Barracuda NG Firewall 6.0.x Product Product Overview CONTENTS About Barracuda Networks, Inc 3 The Barracuda Advantage References Barracuda NG Firewall5 Application & Identity-Aware Protection for Distributed Network Environments Secure Your Networks Perimeter 6 Controlling Application Usage 8 Intrusion Detection and Prevention Malware Protection Advanced Threat Detection Web Filtering Application Control Personalized Application Control Application-Based Provider Selection Deep Application Context User Identity Awareness & Control Application Risk and Usage Report Cloud Enablement and WAN Virtualization 10 Application-Based Provider Selection Traffic Shaping and Quality of Service Failover and Link Balancing WAN Optimization Supported Virtualization and Public Cloud Offerings Secure Remote Access and Access Control Barracuda NG Firewall F10 Barracuda NG Firewall F100 / F101 Barracuda NG Firewall F200 / F201 Barracuda NG Firewall F280 Barracuda NG Firewall F300 / F301 Barracuda NG Firewall F380 Barracuda NG Firewall F400 Barracuda NG Firewall F600 Barracuda NG Firewall F800 Barracuda NG Firewall F900 Barracuda NG Firewall F1000 Barracuda NG Control Center C400 Barracuda NG Control Center C610 18 19 20 21 22 23 24 25 26 27 28 29 30 Additional Hardware Options Barracuda 3G modem [USB] Barracuda Network Module M801 Barracuda Network Module M802 Barracuda Network Module M804 Barracuda Network Module M805 Barracuda Network Module M1001 Barracuda Network Module M1002 Barracuda Network Module M1003 Barracuda 19” rack mount shelf kit Barracuda L-shape Rack Mount bracket 31 32 32 32 32 33 33 33 33 33 Features & Capabilities 12 BYOD (Bring Your Own Device) Dedicated VPN Clients Network Access Control TINA - Barracuda’s Protocol Extension to IPsec Central Management across the Enterprise14 Barracuda NG Control Center Scalable Deployment Lifecycle Management Barracuda Virtual Appliances15 Barracuda NG Firewall Barracuda NG Control Center Public Cloud Model Comparison17 for the Barracuda NG Firewall Hardware Facts Barracuda NG Firewall Barracuda VPN & Network Access Clients Barracuda NG Control Center 37 44 47 Subscriptions Availability Matrix Energize Updates Instant Replacement Warranty Extension Premium Support Barracuda NG Malware Protection Barracuda NG Web Filter Barracuda Web Filter Barracuda NG SSL VPN & NAC Advanced Threat Detection 49 49 50 50 50 51 51 51 52 52 Ordering Information Barracuda NG Firewall Appliances Barracuda NG Firewall Hardware Options Barracuda NG Firewall Virtual Appliances Barracuda NG Control Center Appliances Barracuda NG Control Center Virtual Appliances 53 56 57 57 57 3 About Barracuda Networks, Inc (NYSE: CUDA) Barracuda provides cloud-connected security and storage solutions that simplify IT. These powerful, easy-to-use, and affordable solutions are trusted by more than 150,000 organizations worldwide and are delivered in appliance, virtual appliance, cloud, and hybrid deployments. Barracuda’s customer-centric business model focuses on delivering highvalue, subscription-based IT solutions that provide end-to-end network and data security. THE BARRACUDA ADVANTAGE • Up and Running in Minutes: With no software to install or network modifications required, Barracuda products are easy to deploy and use. • No Support Phone Trees: Highly trained Barracuda support technicians are available 24/7 to answer customer calls and provide award-winning support. • Automatic Product Updates: Data collected at Barracuda Central is analyzed and used to create definitions for automatic Energize Updates that keep Barracuda products ahead of the latest threats. • Affordable, Predictable Pricing: Barracuda’s subscription-based pricing is consistent and easy to understand. Comprehensive, integrated products with no unexpected fees ensure affordability. Barracuda Labs and Barracuda Networks Technical Support Every Barracuda Networks product is backed by world-class services and technical support. To keep systems maintenance-free, Barracuda Energize Updates ensure that Barracuda Networks products are kept up-to-date to mitigate the latest security threats. Barracuda Energize Updates are backed by Barracuda Labs, a 24/7 operations center where engineers monitor the Internet and the industry for the latest threats, applications, websites, and trends. Barracuda Networks Technical Support is staffed with IT experts ready to solve technical issues. With technical support centers across the globe, Barracuda Networks is staffed 24/7 to provide immediate help without phone trees. Barracuda Networks Technical Support is available in three levels, with the highest Premium Support level providing a dedicated account manager and technical support personnel familiar with an organization’s IT environment. All Barracuda Networks appliances are built on hardened, industrial-strength equipment. Beyond the standard warranty, Barracuda Networks Technical Support offers the Instant Replacement program, where Barracuda Networks will ship replacement units within one business day to keep organizations up and running. Barracuda NG Firewall • No Specialized IT Expertise Required: All Barracuda products feature an intuitive web interface for efficient product management. Its ease of use means your IT staffers don’t need to be experts in a particular solution. Barracuda NG Firewall 4 REFERENCES No other product we tried has the flexibility the Barracuda NG deployment has with our complex remote access and site to site needs, as well as great layered security. All the issues we have raised have been promptly resolved by product development, even when they were mistakes made on our end. Great support! IT Vice President, Altair Engineering, Inc. Recently I tried one of these dedicated products to protect of advanced persistent threats. After one month of extensive monitoring it turned out that our Barracuda NG Firewalls protect our infrastructures so well, that we can continue to focus on actual business problems. Having chosen the right firewall still saves us money and time every day. CIO, Union of Turkish Bar Associations As a company with internationally distributed facilities, the centralized management concept particularly impressed us – Barracuda Networks therefore quickly became our partner of choice. Manager of IT Service and Infrastructure Technology, ODLO Sports Group AG Transportation Financial Retail Manufacturing Industry Broadcasting/Advertising NGO Governmental Food Legal Security Healthcare 5 Barracuda NG Firewall Application & Identity-Aware Protection for Distributed Network Environments Barracuda NG Firewall is a family of hardware and virtual appliances designed to protect network infrastructure, improve site-to-site connectivity and simplify administration of network operations. Beyond its powerful network firewall and VPN technologies, Barracuda NG Firewall integrates a comprehensive set of next-generation firewall technologies, including identity-aware Application Control, intrusion prevention, web filtering, antivirus, antispam, and Network Access Control. On top of these next-generation capabilities Barracuda NG Firewall provides sophisticated next-generation Advanced Persistent Threat Protection with the Barracuda Advanced Threat Detection. Barracuda NG Firewall features intelligent site-to-site traffic management capabilities that optimize both availability and performance of the Wide Area Network (WAN). Administrators can control application-level routing and prioritization of traffic across multiple links, tunnels, and traffic conditions. What are the immediate benefits of deploying a Barracuda NG Firewall? Improved security posture - From a security perspective, organizations can improve their security posture by integrating previously disparate security functions, including Web Filtering, Malware Protection, Email Security, Intrusion Prevention, Application Control, and - for protection against zero-day exploits and advanced persistent threat - Advanced Threat Detection into a single platform. Achieve full application awareness - Application Control allows for accurately identifying a vast number of protocols and applications (BitTorrent, Skype, Instant Messaging, etc.) that