Security
While traditional solutions usually detect network threats after they have breached the network by sending log notifications to the administrator, Barracuda Advanced Threat Protection (ATP) implements full system emulation, providing deep visibility into malware behavior. Files are checked against a cryptographic hash database that is constantly updated. In case the file is unknown, it is emulated in a virtual sandbox where malicious behavior can be discovered.
Barracuda ATP offers Administrators granular, file-type-based control including automatic quarantine and block-listing features to maintain the highest level of protection for an organization’s network.
Barracuda Advanced Threat Protection is an optional subscription.
The Intrusion Detection and Prevention System (IDS/IPS) of Barracuda CloudGen Firewall strongly enhances network security by providing complete and comprehensive real-time network protection against a broad range of network threats, vulnerabilities, exploits, and exposures in operating systems, applications, and databases preventing network attacks such as:
- SQL injections and arbitrary code executions
- Access control attempts and privilege escalations
- Cross-Site Scripting and buffer overflows
- Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks
- Directory traversal and probing and scanning attempts
- Backdoor attacks, Trojans, rootkits, viruses, worms, and spyware
Barracuda CloudGen Firewall provides advanced attack and threat protection features such as:
- Stream segmentation and packet anomaly protection
- TCP split handshake protection
- IP and RPC defragmentation
- FTP evasion protection
- URL and HTML decoding
As a result, Barracuda CloudGen Firewall is able to identify and block advanced evasion attempts and obfuscation techniques that are used by attackers to circumvent and trick traditional intrusion prevention systems.
As part of Barracuda Energize Updates subscription, automatic signature updates are delivered on a regular schedule or on an emergency basis to ensure that Barracuda CloudGen Firewall is constantly up-to-date. If the firewall unit is centrally managed, the updates are conveniently distributed by Barracuda Firewall Control Center.
In today’s world of omnipresent botnets, one of the main tasks of perimeter protection is to ensure ongoing availability of the network for legitimate requests and to detect and repel malicious denial of service attacks. With TCP SYN Flood Protection, Barracuda CloudGen Firewall effectively functions as a generic TCP proxy, forwarding only legitimate TCP traffic to the inside of the network.
Additionally, Barracuda CloudGen Firewall allows the definition of a rate limit that is applied to the maximum number of sessions per source address to be handled by the firewall. Packets arriving at a rate faster than allowed will simply be dropped. In a massive DDoS attack, the attackers may simply aim for saturating the link by transmitting vast numbers of UDP packets. The integrated environmental monitoring feature of Barracuda CloudGen Firewall diagnoses such conditions by link and target address monitoring. Once the response of a remote target address to regular ICMP probing fails, the system can be configured to activate different routes and uplinks (for example backup line, ISDN, xDSL). Using this feature, traffic will be unimpeded across unaffected lines and crucial site-to-site and site-to-Internet connectivity remains operational.
Connectivity & SD-WAN
A unique combination of next-generation security and adaptive WAN routing technology allows Barracuda CloudGen Firewall to dynamically assign available bandwidth, uplink, and routing information based not only on protocol, user, location, and content, but also on applications, application categories, and even web content categories. This keeps expensive, highly available lines free for business- and mission-critical applications, while significantly reducing response times and freeing up additional bandwidth.
To view a complete list of applications and sub-applications that are covered by Application-Based Routing, please check the Online Application Explorer.
Due to the limitations that come with standard IPsec connections, Barracuda Networks has created several powerful extensions to standard IPsec tunnel management. This core of Barracuda Firewall VPN Engine is called TINA (Transport Independent Network Architecture). The TINA protocol allows the use of TCP, UDP, and ESP for high speed VPN connections, which improves the VPN connectivity substantially by adding:
- Endpoint-to-Endpoint (not network-to-network) connectivity
- NAT friendliness
- Multiple physical transport paths for a logical tunnel
- Multiple tunnels between two locations
- HTTPS and SOCKS4/5 proxy compatibility
- Dynamic Address Support
- Tunnel heartbeat monitoring
Limited network resources make bandwidth prioritization a necessity. Barracuda CloudGen Firewall provides strong Quality of Service (QoS) that lets the administrator apply quality aspects and service guarantees to selected traffic flows within the WAN. QoS is often used to prioritize the network traffic of applications that are critical and must not be affected by the network traffic of other applications.
