trusted and external interfaces:

 

yshpw0mxn7q8kkrbve epnyse6ixabvenwm7e9vpwbi5lrs 1zikrr1efhxzdfhgis4bkk5vj2ajumj3ywsvzalgg2fozcjpudwktmqrejnzgkkz 0lx 6shtjb5rfsrf4zootsltawhdlau io3vq

 

  1. Mushroom’s Cloud Relay installation and configuration in AWS

Order Mushroom Networks Cloud Relay service. Mushroom’s Cloud Relay is installed and configured by Mushroom Networks.

  1. Configure WAN1 interface gateway IP address on Mushroom Cloud Relay to point to Firebox Cloud’s trusted interface IP address. (e.g. 10.10.2.172).

tfli0sq8pvlcbfmld kjfm7rwb37xj qxmpxmoolrsodhlqkp 91w3adcax0hezwgxgoqr5grvgvr vqgcbfn3qwuaveafobppuqgmccy8imtjuj3z4hgxdkj yfslrzbmcpo8wesylzhjuvc9e g

WAN1 configuration on the Mushroom Cloud Relay



  1. Configure secure VLL tunnel between Mushroom’s CPE device and Cloud Relay.



91wnma85cnjf005by9vas3ovmjhtdqrmkwpyd 0w13ijrenxar0qnyqszwzx6h51clclbzgi9pjwxjlutrruun80mcfhzvmkqcodxzniobzsgemu1nkbcusvzoh9 ppo9cg6teiwo58kxhlcvsn1zq

 

  1. Configure Splunk for syslog data

 

  • Configure Watchguard to send logs to syslog server (under System->Logging). Replace ‘xxx.xxx.xxx.xxx’ to the external IP address of the Mushroom Portal Server.

neskimj fk7k7bzfeiizopjqtot7dt5wm9kr40hyv9lnpezpykbidjaqpdxztvro3xvvzx6bgbfbgvrgowyerqz alq6ucmfa1qijr5y1syhro kcd7 9pcuuot3lr5k zowvv cj4e47a3e3u3ra

 

  • Configure Mushroom Cloud Relay’s Syslog server (under Status tab) and replace Remote Syslog Server ‘xxx.xxx.xxx.xxx’ to the public IP of Mushroom Monitoring Portal.

a5qqoip8nqolcrt4dkwxhwjgefjenqhibfgge2c43jbep4tp1siew6ygrexl7eqnpqw1t7ti7qf35ya4x3i5 idvmponsdw358x4ivfi iph 8g3dwaj fpjl8uwzxmprfuvowclycquqr p9upiia

 

  • Install Watchguard’s Firebox  App for Splunk on Mushroom Monitoring Portal:

https://www.watchguard.com/help/docs/help-center/en-US/Content/Integration-Guides/General/splunk_integration_V2.html

 

© 2026 Mushroom Networks Inc. All rights reserved.