are traversing the network. Even if they are using advanced obfuscation techniques, port-hopping, or encryption. Barracuda’s Application Control can block the usage of unwanted applications, control and throttle acceptable traffic, and preserve bandwidth for business-critical applications to ensure business continuity. Achieve full user-based visibility and control - Barracuda NG Firewall provides seamless integration with all authentication methods (e.g., Active Directory, RADIUS, LDAP/s, etc.) to facilitate policy configuration based on the actual user and group information and not just IP addresses. Corporate network optimization - From a global network management perspective, you can reduce administrative overhead through centralized management capabilities that serve thousands of nodes and reduce hard dollar costs by better managing WAN links and link bandwidth. State-of-the-art failover and bandwidth management capabilities make sure that your business-critical traffic receives the bandwidth it deserves, even in case of link-loss. Accelerated troubleshooting - At a help desk and troubleshooting level, Barracuda NG Firewall provides unprecedented levels of visibility into individual network flows, arming the network engineer with powerful tools to diagnose and maintain the network. Barracuda NG Firewall Inside the Technology Leading next-generation firewall capabilities, industry-leading centralized management, highly resilient VPN technology combined with intelligent traffic management capabilities, allow customers to save line costs and increase overall network availability. 6 Secure Your Networks Perimeter Barracuda NG Firewall provides several layers to protect an organization’s network Barracuda Energize Updates Barracuda Advanced Threat Detection Advanced persistent threats, Advanced malware & zero-day exploits Web Filtering (cloud or on-box) Advanced persistent threats, Advanced malware & zero-day exploits Malware (AV / IPS) Malware (AV) on-box Geo IP Control DoS / DDoS URL filtering Barracuda NG Malware Protection Barracuda NG IPS Barracuda NG Firewall Barracuda NG Firewall INTRUSION DETECTION AND PREVENTION Barracuda NG Intrusion Detection and Prevention System (IDS/IPS) strongly enhances network security by providing complete and comprehensive real-time network protection against a broad range of network threats, vulnerabilities, exploits, and exposures in operating systems, applications, and databases preventing network attacks such as: • SQL injections and arbitrary code executions • DoS and DDoS attacks • Access control attempts and privilege escalations • Directory traversal and probing and scanning attempts • Cross-Site Scripting and buffer overflows • Backdoor attacks, trojans, rootkits, viruses, worms, and spyware By providing advanced attack and threat protection features such as stream segmentation and packet anomaly protection, TCP split handshake protection, IP and RPC defragmentation, FTP evasion protection, as well as URL and HTML decoding, Barracuda NG Firewall is able to identify and block advanced evasion attempts and obfuscation techniques that are used by attackers to circumvent and trick traditional intrusion prevention systems. As part of the Barracuda Energize Updates subscription, automatic signature updates are delivered on a regular schedule or on an emergency basis to ensure that Barracuda NG Firewall is constantly up-to-date. If the firewall unit is centrally managed, the pattern updates are conveniently distributed by the Barracuda NG Control Center. For a detailed feature list, please see page 38 MALWARE PROTECTION Barracuda NG Malware Protection shields the internal network from malicious content by scanning web content (HTTP and HTTPs), email (SMTP, POP3), and file transfers (FTP) via two fully integrated antivirus engines. Malware protection is based on regular signature updates as well as advanced heuristics to detect malware or other potentially unwanted programs even before signatures are available. Barracuda NG Malware Protection covers viruses, worms, trojans, malicious java applets, and programs using known exploits on PDF, pictures and office documents, macro viruses, and many more, even when using stealth or For a detailed feature list, morphing techniques for obfuscation. please see page 38 7 ADVANCED THREAT DETECTION Barracuda Advanced Threat Detection (ATD) uses next-generation sandbox technology powered by full-system emulation to catch not only persistent threats and zero-day exploits, but also advanced malware designed to evade detection. Files are forwarded to a cloud-based sandbox environment, where they are executed and analyzed to identify suspicious and malicious behavior. Barracuda ensures flexible and simple deployment with your existing network infrastructure—no additional hardware is required since resource intensive sandboxing is offloaded to the cloud. The cloud database is continuously updated by all Barracuda NG Firewalls with enabled ATD and, thereby, speed up the processing of already known files. Barracuda NG Firewall Barracuda NG Firewall Barracuda NG Firewall Barracuda NG Firewall Barracuda NG Firewall Barracuda NG Firewall Barracuda NG Firewall Barracuda NG Firewall Barracuda ATD Signature DB Barracuda NG Firewall The administrator has full policy control over how PDF documents, Microsoft Office Files, EXEs/ MSIs/DLLs, Android APKs, compressed files and archives are emulated and delivered to the client. Based on identified malware activity, infected users can be automatically quarantined preventing the malware from spreading within the network. Customizable, on-demand analysis reports for any emulated file provide full insight and details on malicious activities, file behavior, system-registry entries, evasion and obfuscation techniques. This also enables network activities such as establishing encrypted connections For a detailed feature list, to Botnet Command and Control Centers for increased security posture to please see page 39 evade scaled Botnet attacks. Barracuda NG Firewall WEB FILTERING The web filtering options for the Barracuda NG Firewall options enable highly granular, real-time visibility into online activity, broken down by individual users and applications, letting administrators create and enforce effective Internet content and access policies. It protects user productivity, blocks malware downloads and other web-based threats, and enables compliance by blocking access to unwanted websites and servers, providing an important additional layer of security alongside application control. • Barracuda Web Filter offers online URL categorization (requires a valid Energize Updates subscription). For a detailed feature list, please see page 42 • Barracuda NG Web Filter can be operated in online and offline mode (available as a separate subscription) For a detailed feature list, please see page 43 8 Controlling Application Usage Block unwanted applications, control acceptable traffic, and ensure business continuity Barracuda NG Firewall gives administrators granular control over applications, allowing them to define rules for forwarding data traffic using the best respective transmission channels based on type of application, user, content, time of day, and geographical location. Mobile devices, online applications, social networks, and streaming media have caused an enormous increase in non-business network data traffic, pushing bandwidth capacities to their limits and causing degradation in performance of business-critical applications. General Application Control Custom App General use X Games Games use Y use X or Y use Z ISP X ISP Y Barracuda NG Firewall Custom App ISP Z Barracuda NG Firewall Application Usage & Risk Report.pdf APPLICATION CONTROL Barracuda NG Firewall provides a powerful and extremely reliable detection and classification of more than 1,400 applications and sub-applications by combining Deep Packet Inspection (DPI) and behavioral traffic analysis – no matter if the protocols are using advanced obfuscation, port hopping techniques, or encryption. It allows the creation of dynamic application policies and facilitates establishing and enforcing acceptable access and