Barracuda CloudGen Firewall provides a large set of QoS techniques, such as traffic shaping, traffic prioritization, and bandwidth partitioning, which assigns a bandwidth limit to certain types of traffic. To select traffic for different priority classes, the available real-time traffic analysis can be used to identify whether network traffic was sent by business-critical applications or by potentially unwanted applications.
Barracuda CloudGen Firewall can significantly enhance the WAN performance of distributed network environments by improving the availability, performance, and response time of business-critical applications by lowering throughput and transmission delays, affecting time-sensitive decisions and enterprise profitability. The next-generation networking concept of Barracuda CloudGen Firewall provides a set of powerful features to efficiently reduce and offset the negative effects of high latencies and response times.
By implementing enterprise-grade WAN acceleration features such as data deduplication, traffic compression, and protocol optimization, Barracuda CloudGen Firewalls can significantly improve site-to-site WAN traffic and increase productivity by accelerating the delivery of business applications - at no extra charge. WAN traffic can be effectively compressed up to 95 percent, significantly reducing the bandwidth needed at remote locations while increasing network responsiveness.
With Azure Virtual WAN, Microsoft and Barracuda CloudGen Firewall automate the process of building secure, high-performance branch-to-branch and branch-to-cloud networks. Support for Azure Virtual WAN fully automates the creation of company-wide secure WANs using Azure’s high-performance fiber backbone. Every Barracuda CloudGen Firewall supports Azure vWAN, and Barracuda Firewall Control Center provides central orchestration, management, and maintenance.
By combining Azure vWAN and CloudGen Firewall, you get:
- Fully automated rollout of branch-to-branch connectivity
- Fully automated rollout of branch-to-Azure connectivity
- Scalability to thousands of remote locations
- Active-active IPsec VPN connections to Azure vWAN for uninterrupted connectivity
- Azure Office 365 local breakout policy integration for optimized application performance
- Optimized routing and minimal latency for branch-to-branch and branch-to-Azure connectivity
- Unified network and security policy management across the company-wide WAN
About optimizing application traffic:
Azure vWAN Office 365 policies let you specify what type of application traffic to route through your paid subscription and what application traffic to optimize for direct internet breakouts. Barracuda CloudGen Firewall integrates to the Office 365 policy service provided by Azure, detects if the traffic falls in the “optimize” category, and routes traffic directly to the nearest Office 365 access points dynamically provided by the service. This ensure Office 365 traffic is always sent to the Office 365 service with the best possible round-trip time, resulting in the best possible user experience.
Intelligent Network Perimeters
Barracuda CloudGen Firewall combines Deep Packet Inspection (DPI) and behavioral traffic analysis to reliably detect and classify thousands of applications and sub-applications, regardless of advanced obfuscation, port hopping techniques, or encryption. It allows the creation of dynamic policies and facilitates establishing and enforcing access and use policies for users and groups by application, application category, location, and time of day. Administrators can now:
- Block unwanted applications for certain users or groups
- Control and throttle acceptable traffic
- Preserve bandwidth and speed-up business-critical applications to ensure business continuity
- Enable or disable specific application sub-functions (e.g., Facebook Chat, YouTube Postings, or MSN file transfers)
- Intercept SSL-encrypted application traffic
Barracuda CloudGen Firewall features advanced application-based routing path selection and Quality of Service (QoS) capabilities. These provide additional business value in addition to security by significantly improving network quality and availability, as well as reducing direct line cost due to bandwidth saved.
For rich reporting and drill-down capabilities, the CloudGen Firewall comes with real-time and historical application visibility that shows application traffic on the corporate network, thus providing a basis for deciding which connections should be given bandwidth prioritization, crucial to QoS optimization for business-critical applications. Furthermore, it allows adjusting and refining the corporate application use policies.
For an up-to-date list of applications and sub-applications that are pre-loaded into Application Control, please check the Online Application Explorer.
In addition to the thousands of applications pre-loaded in Application Control, Barracuda CloudGen Firewall makes it easy for you to create your own application definitions tailored to your specific needs.
To view a complete list of applications and sub-applications that are included under Application Control, please check the Online Application Explorer.
Different network users may need different bandwidth-use rules. Most often, access to certain network resources is limited to certain users or user groups. Preferential allocation of more bandwidth to certain users or user groups and a limitation of available bandwidth for others is a common requirement. It requires the network device to know what user an IP actually belongs to.
