Connectivity and SD-WAN
CloudGen WAN brings full SD-WAN functionality to Azure Virtual WAN, Microsoft’s native hybrid cloud service. Secure SD-WAN dynamically selects the most suitable uplink for each application in real time, based on traffic characteristics, available bandwidth, and latency between VPN endpoints. This lets you replace MPLS lines by globally connecting your sites via the Microsoft Global Network, the world’s fasted private network. Purpose-built for the cloud, CloudGen WAN provides seamless, automated access to your business-critical resourses, leveraging a rich feature-set including:
- Adaptive bandwidth protection
- Adaptive session balancing
- Forward error correction (FEC)
- SD-WAN breakout
- Dynamic bandwidth and latency detection
- Performance-based transport selection
- TINA—Barracuda’s proprietary VPN protocol
- Site-to-site connectivity
- Failover link support
- Dynamic quality of service
- WAN compression
A unique combination of next-generation security and adaptive WAN routing technology allows Barracuda CloudGen WAN to dynamically assign available bandwidth, uplink, and routing information based on protocol, user, location, and content as well as application, application categories, and even web content categories. This keeps expensive, highly available lines free for business- and mission-critical applications, while significantly reducing response times and freeing up additional bandwidth.
To view a current list of applications and sub-applications that ClouGen WAN recognizes for application-based routing, please visit the Online Application Explorer.
Personal Access with Barracuda CloudGen WAN is the most convenient way to provide endpoint connectivity to workloads in Azure. Personal Access for CloudGen WAN lets remote users access company resources in Azure over an encrypted VPN tunnel directly from work-at-home environments or on the go. The high-performance TINA VPN protocol allows much more stable and resilient always-on connections from remote devices.
CloudGen WAN Personal Access benefits compared to other client VPN to Azure solutions:
- No need to deploy additional VPN gateways or services—Personal Access uses the existing CloudGen WAN Gateway infrastructure
- Fast and easy self-enrollment for end users
- High-performance connectivity to cloud-hosted resources using TINA protocol—faster, more stable, and more resilient
- Integration with your existing Azure Active Directory
- Lower cost compared to built-in Azure Virtual WAN point-to-site connectivity.
- Lower cost compared to dedicated VPN services—only pay for actual usage
Management and automation
Security
- Advanced Threat Protection
- Intrusion detection and prevention
- Malware protection
- SSL inspection
- Stateful deep packet inspection
- Single pass architecture
- URL filtering--application-based ACL
- SQL injections and arbitrary code executions
- Access control attempts and privilege escalations
- Cross-site scripting and buffer overflows
- Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks
- Directory traversal and probing and scanning attempts
- Backdoor attacks, trojans, rootkits, viruses, worms, and spyware
As a result, Barracuda CloudGen WAN can identify and block advanced evasion attempts and obfuscation techniques that are used by attackers to circumvent and trick traditional intrusion prevention systems.
Automatic signature updates are delivered on a regular schedule or on an emergency basis as new vulnerabilities emerge, to ensure that Barracuda CloudGen WAN is constantly up to date.
SASE
Barracuda CloudGen WAN provides a practical SASE solution that is easy to deploy in Azure. While other SASE vendors use their own cloud and their own network, CloudGen WAN allows leveraging the global presence and power of Azure data centers and Microsoft’s global network. For all organizations leveraging Azure or planning to adopt Azure it makes perfect sense to deploy a SASE offering on the same public cloud platform.
For organizations having certain geopolitical requirements or using applications requiring an organization’s IP address as source IP address, every CloudGen WAN site device serves as a private enforcement node for SWG, FWaaS enforcement and as entry point to the cloud service for remote endpoints. The SASE enforcement points in Azure, as well as the private enforcement points on the site devices, are controlled by security policies defined centrally in the CloudGen WAN management portal, without requiring administrators to know where the traffic enters the service.