use policies for users and groups by application, application category, location, and time of day. Barracuda NG Firewall combines its application control with the seamless integration of authentication schemes like Active Directory, LDAP/S, NTLM, etc. As a consequence, an administrator is always on top of what the users to on the organization’s network. Barracuda NG Firewall features advanced application-based routing path selection and Quality of Service (QoS) capabilities. These provide additional business value in addition to security by significantly improving network quality and availability, as well as reducing direct line cost due to bandwidth saved. For rich reporting and drill-down capabilities, Barracuda NG Firewall comes with real-time and historical application visibility that shows application traffic on the corporate network, thus providing a basis for deciding which connections should be given bandwidth prioritization, crucial to QoS optimization for For a detailed feature list, business-critical applications. Furthermore, it allows adjusting and refining please see page 37 the corporate application use policies. PERSONALIZED APPLICATION CONTROL On top of the 1,400+ applications that are delivered out of the box and constantly updated, Barracuda NG Firewall provides a way to easily create user-defined application definitions for best-in-class application control customized and tailored to an organization’s specific needs. 9 APPLICATION-BASED PROVIDER SELECTION The combination of next-generation security and adaptive WAN routing allows Barracuda NG Firewall to dynamically assign available bandwidth for several links not only based on protocol, user, location, and content, but also based on applications, application categories, and web filter categories. This keeps expensive, highly available lines free for business and mission-critical applications, while significantly reducing response times and freeing up additional bandwidth. DEEP APPLICATION CONTEXT The deep application context analysis allows for deeper inspection of the application data stream by continually evaluating the actual intention of applications and the respective users. By this means administrators can gain detailed insight into what a specific application was used for or if a user was trying to circumvent the corporate application usage policy. USER IDENTITY AWARENESS & CONTROL Barracuda NG Firewall supports authentication of users and enforcement of user-aware firewall rules, web filter settings, and application control by seamlessly integrating with • Microsoft and Citrix terminal service environments RSA SecurID x.509 TACACS+ RADIUS i • Active Director LDAP/S • NTLM SMS Passcode (VPN) • RADIUS • RSA SecurID NTLM • LDAP/LDAPS • TACACS+ DC Agent For a detailed feature list, please see page 40 TS Agent Active Directory Citrix TS Microsoft TS APPLICATION RISK AND USAGE REPORT The Application Usage and Risk Report is a predefined report type in the Barracuda Report Creator tool providing automated reports and risk analysis based on the network traffic that is traversing the network. It provides an overview on how effective the currently deployed technologies are in detecting and enforcing the corporate application usage policies and gives recommendations what should be taken into account when redefining these policies. For collecting the traffic required for this report, Barracuda offers two different approaches: • Layer2 Bridging • SPAN Port / Port Mirroring In either way, collecting the traffic has no impact on the firewall performance at all. The report creation can be started manually (on-demand) or scheduled (including automated email distribution). And - of course - this report is fully customizable to comply with possible branding requirements. Application Usage and Risk Report Top Application Traffic traversing the Network The Barracuda NG Firewall provides powerful and extremely reliable detection and classification of applications and sub-applications by combining Deep Packet Inspection (DPI) and behavioral traffic analysis - no matter if the protocols are using advanced obfuscation, port hopping techniques or encryption. The Barracuda NG Firewall comes with real-time and historical application visibility that shows application traffic on the corporate network. This provides a basis for deciding which connections should be given bandwidth prioritization, which is crucial for QoS optimization of business-critical applications. Furthermore, it allows for adjusting and refining the corporate application use policy. Barracuda Networks provides a risk rating for any identified application and protocol crossing the network. Based in the conducted traffic analysis the overall risk rating is as follows: ACME Inc. Application Traffic Risk Rating: The following chart provides an overview of the top applications based on bandwidth consumption that are traversing the network of ACME Inc.: Applications Risk ESXi Sessions 148.4 GB 25779 46.0 GB 1036202 Copy 27.8 GB 9837 VNC 7.7 GB 24 Amazon Webservices 4.6 GB 1625 Youtube Watch Video 4.2 GB 1735 Dropbox 1.6 GB 13208 Shoutcast 1.5 GB 18 Jabber General 1.3 GB 167 Google Services Base 1.1 GB Microsoft Update 43714 1.0 GB 4319 Skype General 647.9 MB 684312 Grooveshark Play 567.8 MB 74 Facebook Base 242.7 MB 22148 Lync 231.2 MB 6393 Avira AV Update 193.2 MB 184 Google Safe Browsing 192.7 MB 17797 OpenVPN 171.2 MB 12 Vkontakte 164.5 MB 525 Icecast 146.5 MB 5 Soundcloud 136.1 MB 3249 Page 6 of 19 Example of a report pdf page Traffic Web browsing Barracuda NG Firewall • and more... local authentication database 10 Cloud Enablement and WAN Virtualization The need for an Application Delivery Network Today’s corporate networks are being transformed by the proliferation of mobile devices and the increasing adoption of SaaS offerings like Microsoft’s Office 365 and moving corporate services to private or public clouds. The net result of this is increased dispersion or fragmentation of corporate network into multiple dislocated segments and a massively increased attack surface. In this scenario a firewall solution is needed that can be deployed to multiple locations on the network with the corresponding next-generation deep inspection features to mitigate attacks. The introduction of, e.g., Office 365 all of a sudden creates a need for direct internet break outs at multiple branch office locations. Thus multiple enforcement points need to be created. Business critical internal traffic running across the WAN links must be protected against outages as well as quality of service impairments due to aggressive but less important network activities on the same physical infrastructure. Multiple Barracuda NG firewalls deployed to multiple physical and cloud locations allow an organization to span a highly performant and secure logical application delivery network (ADN) on top of the physical and virtualized infrastructure components. In conjunction with our leading central management concepts both the initial implementation and subsequent life cycle management tasks around the AND can be accomplished a surprisingly low total cost. Barracuda NG Firewall The key feature here is that full next-gen deep inspection can be combined with smart policy based adaptive traffic management. Policy based means that applicable QoS settings (bandwidth guarantees, priorities), network path selection, e.g., MPLS vs VPN, and/or privacy requirements can be based on the application or the person/groups causing the traffic. Adaptive means that failover policies can be defined that make sure that in case of unavailability of a particular path available alternative paths can be utilized. This feature allows for improved fault tolerance against outages as well for cost optimization strategies where multiple carriers/ISPs are combined to get the required bandwidth at an optimum price point. Public cloud offerings like Amazon EC2 and Microsoft Azure are a new and increasingly attractive way to lower cost around IT operations. The business lines profit from a faster-time-to-market, good compute elasticity and an easy option to achieve global service availability quickly. There are challenges