Leading logistics provider supercharges wide area network with secure SD-WAN built into Barracuda CloudGen Firewalls

Download PDF


The company was founded by Henri Essers in 1928 and has since become one of the leading companies in Europe in the field of transport and logistics for such sectors as chemicals, pharmaceuticals, healthcare, and high-quality goods. The company has experienced solid expansion in the last decade, driven by autonomous growth and a number of strategic acquisitions. The company currently has 975,000 m² of warehouse space, a fleet of 1,460 trucks and 3,050 trailers. The company has over 6,270 employees across 71 branches in 17 countries in Western and Eastern Europe. The strength of the company lies in its asset-based strategy: it is the owner of the transport fleet, warehouses and IT systems. This allows it to maintain optimum control over all strategic processes. The familial character of the company ensures that the lines of decision-making are kept short. This enables H.Essers to respond quickly to the changing demands of its clients and shifts in the international market.

The headquarters in Genk/Belgium hosts the central Citrix and Skype for Business Servers that all remote locations need to be reliably connected at all times. Large downloads from the internet occasionally adversely affects business critical application performance. In case one line goes down, activating the backup line takes some time and causes service interruptions. H.Essers was looking for direct internet breakouts at all remote locations with full centrally managed security without interfering business critical traffic.

"Of all the products we tested only Barracuda Cloud Generation Firewalls provided internet and VPN load balancing across multiple uplinks combined with full next-generation security capabilities on a single appliance."
- Ivar Indekeu, ICT Infrastructure Manager, H.Essers


  • Transport & Logistics
  • Founded in 1928
  • Based in Genk, Belgium with 71 branches in 17 countries


  • Reliably connect all remote branches to the HQ.
  • Utilize all uplinks simultaneously.
  • Prioritize Skype for Business and Citrix to utilize the best-suited uplink.
  • Integrated full security and remote connectivity.


  • High Availability setups of Barracuda CloudGen Firewalls at the HQ with ZTD rollout to all remote locations.


  • Always-on availability of Citrix and Skype for Business.
  • Efficient use of all available internet uplinks.
  • Full next-generation security levels for direct internet breakouts.

Always-on availability of business critical applications

H.Essers streamlined their WAN infrastructure and standardised on Barracuda CloudGen Firewalls of various sizes and form factors for the headquarters and all remote offices, all centrally managed by a Barracuda Firewall Control Center VC400. For the remote locations a high quality uplink with basic bandwidth is augmented with one ore multiple cost effective broadband internet lines.

Barracuda CloudGen Firewalls make sure the high quality uplink is reserved for the Citrix and Skype for Business traffic. In the unlikely event of a blackout or brownout of the high quality line, the business critical traffic is shifted to the broadband links automatically and without session loss.

Less critical applications like Outlook and regular internet access is handled by the higher bandwidth broadband internet lines. This allows making use of all uplinks at all times and to ensure around the clock availability of the centrally hosted Citrix and Skype for Business services. Security for the direct internet breakouts at the branch offices as well as guest networks is enforced directly at the remote locations with full central management via Barracuda Firewall Control Center.

"Large downloads from the Internet no longer adversely affects the quality of business critical traffic."
- Ivar Indekeu, ICT Infrastructure Manager, H.Essers

Hassle Free Deployment

Supercharging the Wide Area Network would not have been possible without Barracuda’s Zero Touch Deployment capabilities available on all CloudGen Firewalls. With no need for manual configuration on-site, Zero Touch Deployment allows to shipping the firewalls directly to the remote location where they automatically authenticate to the customer-owned Barracuda Firewall Control Center to receive configuration instructions. The process ensures full confidentiality of company data, accelerates deployment times, and helps to make large-scale rollouts in an economic manner possible at all.

"Deployment of Barracuda CloudGen Firewalls with Secure SD-WAN was easy and straightforward. Zero Touch Deployment worked very well, we can directly ship the firewalls to the remote locations."
- Ivar Indekeu, ICT Infrastructure Manager, H.Essers

About Barracuda

Barracuda simplifies IT with cloudenabled solutions that empower customers to protect their networks, applications, and data, regardless of where they reside. These powerful, easy-to-use, and affordable solutions are trusted by more than 150,000 organizations worldwide and are delivered in appliance, virtual appliance, cloud, and hybrid deployments. Barracuda’s customer-centric business model focuses on delivering highvalue, subscription-based IT solutions that provide end-to-end network and data security. For additional information, please visit barracuda.com.

About the Barracuda CloudGen Firewall

Barracuda CloudGen Firewalls feature advanced security capabilities, including integrated Intrusion Prevention (IPS), URL filtering and antivirus to identify and block evasion attempts that would trick traditional systems. Barracuda’s security extends beyond a network to Barracuda’s Advanced Threat Protection (ATP) cloud for both statistical and sandboxing analysis of zero-day and targeted threats that routinely bypass signature-based IPS and antivirus engines.

Barracuda CloudGen Firewall Fast Facts

  • Integrated next-generation security
  • Full SD-WAN capabilities included
  • Full user/group awareness
  • Full application visibility and granular access control
  • Advanced Threat Protection (incl. sandboxing)
  • Built-in web security and IDS/IPS
  • Connection-friendly and robust VPN
  • QoS and link balancing
  • Industry-leading central management