To prevent having to use old fax hardware, we use a Hylafax solution to send and receive faxes via Weepee Telecom, our incoming faxes are handled by their Hylafax solution that nicely converts them to email for our mailserver and if we send faxes out, we use a Hylafax client:
For Windows: Winprint Hylafax
For OS X: Fax 90 Client
And for All: HylaFaxSender
Here is a list of other supported clients, if the above don’t fit.
Now to configure this traffic through a Watchguard XTM it’s a bit non-standard so here we go:
Go to https://yourwatchguardfirewall:8080, login with the write password
The Hylafax clients are communicating with the server over Tcp port 4559, so we have to make a rule for that, click on Firewall -> Firewall Policies -> Green + in the above right corner to add a policy:
Click on ‘Custom’:
Now for the new rule that we have to make, we have to use a very custom proxy. A Hylafax client can be compared with an FTP client when doing fax transactions as it uses a ‘FTP connection tracking‘, so we will add a ‘Hylafax FTP Proxy’:
- Choose a name for your policy and a description
- As type choose Proxy and select FTP from the dropdown list
Click on ‘Ok’, now you should have:
Click on Save and you are done.
This custom made policy with FTP connection tracking can now be used