Barracuda CloudGen Firewall are fully user-identity aware by linking a user to one or several IP addresses. Any role assignments that result from identity communicated to the firewall by our health agents can be used within the firewall to facilitate role-based access control (RBAC). CloudGen Firewalls support authentication of users and enforcement of user-aware firewall rules, web security gateway settings, and Application Control 2.0 using Active Directory, NTLM, MS CHAP, RADIUS, RSA SecurID, LDAP/LDAPS, TACACS+, as well as authentication with x.509 certificates.
Remote Access
The influx of private computing devices, from smartphones to laptops and tablets, into the workplace may help increase productivity, flexibility, and convenience. However, BYOD adds new security challenges and risks, such as enabling and controlling access, as well as preventing data loss.
Barracuda CloudGen Firewall provides strong capabilities to give users the full advantage of their devices while reducing possible risks to the business. Unwanted applications can be blocked, LAN segmentation can protect sensitive data, and network access control can check the health state of each device connecting to the corporate network.
Barracuda CloudGen Firewall incorporates advanced site-to-site and client-to-site VPN capabilities, using both SSL and IPsec protocols to ensure remote users can easily and securely access network resources without complex client configuration and management. Every CloudGen Firewall unit supports an unlimited number of VPN clients at no extra cost.
Barracuda VPN Client also provides the ability to enforce Windows Security Center settings on client machines running Windows. This allows administrators to centrally enforce the usage of Windows Security settings on PCs. The enforced policies can include enabling the Microsoft Network Firewall, Windows Updates, Windows Virus Protection, Windows Spyware Protection, and Internet Security Settings.
Barracuda VPN Clients are available for Microsoft Windows, Mac OS, and various Linux systems.
The optional Advanced Remote Access subscription for Barracuda CloudGen Firewall adds a customizable and easy-to-use portal-based SSL VPN as well as sophisticated Network Access Control (NAC) functionality.
Barracuda Network Access Client, when used with Barracuda CloudGen Firewall, provides centrally managed Network Access Control (NAC) and an advanced personal firewall. This allows enforcement of minimum Windows client security prerequisites before being allowed access to the network or access to a quarantine network. Security posture can be specified according to available Windows patch level, availability of antivirus and/or anti-spyware, and user ID. Access restrictions are enforced locally on the client by the centrally managed personal Windows firewall as well as at the gateway. Using existing Barracuda CloudGen Firewall appliances, Barracuda Networks offers a ready-to-use Network Access Control framework without expensive investments into the basic network infrastructure. All Barracuda Network Access Clients as well as all Barracuda CloudGen Firewall units acting as policy servers can be administered, monitored, and reviewed from a single Barracuda Firewall Control Center.
Gain easy access to your organization’s applications via SSL VPN connections. Barracuda‘s Mobile Portal enables you to set up shortcuts on the home screen of devices such as smartphones or tablets. When accessing the portal via the web browser on a mobile device, users can browse apps, network folders and files as if they were connected to the office network.
The Mobile Portal supports most commonly used devices, e.g., Apple iOS, Android, and Blackberry devices.
Barracuda’s Mobile Portal is an optional feature included with the optional Advanced Remote Access subscription.
CudaLaunch is an application for Windows, macOS, iOS, and Android devices that provides mobile workers secure remote access through Barracuda CloudGen Firewall to their organization’s private cloud applications and other sensitive information. CudaLaunch provides several benefits over traditional browser-based SSL VPN remote access. As an app, it provides a familiar app store setup and install experience for end users.
Unlike browser-based remote access, CudaLaunch provides a more responsive look and feel that is unified across mobile platforms and avoids the idiosyncrasies of mobile browsers. Once an end user starts the app, a swipeable launchpad provides quick and easy access to internal applications, favorites, and TINA VPN connections (which securely connect the device to your corporate network). This richer VPN connection supports mobile apps that connect back to the corporate network (like remote desktop apps).
Designed to be completely self-configuring, CudaLaunch includes easy central management for large deployments and integrates with the powerful security features of Barracuda CloudGen Firewall. For IT administrators, the firewall provides one place to manage security policies for all types of remote access (CudaLaunch, SSL VPN, Barracuda Network Access Client, and standard IPsec). The end user experience is consistent across platforms and remote access types, making for ease of use and significantly lower support costs. The self-configuration and management of VPN connections eliminates the need to manually configure IPsec connections on Windows, macOS, iOS, and Android, making setup fast and easy.