too. Replication typical on-premises DC concepts in these environments is impossible without a cloud compatible firewall product. The Barracuda NG Firewall is ideal for securing and compartmentalizing these public cloud environments – connecting on-premises networks to the cloud and connecting logically separated components within the cloud data centers. APPLICATION-BASED PROVIDER SELECTION But before an organization can benefit of the cloud, it is mandatory to get to the cloud! As mentioned earlier, Barracuda NG Firewall includes information on application, application categories, as well as web filter categories into its link selection policy. Such link policies can force for instance business critical traffic to use T1 lines whereas uncritical bulk traffic is routed via less expensive lines. TRAFFIC SHAPING AND QUALITY OF SERVICE Limited network resources make bandwidth prioritization a necessity. Barracuda NG Firewall provides strong Quality of Service (QoS) that lets the administrator apply quality aspects and service guarantees to selected traffic flows within the WAN. QoS is often used to prioritize the network traffic of applications that are critical and must not be affected by the network traffic of other applications. Barracuda NG Firewall provides a large set of QoS techniques, such as traffic shaping, on-the-fly traffic prioritization, and bandwidth partitioning, which assigns a bandwidth limit to certain types of traffic. To select traffic for different priority classes, the available real-time traffic analysis can be used to identify whether network traffic was sent by business-critical applications or by potentially unwanted applications. 11 FAILOVER AND LINK BALANCING To ensure the best and most cost-efficient connectivity, Barracuda NG Firewall provides a wide range of built-in uplink options such as unlimited leased lines, up to four uplinks, etc. By eliminating the need to purchase additional devices for link balancing, security conscious customers will have access to a WAN connection that never goes down, even if one or two of the existing WAN uplinks are severed. Further, traffic intelligence mechanisms make sure the next defined uplink is activated on the fly and all traffic is rerouted to make full use of the remaining lines. In the event that backup lines provide less bandwidth, intelligent traffic shaping automatically prioritizes business-critical applications, networks, or distinct endpoints. WAN OPTIMIZATION Barracuda NG Firewall can significantly enhance the WAN performance of distributed network environments by improving availability, performance, and response time of business-critical applications by lowering throughput and transmission delays, affecting time-sensitive decisions and enterprise profitability. The next-generation networking concept of Barracuda NG Firewall provides a set of powerful features to efficiently reduce and offset the negative effects of high line latencies and response times. By implementing enterprise-grade WAN acceleration features such as data deduplication, traffic compression, and protocol optimization, Barracuda NG Firewall can significantly improve site-to-site WAN traffic and increase productivity by accelerating the delivery of business applications - at no extra charge. WAN traffic can be effectively compressed up to 95 percent, significantly reducing the bandwidth needed at remote locations while increasing network responsiveness. SUPPORTED VIRTUALIZATION AND PUBLIC CLOUD OFFERINGS Barracuda NG Firewall 12 Secure Remote Access and Access Control Barracuda NG Firewall incorporates advanced site-to-site and client-to-site VPN capabilities, using both SSL and IPsec protocols to ensure remote users can easily and securely access network resources without time-consuming client configuration and management. The communication protocols used with our VPN clients are optimized to be fully roaming-capable by quickly reconnecting upon loss of communication. Smart pathfinder technology determines the nearest point of entry to the corporate network. Advanced NAT traversal technology can use different For a detailed feature list, please see page 44 ports encapsulated in either TCP or UDP and, thus, is able to pass through web proxies. BYOD Mobile Device VPN Support Dedicated VPN Clients TINA VPN Connection TINA VPN Connection Mobile Portal Clientless SSL VPN Barracuda NG Firewall Barracuda NG Firewall BYOD (BRING YOUR OWN DEVICE) The influx of private computing devices, from smartphones to laptops and tablets, into the workplace may help increase productivity, flexibility, and convenience. However, BYOD adds new security challenges and risks, such as enabling and controlling access, as well as preventing data loss. Barracuda NG Firewall provides strong capabilities to give users the full advantage of their devices while reducing possible risks to the business. Unwanted applications can be blocked, LAN segmentation can protect sensitive data, and network access control can check the health state of each device connecting to the corporate network. Barracuda‘s Mobile Portal enables you to set up shortcuts on the home-screen of devices such as smartphones or tablets. When accessing the portal via the web browser on a mobile device, users can browse apps, network folders and files as if they were connected to the office network. The Mobile Portal supports most of commonly used devices, e.g., Apple iOS, Android, and Blackberry devices and is part of the “NG SSL VPN and NAC” subscription. 13 DEDICATED VPN CLIENTS Every Barracuda NG Firewall unit supports an unlimited number of VPN clients at no extra cost. The Barracuda VPN client also provides the ability to enforce Windows Security Center settings on client machines running Windows. This allows administrators to centrally enforce the usage of Windows Security settings on PCs. The enforced policies can include enabling the Microsoft Network Firewall, Windows Updates, Windows Virus Protection, Windows Spyware Protection, and Internet Security Settings. Barracuda VPN Clients are available for Microsoft Windows, Mac OS, and various Linux systems. NETWORK ACCESS CONTROL The optional Barracuda NG Firewall SSL VPN and NAC subscription adds a customizable and easy-to-use portal-based SSL VPN as well as sophisticated Network Access Control (NAC) functionality. The Barracuda Network Access Client, when used with a Barracuda NG Firewall, provides centrally managed Network Access Control (NAC) and an advanced personal firewall. This allows enforcement of minimum Windows client security prerequisites before being allowed access to the network or access to a quarantine network. Security posture can be specified according to available Windows patch level, availability of antivirus and/or anti-spyware, and user ID. Access restrictions are enforced locally on the client by the centrally managed personal Windows firewall as well as at the gateway. Using existing Barracuda NG Firewall appliances, Barracuda Networks offers a ready-to-use Network Access Control framework without expensive investments into the basic network infrastructure. All Barracuda Network Access Clients as well as all Barracuda NG Firewall units acting as policy servers can be administered, monitored, and reviewed via the Barracuda NG Control Center. Barracuda VPN Client for Windows 7 TINA - BARRACUDA’S PROTOCOL EXTENSION TO IPSEC Due to the limitations that come with standard IPsec connections Barracuda Networks created several powerful extensions to standard IPsec tunnel management. This core of the Barracuda NG VPN engine is called TINA (Transport Independent Network Architecture Virtual). The TINA protocol allows to use TCP, UDP, ESP, and IPsec protocols for high speed VPN connections which improves the VPN connectivity substantially by adding: • Endpoint-to-Endpoint (not network-to-network) connectivity • NAT friendliness • Multiple physical transport paths for a logical tunnel • Multiple tunnels in between two locations • HTTPS and SOCKS4/5 proxy compatibility • Dynamic Address Support • Tunnel heartbeat monitoring Barracuda NG Firewall Barracuda VPN Client for Mac OS 14 Central Management across the Enterprise Barracuda