More information on CudaLaunch is available here.
The app is available for free at:
Mac App Store (macOS)
Windows Store (Windows)
(Also available as a standalone app that requires no installation; therefore, there are no local admin rights. This version is available on the Barracuda Cloud Control only for windows version.)
App Stores (iOS)
Google Play (Android)
Please note that CudaLaunch requires Barracuda CloudGen Firewall firmware 6.1.1 and an active Advanced Remote Access subscription.
Barracuda Secure Connector appliances are purpose-built ultra-compact edge devices for the Industrial Internet of Things and SoHo use cases. They are designed to provide edge compute capabilities and backhaul all traffic to CloudGen Firewall units (Appliance, Vx or Cloud) or dedicated Secure Access Controllers for scalability. CloudGen Firewall and Secure Access Controller units apply full security inspection.
More information on Secure Connector appliances is available here.
Management & Automation
Barracuda Firewall Control Center provides 100% central management of all CloudGen Firewall functions, regardless if configuration of security, content, traffic management, networking, access policies or software updates.
Barracuda Firewall Control Center helps reducing the cost associated with security & lifecycle management while providing enhanced troubleshooting and connectivity functionality, both centrally and locally, at the managed gateway.
Barracuda Firewall Control Center allows you to create re-usable objects for any configuration entry imaginable: IP address, networks, ranges, DNS names, content security policies, network security policies etc.
These objects can be created once and reused in subsequent configurations nodes. For example, if there is an object Internal_Network_Branchname as a network object, it can be referenced in the network settings, firewall rules, and VPN settings. If the object needs to be changed, it only needs to be changed once, preferably on the Firewall Control Center. Then, the changes will be automatically applied at every location where the object is referenced. This provides a faster, easier, and more convenient method of changing configuration services across multiple units.
When configuring multiple CloudGen Firewalls across the WAN, there will always be components that the firewall have in common, such as domain names, DNS servers, NTP servers, application security configurations, URL filter configurations, and so on. Barracuda Firewall Control Center collects all of these in a repository (global configuration node) linked to multiple Barracuda CloudGen Firewalls. Using repositories on the Firewall Control Center, an administrator can update thousands of firewalls with just a single change in the repository.
Repositories still provide the flexibility to override specific settings on specific firewalls. For example, if one location uses a different DNS server than the others, you can create an explicit overwrite for just this setting on this single firewall.
With a pool license, the license of Barracuda CloudGen Firewall is tied to the Firewall Control Center, not to the serial number and hardware combination. So in case of hardware failure, a new appliance can be deployed without being relicensed. This is great for managed security services providers because they can optimize license usage.
For more details, please refer to the White Paper Barracuda Enterprise and Service Provider Licensing.
Reporting
Barracuda Firewall Report Creator is a standalone application recommended for reporting on a single appliance or up to few dozen appliances of Barracuda CloudGen Firewall. This free tool creates customized reports using statistics and logs collected directly from the deployed firewalls.
Configuration allows each report to analyze multiple appliances, using custom or predefined report data templates, and a customizable layout and delivery method. Custom reports can include the following information:
- User activity reports – include information on traffic caused by individual users, IP addresses or networks, or active directory user groups.
- Address activity reports – include information for accessed URL categories per source IP address or source network.
- URL category reports – include information on which URLs out of a specific category were accessed based on source IP address or source network.
- Application category reports – include information on detected application categories.
- Application property reports – include information on top blocked or allowed application properties.
- Applications reports – include information on detected applications in a specific application category per source IP address or source network.
- Security reports – include IPS patterns, virus scanner engine, and ATP threat reports.
- VPN usage reports – include information on usage of TINA client-to-site and site-to-site tunnels.
Firewall Report creator is included in the CloudGen Firewall base license.
Please go to login.barracudanetworks.com for the free-of-charge download.
Barracuda CloudGen Firewall allows leveraging Tufin SecureTrack to view, search and track changes in the corporate security infrastructure, and detect misconfigurations, such as rule permissiveness, shadowing, and more. This vendor-agnostic management platform gives the visibility and control needed to ensure seamless protection, availability of applications and data, and excellent user experience in heterogeneous, multi-vendor, and multi-platform infrastructures.
About Tufin
With over 2,000 customers since its inception, Tufin’s network security automation enables enterprises to implement changes in minutes instead of days, while improving their security posture and business agility. Learn more at tufin.com.