NG Control Center To centralize management across many different firewalls and remote access users, the Barracuda NG Control Center enables administrators to manage and configure security, content, traffic management, and network access policies from a single interface. Template-based configuration and globally available security objects enable efficient configuration across thousands of locations. The Barracuda NG Control Center helps significantly reduce the cost associated with security management while providing extra functionality both centrally and locally at the managed gateway. Software patches and version upgrades are centrally controlled from within the management console and deployment can be applied to all managed devices. Highly customizable administrative roles can be defined to delegate administrative capabilities for specific departments or locations. Barracuda NG Firewall For a detailed feature list, please see page 47 Barracuda NG Control Center’s Status Map displays a drill down status overview of all centrally managed Barracuda NG Firewall units. SCALABLE DEPLOYMENT Managing the security issues in a widely distributed enterprise network can be painful and extremely time consuming. Managing a system may take only 15 minutes per day. But having 20 firewall systems in place results in five hours per day – just to manage the existing system. With Barracuda NG Control Center, managing mulitple Barracuda NG Firewalls takes the same amount of time as managing one. • Create pre-configured templates for easy-rollout. • Have all information about the enterprise security deployment available in real time. • Create reports of either one or all Barracuda NG Firewalls. LIFECYCLE MANAGEMENT Scalable Barracuda NG Firewalls offer companies sustainable investment protection. Energize Updates automatically provide the latest firmware and threat definitions to keep the appliance up to date. With a maintained Instant Replacement subscription, organizations receive a new appliance with the latest specs every four years. 15 Barracuda Virtual Appliances Virtual versions of Barracuda’s hardware appliance-based solutions As organizations have adopted virtualization for their server infrastructures, there has been a corresponding trend to extend the benefits of virtualization to the security layer. The Barracuda NG Firewall Vx provides the same powerful technology, comprehensive features, and ease-of-use found in a Barracuda NG Firewall hardware appliance. It is ideally suited for organizations that are standardizing hardware platforms or deploying virtual environments. Beyond its powerful network firewall, IPS, and VPN technologies, Barracuda NG Firewall Vx integrates a comprehensive set of nextgeneration firewall technologies, including Layer 7 Application Control, availability, and traffic flow optimization across the wide area network, web filtering, antivirus, anti-spam, and network access control enforcement. Note: For more details on Barracuda Virtual Appliances, please visit http://www.barracuda.com/vx. BARRACUDA NG FIREWALL For a detailed feature list, please see page 37 Available for: BARRACUDA NG FIREWALL VX EDITIONS VF25 VF50 VF100 VF250 VF500 VF1000 VF2000 VF4000 VF8000 CAPACITY Number of Protected IPs 25 50 100 250 500 Allowed Cores 2 2 2 2 2 Unlimited Unlimited Unlimited Unlimited 2 4 8 16 NG Web Security Optional Advanced Threat Detection Optional Spam Filter Optional NG SSL VPN and NAC Optional For a detailed feature list, please see page 47 BARRACUDA NG CONTROL CENTER Available for: BARRACUDA NG CONTROL CENTER STANDARD EDITION ENTERPRISE EDITION GLOBAL EDITION Available models VC400 VC610 VC820 Maximum managed gateways [recommended] No limit [20] No limit [depending on HW] No limit [depending on HW] Multi tenancy - Yes, with configuration groupings Yes, includes support for 5 tenants (additional tenants available) Manageable configuration groupings 1 No limit No limit Optional Optional HA license included - - Optional AVAILABLE OPTIONS High availability (HA) support Additional tenant for multi tenancy Barracuda NG Firewall AVAILABLE SUBSCRIPTIONS 16 PUBLIC CLOUD Growth in cloud computing capabilities and services has driven more data into places where traditional IT security measures cannot reach; specifically, data centers not owned by your corporate IT group. Barracuda NG Firewall provides centralized management and highly secure, encrypted traffic to, from, and within public cloud deployments. Integrated Next-Generation Security Barracuda NG Firewall is designed and built from the ground up to provide comprehensive, next-generation firewall capabilities. Based on application visibility, user-identity awareness, intrusion prevention, and centralized management, Barracuda NG Firewall is the For a detailed feature list, ideal solution for today’s dynamic enterprises that are adding public cloud please see page 37 deployments into their company network. Central Management Users of a Barracuda NG Firewall benefit from the same single-pane-of-glass central management that is used in on-premises deployments. It enables users to manage the secure VPN connections, to, from, and within public cloud deployments, and the Barracuda NG Firewall itself. For a detailed feature list, please see page 47 For more details on Microsoft Azure and Barracuda NG Firewall, please visit barracuda.com/programs/azure. MICROSOFT AZURE - COMPUTE INSTANCE NAME SMALL (A1) MEDIUM (A2) LARGE (A3) EXTRA LARGE (A4) CAPABILITIES Barracuda NG Firewall Virtual Cores LEVEL 2 LEVEL 4 LEVEL 6 LEVEL 8 1 2 4 8 Firewall Throughput 400 Mbps 2 Gbps 5 Gbps 9 Gbps VPN Throughput 120 Mbps 500 Mbps 1 Gbps 1.5 Gbps IPS Throughput 80 Mbps 900 Mbps 2.5 Gbps 3 Gbps Concurrent Sessions 35,000 300,000 500,000 1,000,000 New Session/s 2,500 16,000 35,000 45,000 Malware Protection Optional Optional Optional Optional Advanced Threat Detection Optional Optional Optional Optional Optional Optional FEATURES 1 Premium Support For more details on Amazon Web Services and Barracuda NG Firewall, please visit barracuda.com/programs/aws. AMAZON WEB SERVICES - COMPUTE INSTANCE NAME M1.SMALL C1.MEDIUM M1.XLARGE C1.XLARGE CAPABILITIES LEVEL 2 LEVEL 4 LEVEL 6 LEVEL 8 Virtual Cores 1 Max Number of Interfaces 2 2 4 8 2 4 4 Firewall Throughput 400 Mbps 2 Gbps 5 Gbps 9 Gbps VPN Throughput 120 Mbps 500 Mbps 1 Gbps 1.5 Gbps IPS Throughput 80 Mbps 900 Mbps 2.5 Gbps 3 Gbps Concurrent Sessions 35,000 300,000 500,000 1,000,000 New Session/s 2,500 16,000 35,000 45,000 Malware Protection Optional Optional Optional Optional Advanced Threat Detection Optional Optional Optional Optional Optional Optional FEATURES 1 Premium Support 17 Model Comparison for the Barracuda NG Firewall With hardware models available for small branch offices as well as large headquarters and data centers, and a corresponding offering of virtual appliances, the Barracuda NG Firewall is designed for deployment across the entire enterprise. MODEL COMPARISON F10 F100/ F200/ F300/ F280 F380 F101 F201 F301 F400 F600 F800 F900 F1000 CAPACITY (more detailed on page 18ff.) VPN Throughput 3 300 Mbps 85 Mbps 300 Mbps 85 Mbps 650 Mbps 120 Mbps 1.6 Gbps 310 Mbps 680 Mbps 370 Mbps 3.8 Gbps 750 Mpbs 5.0 Gbps 960 Mbps 16.3 Gbps 2 2.3 Gbps 2 19.6 Gbps 2 6.8 Gbps 2 22.2 Gbps 2 7.6 Gbps 2 40 Gbps 2 10 Gbps 2 IPS Throughput 1 60 Mbps 60 Mbps 115 Mbps 450 Mbps 125 Mbps 1.1 Gbps 1.5 Gbps 3.9 Gbps 2 4.8 Gbps 2 5.4 Gbps 2 10 Gbps 2 Concurrent Sessions 2,000 8,000 35,000 100,000 70,000 200,000 310,000 2,000,000 2 2,500,000 2 2,800,000 2 4,000,000 2 New Sessions/s 1,000 1,500 2,500 Firewall Throughput 1 9,000 2,500 9,500 Firewall Users Site-to-Site VPN Tunnels Barracuda VPN Clients 5 5 25 50 25 (recommended) 4 AVAILABLE SUBSCRIPTIONS (more detailed on page 49ff.) Mandatory Instant Replacement Optional Warranty Extension Optional Cold Spare Unit Optional Premium Support Optional NG Web Security 5 Optional NG Web Filter NG Malware Protection NG SSL VPN & NAC Advanced Threat Detection Optional 1 2 3 200,000 2 1,000 2,000 No limit No limit 50 50 100 500 Optional Optional Dedicated VPN Clients 4 5 Branch Office Firewalls F10 Basically, the number of Barracuda VPN Clients connecting is unlimited. The Barracuda NG Web Security subscription bundles the Barracuda NG Web Filter and Barracuda NG Malware Protection subscription. Head Office / Core Firewalls F380 Public Cloud F400 F100 F600 F200 User Interface / Tools 160,000 2 Optional Measured with large packets (MTU1500) Measured with 10GbE fiber ports. VPN throughput using AES-128 NOHASH SSL VPN Mobile Support 110,000 2 150,000 2 F800 F280 F900 F300 F1000 Vx Barracuda NG Firewall F1000 IPMI CONSOLE USB Control Center Servers USB MGMT Barracuda NG Firewall Energize Updates 16,000 18 Hardware Facts for the Barracuda NG Firewall BARRACUDA NG FIREWALL F10 INTERFACE MTBF [SYSTEM] Copper Ethernet NICs 4x1 GbE USB 2.0 2 Serial / console 1 [RJ45] >5 CERTIFICATIONS & COMPLIANCE CE emissions Yes PERFORMANCE [AS OF FIRMWARE RELEASE 6.0.x] CE electrical safety Yes Firewall throughput [Mbps] 300 FCC emissions Yes VPN throughput [AES-128, NOHASH, Mbps] 85 ROHS compliant Yes VPN throughput [AES-128, MD5, Mbps] 75 POWER & EFFICIENCY VPN throughput [AES-128, SHA, Mbps] 75 Power supply type External brick VPN throughput [AES-256, MD5, Mbps] 65 Power type [AC/DC] AC Input rating [Volts] 100-240 IPS throughput [Mbps] Barracuda NG Firewall MTBF [yrs.] 1 1 60 Concurrent sessions 2,000 Input frequency [Hz] New sessions/s 1,000 Auto sense Yes Wattage / max. power draw [W] 40 Max. power draw [Amps.] 1.6 Max. heat dissipation [W] 36 2 MEMORY RAM [MB] 512 MASS STORAGE Type Size [GB] Flash Max. heat dissipation [BTU] 123 4 or better Energy efficiency [average] > 80% SIZE, WEIGHT, DIMENSIONS Weight appliance [lbs] Weight carton with appliance [lbs] Appliance size: width x depth x height [in] Carton size: width x depth x height [in] Form factor PACKAGING CONTENT 4.4 Appliance Yes 6.6 Serial cable Yes Straight network cable Yes Cross network cable Yes External power brick & cables Yes USB flash drive for recovery & installation Yes Quick start guide Yes 9.4 x 6.5 x 1.2 10.2 x 12.6 x 5.5 Mini HARDWARE Display Hardware crypto accelerator Cooling Power supply Yes, built-in Fanless Single, external ENVIRONMENTAL Noise emission [db/A] Operating temperature [°C] < 32 0 to +40 Storage temperature [°C] -20 to +70 Operating humidity [non-condensing] 5% to 95% 1 2 Measured with large packets (MTU1500) Measured with TCP 50-60 19 INTERFACE Copper Ethernet NICs USB 2.0 Serial / console Integrated WiFi (IEEE 802.11b/g/n) BARRACUDA NG FIREWALL F100 / F101 ENVIRONMENTAL 4x1 GbE 2 1 [RJ45] Model F101 only Noise emission [db/A] Operating temperature [°C] < 32 / 45 5 0 to +40 Storage temperature [°C] -20 to +70 Operating humidity [non-condensing] 5% to 95% PERFORMANCE [AS OF FIRMWARE RELEASE 6.0.x] MTBF [SYSTEM] Firewall throughput [Mbps] 1 300 MTBF [yrs.] VPN throughput [AES-128, NOHASH, Mbps] 85 CERTIFICATIONS & COMPLIANCE VPN throughput [AES-128, MD5, Mbps] 80 CE emissions Yes VPN throughput [AES-128, SHA, Mbps] 78 CE electrical safety Yes VPN throughput [AES-256, MD5, Mbps] 70 FCC emissions Yes IPS throughput [Mbps] 1 60 ROHS compliant Yes Concurrent sessions 8,000 POWER & EFFICIENCY New sessions/s 2 1,500 Power supply type 2 MASS STORAGE Type Size [GB] 4 or better Weight carton with appliance [lbs] AC Input rating [Volts] 100-240 Auto sense 50-60 Yes Wattage / max. power draw [W] 60 Max. power draw [Amps.] 1.6 7.7 Max. heat dissipation [W] 60 SIZE, WEIGHT, DIMENSIONS Weight appliance [lbs] Power type [AC/DC] Input frequency [Hz] Flash External brick 12.1 Max. heat dissipation [BTU] 205 Appliance size: width x depth x height [in] 14.7 x 7.5 x 2.0 Energy efficiency [average] > 83% Carton size: width x depth x height [in] 18.5 x 14.0 x 7.1 Form factor Compact HARDWARE Display Hardware crypto accelerator Cooling Power supply Yes, built-in Fanless 3 Single, external PACKAGING CONTENT Appliance Yes Serial cable Yes Straight network cable Yes Cross network cable Yes External power brick & cables Yes USB flash drive for recovery & installation Yes Quick start guide Yes Wireless antenna Yes, for F101 only Barracuda 19” rack mount shelf kit Note: While it is technically feasible and fully supported to run the Barracuda NG Malware Protection and the Barracuda Web Filter on this unit, Barracuda Networks recommends offloading Malware Protection and Web Filter functions to the Barracuda Web Security Service for best performance. 1 2 3 Optional Measured with large packets (MTU1500) Measured with TCP If model F101 is ordered with the Barracuda ISDN PCI Modem M20, a low noise fan will be installed to make sure the heat generated by the data card during extended operation can be dissipated. Barracuda NG Firewall MEMORY RAM [GB] >5 20 BARRACUDA NG FIREWALL F200 / F201 INTERFACE Copper Ethernet NICs USB 2.0 Serial / console Barracuda NG Firewall Integrated WiFi (IEEE 802.11b/g/n) ENVIRONMENTAL 4x1 GbE 2 1 [RJ45] Model F201 only Noise emission [db/A] Operating temperature [°C] 47 0 to +40 Storage temperature [°C] -20 to +70 Operating humidity [non-condensing] 5% to 95% PERFORMANCE [AS OF FIRMWARE RELEASE 6.0.x] MTBF [SYSTEM] Firewall throughput [Mbps] 1 650 MTBF [yrs.] VPN throughput [AES-128, NOHASH, Mbps] 120 CERTIFICATIONS & COMPLIANCE VPN throughput [AES-128, MD5, Mbps] 110 CE emissions Yes VPN throughput [AES-128, SHA, Mbps] 110 CE electrical safety Yes VPN throughput [AES-256, MD5, Mbps] 100 FCC emissions Yes IPS throughput [Mbps] 1 115 ROHS compliant Yes Concurrent sessions 35,000 POWER & EFFICIENCY New sessions/s 2 2,500 Power supply type MEMORY RAM [GB] 2 MASS STORAGE >6 External brick Power type [AC/DC] AC Input rating [Volts] 100-240 Input frequency [Hz] 50-60 Type Solid State Auto sense Size [GB] 40 or better Wattage / max. power draw [W] 60 Max. power draw [Amps.] 1.6 Max. heat dissipation [W] 60 SSD MTBF [hours] 1,200,000 SIZE, WEIGHT, DIMENSIONS Yes Weight appliance [lbs] 8.0 Max. heat dissipation [BTU] 205 Weight carton with appliance [lbs] 12.3 Energy efficiency [average] > 83% Appliance size: width x depth x height [in] 14.7 x 7.5 x 2.0 PACKAGING CONTENT Carton size: width x depth x height [in] 18.5 x 14.0 x 7.1 Appliance Yes Compact Serial cable Yes Straight network cable Yes Cross network cable Yes External power brick & cables Yes USB flash drive for recovery & installation Yes Quick start guide Yes Wireless antenna Yes, for F201 only Form factor HARDWARE Display Hardware crypto accelerator Cooling Power supply Yes, built in Fan Single, external Barracuda 19” rack mount shelf kit 1 2 Measured with large packets (MTU1500) Measured with TCP Optional 21 INTERFACE Copper Ethernet NICs USB 2.0 Serial / console Integrated WiFi (IEEE 802.11b/g/n) BARRACUDA NG FIREWALL F280 ENVIRONMENTAL 4x1 GbE 2 1 [RJ45] Yes Noise emission [db/A] Operating temperature [°C] 47 0 to +40 Storage temperature [°C] -20 to +70 Operating humidity [non-condensing] 5% to 95% PERFORMANCE [AS OF FIRMWARE RELEASE 6.0.x] MTBF [SYSTEM] Firewall throughput [Gbps] 1 1.6 MTBF [yrs.] VPN throughput [AES-128, NOHASH, Mbps] 310 CERTIFICATIONS & COMPLIANCE VPN throughput [AES-128, MD5, Mbps] 290 CE emissions Yes VPN throughput [AES-128, SHA, Mbps] 260 CE electrical safety Yes VPN throughput [AES-256, MD5, Mbps] 250 FCC emissions Yes IPS throughput [Mbps] 1 450 ROHS compliant Yes Concurrent sessions New sessions/s 2 100,000 9,000 4 MASS STORAGE POWER & EFFICIENCY Power supply type External brick Power type [AC/DC] AC Input rating [Volts] 100-240 Input frequency [Hz] 50-60 Type Solid State Auto sense Size [GB] 80 or better Wattage / max. power draw [W] 60 Max. power draw [Amps.] 1.6 Max. heat dissipation [W] 60 SSD MTBF [hours] 1,200,000 SIZE, WEIGHT, DIMENSIONS Yes Weight appliance [lbs] 5.1 Max. heat dissipation [BTU] 205 Weight carton with appliance [lbs] 8.4 Energy efficiency [average] > 83% Appliance size: width x depth x height [in] 10.7 x 7.7 x 1.7 PACKAGING CONTENT Carton size: width x depth x height [in] 16.7 x 12.1 x 6.4 Appliance Yes Compact Serial cable Yes Straight network cable Yes Cross network cable Yes External power brick & cables Yes USB flash drive for recovery & installation Yes Quick start guide Yes Wireless antenna Yes Form factor HARDWARE Display Hardware crypto accelerator Cooling Power supply Yes Fan Single, external 2x Barracuda L-shape rack mount bracket 1 2 Measured with large packets (MTU1500) Measured with TCP Optional Barracuda NG Firewall MEMORY RAM [GB] >6 22 BARRACUDA NG FIREWALL F300 / F301 INTERFACE ENVIRONMENTAL 4x1 GbE + 4x1 10/100 1 Copper Ethernet NICs USB 2.0 2 Serial / console 1 [RJ45] Integrated WiFi (IEEE 802.11b/g/n) Model F301 only PERFORMANCE [AS OF FIRMWARE RELEASE 6.0.x] Operating temperature [°C] N/A 0 to +40 Storage temperature [°C] -20 to +70 Operating humidity [non-condensing] 5% to 95% MTBF [SYSTEM] MTBF [yrs.] >5 680 CERTIFICATIONS & COMPLIANCE VPN throughput [AES-128, NOHASH, Mbps] 370 CE emissions Yes VPN throughput [AES-128, MD5, Mbps] 300 CE electrical safety Yes VPN throughput [AES-128, SHA, Mbps] 290 FCC emissions Yes VPN throughput [AES-256, MD5, Mbps] 220 ROHS compliant Yes IPS throughput [Mbps] 2 125 POWER & EFFICIENCY Firewall throughput [Mbps] 2 Concurrent sessions 70,000 Power supply type Internal New sessions/s 3 2,500 Power type [AC/DC] AC Input rating [Volts] 100-240 MEMORY RAM [GB] Barracuda NG Firewall Noise emission [db/A] 2 MASS STORAGE Type Size [GB] SSD MTBF [hours] Input frequency [Hz] Auto sense Solid State 50-60 Yes Wattage / max. power draw [W] 60 80 Max. power draw [Amps.] 1.6 1,200,000 Max. heat dissipation [W] 60 Max. heat dissipation [BTU] 205 > 83% SIZE, WEIGHT, DIMENSIONS Weight appliance [lbs] 9.9 Energy efficiency [average] Weight carton with appliance [lbs] 17.6 PACKAGING CONTENT Appliance size: width x depth x height [in] 16.9 x 13.0 x 1.7 Appliance Yes Carton size: width x depth x height [in] 21.3 x 21.3 x 8.3 Serial cable Yes Form factor 1U Rack Mount Straight network cable Yes Cross network cable Yes Direct power to wall outlet Yes USB flash drive for recovery & installation Yes Quick start guide Yes HARDWARE Display Hardware crypto accelerator Cooling Power supply Yes Yes, built in Fan Single, internal 2x Barracuda L-shape rack mount bracket Wireless antenna 1 2 3 4x10/100 copper ports are covered by the faceplate on the right hand side Measured with large packets (MTU1500) Measured with TCP Yes Yes, for F301 only 23 INTERFACE BARRACUDA NG FIREWALL F380 ENVIRONMENTAL Copper Ethernet NICs 8x1 GbE USB 2.0 2 Serial / console Noise emission [db/A] 1 [RJ45] PERFORMANCE [AS OF FIRMWARE RELEASE 6.0.x] Operating temperature [°C] Firewall throughput [Gbps] ISO 11201:1995(E) ISO 7779:1999/ Amd.1: 2003 (E) 0 to +40 3.8 Storage temperature [°C] -20 to +70 VPN throughput [AES-128, NOHASH, Mbps] 750 Operating humidity [non-condensing] 5% to 95% VPN throughput [AES-128, MD5, Mbps] 640 MTBF [SYSTEM] VPN throughput [AES-128, SHA, Mbps] 620 MTBF [yrs.] VPN throughput [AES-256, MD5, Mbps] 600 CERTIFICATIONS & COMPLIANCE IPS throughput [Gbps] 1 1.1 CE emissions Yes CE electrical safety Yes FCC emissions Yes ROHS compliant Yes 1 Concurrent sessions New sessions/s 2 200,000 9,500 MEMORY RAM [GB] 4 MASS STORAGE Type SSD MTBF [hours] Power supply type Internal Solid State Power type [AC/DC] AC 80 Input rating [Volts] 100-240 1,200,000 SIZE, WEIGHT, DIMENSIONS Weight appliance [lbs] POWER & EFFICIENCY Input frequency [Hz] Auto sense Yes Wattage / max. power draw [W] 60 22 Max. power draw [Amps.] 1.6 Appliance size: width x depth x height [in] 16.8 x 14.5 x 1.7 Max. heat dissipation [W] 60 Carton size: width x depth x height [in] 22.0 x 22.4 x 7.5 Max. heat dissipation [BTU] 205 Form factor 1U Rack Mount Energy efficiency [average] > 83% Weight carton with appliance [lbs] 14.3 50-60 HARDWARE Display Hardware crypto accelerator Cooling Power supply PACKAGING CONTENT Yes Appliance Yes - Serial cable Yes Straight network cable Yes Cross network cable Yes Direct power to wall outlet Yes USB flash drive for recovery & installation Yes Quick start guide Yes Fan Single, internal 2x Barracuda L-shape rack mount bracket Barracuda rail kit 1 2 Measured with large packets (MTU1500) Measured with TCP Yes Optional Barracuda NG Firewall Size [GB] >5 24 BARRACUDA NG FIREWALL F400 Picture shows Barracuda NG Firewall F400 model F20. INTERFACE ENVIRONMENTAL Standard model 8x1 GbE Copper Noise emission [db/A] Model F20 8x1 GbE Copper + 4x1 GbE SFP Operating temperature [°C] USB 2.0 Serial / console 2 1 [RJ45] 0 to +40 Storage temperature [°C] -20 to +60 Operating humidity [non-condensing] 5% to 95% MTBF [SYSTEM] PERFORMANCE [AS OF FIRMWARE RELEASE 6.0.x] MTBF [yrs.] Firewall throughput [Gbps] 1 5.0 CERTIFICATIONS & COMPLIANCE VPN throughput [AES-128, NOHASH, Mbps] 960 CE emissions Yes VPN throughput [AES-128, MD5, Mbps] 790 CE electrical safety Yes VPN throughput [AES-128, SHA, Mbps] 740 FCC emissions Yes VPN throughput [AES-256, MD5, Mbps] 690 ROHS compliant Yes IPS throughput [Gbps] 1 1.5 POWER & EFFICIENCY >5 Concurrent sessions 310,000 Power supply type Internal New sessions/s 2 16,000 Power type [AC/DC] AC Input rating [Volts] 100-240 4 Input frequency [Hz] MEMORY Barracuda NG Firewall N/A RAM [GB] MASS STORAGE Type Size [GB] SSD MTBF [hours] Solid State 50-60 Auto sense Yes Wattage / max. power draw [W] 250 80 Max. power draw [Amps.] 0.6 1,200,000 Max. heat dissipation [W] 250 SIZE, WEIGHT, DIMENSIONS Max. heat dissipation [BTU] 1024 Weight appliance [lbs] 15.4 Energy efficiency [average] > 80% Weight carton with appliance [lbs] 22.5 PACKAGING CONTENT Appliance size: width x depth x height [in] 16.8 x 17.7 x 1.7 Appliance Yes Carton size: width x depth x height [in] 24.4 x 23.2 x 7.9 Serial cable Yes Form factor 1U Rack Mount Straight network cable Yes Cross network cable Yes Direct power to wall outlet Yes USB recovery & installation stick Yes Quick start guide Yes 2x Barracuda L-shape rack mount bracket Yes HARDWARE Display Hardware crypto accelerator Cooling Power supply 1 2 Measured with large packets (MTU1500) Measured with TCP Yes Fan Single, internal (standard) Dual hot swap, internal (SFP) Barracuda rail kit Optional 25 BARRACUDA NG FIREWALL F600 Picture shows Barracuda NG Firewall F600 model E20. INTERFACE 1 ENVIRONMENTAL Model C10 / C20 12x1 GbE Copper Noise emission [db/A] Model F10 / F20 8x1 GbE Copper + 4x1 GbE SFP Operating temperature [°C] Storage temperature [°C] -20 to +60 Model E20 8x1 GbE Copper + 2x10 GbE SFP+ Operating humidity [non-condensing] 5% to 95% USB 2.0 Serial / console 2 1 [RJ45] PERFORMANCE [AS OF FIRMWARE RELEASE 6.0.x] 2 Firewall throughput [Gbps] 3 16.3 VPN throughput [AES-128, NOHASH, Gbps] 2.3 VPN throughput [AES-128, MD5, Gbps] 1.7 VPN throughput [AES-128, SHA, Gbps] 1.7 VPN throughput [AES-256, MD5, Gbps] 1.4 IPS throughput [Gbps] 3 3.9 Concurrent sessions 110,000 MEMORY RAM [GB] 8 MASS STORAGE Type Size [GB] SSD MTBF [hours] SSD 80 or better 1,200,000 SIZE, WEIGHT, DIMENSIONS Weight appliance [lbs] 18.7 Weight carton with appliance [lbs] 26.5 Appliance size: width x depth x height [in] 16.8 x 17.7 x 1.7 Carton size: width x depth x height [in] 25.6 x 23.2 x 7.9 Form factor 1U Rack Mount HARDWARE Display Hardware crypto accelerator Cooling Power supply 1 1 2 3 4 Yes Fan Single, internal, Dual hot swap, internal (optional) Please consult section “Available F600 Sub-models” on page 34 Measured with 10GbE fibre ports. Measured with large packets (MTU1500) Measured with TCP 0 to +40 MTBF [SYSTEM] MTBF [yrs.] >5 CERTIFICATIONS & COMPLIANCE CE emissions Yes CE electrical safety Yes FCC emissions Yes ROHS compliant Yes POWER & EFFICIENCY Power supply type Internal Power type [AC/DC] AC Input rating [Volts] 100-240 Input frequency [Hz] 50-60 Auto sense Yes Wattage / max. power draw [W] 300 Max. power draw [Amps.] 5 Max. heat dissipation [W] 300 Max. heat dissipation [BTU] 1024 Energy efficiency [average] > 80% PACKAGING CONTENT Appliance Yes Serial cable Yes Straight network cable Yes Cross network cable Yes Direct power to wall outlet Yes USB recovery & installation stick Yes Quick start guide Yes 2x Barracuda L-shape rack mount bracket Yes Barracuda rail kit Yes Barracuda NG Firewall New sessions/s 4 2,000,000 N/A 26 BARRACUDA NG FIREWALL F800 Picture shows Barracuda NG Firewall F800 model CCF. INTERFACE 1 20x1 GbE Copper Noise emission [db/A] Model CCF 12x1 GbE Copper + 4x1 GbE SFP Operating temperature [°C] Storage temperature [°C] -20 to +60 Model CCE 12x1 GbE Copper + 2x10 GbE SFP+ Operating humidity [non-condensing] 5% to 95% USB 2.0 Serial / console Barracuda NG Firewall ENVIRONMENTAL Model CCC 2 N/A 0 to +40 MTBF [SYSTEM] MTBF [yrs.] >4 CERTIFICATIONS & COMPLIANCE 1 [RJ45] PERFORMANCE [AS OF FIRMWARE RELEASE 6.0.x] 2 CE emissions Yes Firewall throughput [Gbps] 3 19.6 CE electrical safety Yes VPN throughput [AES-128, NOHASH, Gbps] 6.8 FCC emissions Yes VPN throughput [AES-128, MD5, Gbps] 5.5 ROHS compliant Yes VPN throughput [AES-128, SHA, Gbps] 5.3 POWER & EFFICIENCY VPN throughput [AES-256, MD5, Gbps] 4.2 Power supply type Internal IPS throughput [Gbps] 3 4.8 Power type [AC/DC] AC Input rating [Volts] 100-240 Concurrent sessions New sessions/s 4 2,500,000 150,000 MEMORY RAM [GB] Auto sense 12 MASS STORAGE Type Size [GB] SSD MTBF [hours] Input frequency [Hz] Solid State Wattage / max. power draw [W] 50-60 Yes 2x 400 Max. power draw [Amps.] 5 Max. heat dissipation [W] 400 160 or better Max. heat dissipation [BTU] 1366 1,200,000 Energy efficiency [average] >80% SIZE, WEIGHT, DIMENSIONS PACKAGING CONTENT Weight appliance [lbs] 28.7 Appliance Yes Weight carton with appliance [lbs] 34.2 Serial cable Yes Appliance size: width x depth x height [in] 17.4 x 20.4 x 1.7 Straight network cable Yes Carton size: width x depth x height [in] 26.2 x 23.0 x 8.9 Cross network cable Yes Form factor 1U Rack Mount Direct power to wall outlet Yes USB flash drive for recovery & installation Yes HARDWARE Display Yes Quick start guide Yes Hardware crypto accelerator Yes 2x Barracuda L-shape rack mount bracket Yes Cooling Fan Barracuda rail kit Yes Power Supply Dual hot swap, internal 1 2 3 4 Please consult section “Available F800 Sub-models” on page 35 Measured with 10GbE fibre ports. Measured with large packets (MTU1500) Measured with TCP 27 BARRACUDA NG FIREWALL F900 Picture shows Barracuda NG Firewall F900 model CFE. INTERFACE 1 ENVIRONMENTAL Model CCC 24x1 GbE Copper Noise emission [db/A] Model CCE 16x1 GbE Copper 4x10 GbE SFP Operating temperature [°C] Storage temperature [°C] -20 to +60 Operating humidity [non-condensing] 5% to 95% Model CFE 8x1 GbE Copper 8x1 GbE SFP 4x10 GbE SFP+ USB 2.0 Serial / console 0 to +40 MTBF [SYSTEM] MTBF [yrs.] >4 CERTIFICATIONS & COMPLIANCE 2 1 [RJ45] PERFORMANCE [AS OF FIRMWARE RELEASE 6.0.x] N/A 2 CE emissions Yes Yes 22.2 FCC emissions Yes VPN throughput [AES-128, NOHASH, Gbps] 7.6 ROHS compliant Yes VPN throughput [AES-128, MD5, Gbps] 6.6 POWER & EFFICIENCY VPN throughput [AES-128, SHA, Gbps] 6.4 VPN throughput [AES-256, MD5, Gbps] 5.6 IPS throughput [Gbps] 3 Concurrent sessions New sessions/s 4 Power supply type Internal, dual hot swap 5.4 Power type [AC/DC] AC 2,800,000 Input rating [Volts] 100-240 160,000 MEMORY RAM [GB] 12 MASS STORAGE Type Size [GB] SSD MTBF [hours] Solid State 80 (system) + 300 (logs, cache) Weight carton with appliance [lbs] 50-60 Auto sense Yes Wattage / max. power draw [W] 500 Max. power draw [Amps.] 5 Max. heat dissipation [W] 300 Max. heat dissipation [BTU] 1024 Energy efficiency [average] >80% PACKAGING CONTENT 1,200,000 SIZE, WEIGHT, DIMENSIONS Weight appliance [lbs] Input frequency [Hz] Appliance Yes 39.7 Serial cable Yes 48.5 Straight network cable Yes Appliance size: width x depth x height [in] 17.4 x 26.0 x 3.5 Cross network cable Yes Carton size: width x depth x height [in] 23.2 x 34.3 x 11.4 Direct power to wall outlet Yes Form factor 2U Rack Mount USB flash drive for recovery & installation Yes HARDWARE Quick start guide Yes Yes 2x Barracuda L-shape rack mount bracket Yes Hardware crypto accelerator Yes Barracuda rail kit Yes Cooling Fans Display Power supply Dual hot swap, internal 1 2 3 4 Please consult section “Available F900 Sub-models” on page 35 Measured with 10GbE fibre ports. Measured with large packets (MTU1500) Measured with TCP Barracuda NG Firewall CE electrical safety Firewall throughput [Gbps] 3 28 BARRACUDA NG FIREWALL F1000 Picture shows Barracuda NG Firewall F1000 model CFE. Barracuda NG Firewall F1000 IPMI CONSOLE USB USB USB USB MGMT MGMT CONSOLE Barracuda NG Firewall F1000 INTERFACE IPMI ENVIRONMENTAL 1 16x1 GbE Copper 4x10 GbE SFP+ Noise emission [db/A] Model CE2 32x1 GbE Copper 8x10 GbE SFP+ Storage temperature [°C] -20 to +75 Operating humidity [non-condensing] 10% to 85% Model CFE 16x1 GbE Copper 16x1 GbE SFP 8x10 GbE SFP+ Model CE0 USB 2.0 2 0 to +40 MTBF [SYSTEM] MTBF [yrs.] >4 CERTIFICATIONS & COMPLIANCE CE emissions Yes IPMI 1 [RJ45] CE electrical safety Yes Serial / console 1 [RJ45] FCC emissions Yes ROHS compliant Yes PERFORMANCE [AS OF FIRMWARE RELEASE 6.0.x] Firewall throughput [Gbps] 3 Barracuda NG Firewall Operating temperature [°C] N/A 10 VPN throughput [AES-128, MD5, Gbps] 8.6 VPN throughput [AES-128, SHA, Gbps] 8.3 VPN throughput [AES-256, MD5, Gbps] IPS throughput [Gbps] 3 New sessions/s 4 Size [GB] SSD MTBF [hours] Internal, dual hot swap AC 8.6 Input rating [Volts] 100-240 10 Input frequency [Hz] 4,000,000 200,000 12 MASS STORAGE Type Power supply type Power type [AC/DC] MEMORY RAM [GB] POWER & EFFICIENCY 40 VPN throughput [AES-128, NOHASH, Gbps] Concurrent sessions 2 Solid State Auto sense Yes Wattage / max. power draw [W] 810 Max. power draw [Amps.] 6.8 Max. heat dissipation [W] 680.4 Max. heat dissipation [BTU] 2321.6 Energy efficiency [average] > 86% PACKAGING CONTENT 600 1,200,000 SIZE, WEIGHT, DIMENSIONS 50-60 Appliance Yes Serial cable Yes Weight appliance [lbs] 44.1 Straight network cable Yes Weight carton with appliance [lbs] 57.3 Cross network cable Yes Appliance size: width x depth x height [in] 16.9 x 24.6 x 3.5 Direct power to wall outlet Yes Carton size: width x depth x height [in] 23.2 x 34.3 x 11.4 USB flash drive for recovery & installation Yes Form factor 2U Rack Mount Quick start guide Yes 2x Barracuda L-shape rack mount bracket Yes Barracuda rail kit Yes HARDWARE Display Yes Hardware crypto accelerator Yes Cooling Fans, hot swap Power supply Dual hot swap, internal 1 2 3 4 Please consult section “Available F1000 Sub-models” on page 36 Measured with 10GbE fibre ports. Measured with large packets (MTU1500) Measured with TCP 29 PORT1 PORT2 PORT1 PORT2 INTERFACE Copper Ethernet NICs USB 2.0 Serial / console CERTIFICATIONS & COMPLIANCE 2x1 GbE 4 1 [DB9] / 1 [RJ45] MEMORY RAM [GB] 2 MASS STORAGE Type Size [GB] BARRACUDA NG CONTROL CENTER C400 CE emissions Yes CE electrical safety Yes FCC emissions Yes ROHS compliant Yes POWER & EFFICIENCY Power supply type Single, internal HDD Power type [AC/DC] AC 2x 250 or better Input rating [Volts] 100-240 SIZE, WEIGHT, DIMENSIONS Input frequency [Hz] 47-63 Weight appliance [lbs] 13.1 Auto sense Yes Weight carton with appliance [lbs] 16.4 Max. power draw [Amps.] 1.8 16.0 x 16.7 x 1.7 PACKAGING CONTENT Carton size: width x depth x height [in] 19.0 x 22.2 x 7.0 Appliance Yes Direct power to wall outlet Yes USB flash drive for recovery & installation Yes Quick start guide Yes 2x Barracuda L-shape rack mount bracket Yes Form factor 1U Full Size ENVIRONMENTAL Noise emission [db/A] Operating temperature [°C] N/A 0 to +35 Storage temperature [°C] -20 to +70 Operating humidity [non condensing] 5% to 95% Barracuda NG Firewall Appliance size: width x depth x height [in] 30 BARRACUDA NG CONTROL CENTER C610 INTERFACE Copper ethernet NICs USB 2.0 Serial CERTIFICATIONS & COMPLIANCE 2x1 GbE 2 1 [DB9] MEMORY RAM [GB] 4 MASS STORAGE Type Size [GB] Redundant Disk Array (RAID) Yes CE electrical safety Yes FCC emissions Yes ROHS compliant Yes POWER & EFFICIENCY Power supply type Dual, internal HDD Power type [AC/DC] AC 4x 500 or better Input rating [Volts] 100-240 RAID 5 SIZE, WEIGHT, DIMENSIONS Barracuda NG Firewall CE emissions Input frequency [Hz] 47-63 Auto sense Yes 4.1 Weight appliance [lbs] 39.7 Max. power draw [Amps.] Weight carton with appliance [lbs] 62.8 PACKAGING CONTENT Appliance size: width x depth x height [in] 17.4 x 25.5 x 3.5 Appliance Yes Carton size: width x depth x height [in] 26.8 x 34.3 x 11.3 Direct power to wall outlet Yes Form factor 2U Rack Mount USB flash drive for recovery & installation Yes Quick start guide Yes 2 x Barracuda L-shape rack mount bracket Yes Barracuda Rail kit Yes ENVIRONMENTAL Noise emission [db/A] Operating temperature [°C] N/A 0 to +40 Storage temperature [°C] -20 to +70 Operating humidity [non condensing] 5% to 95% 31 F10 F100 F101 F200 F201 F280 F300 F301 F380 F400 F600 F800 F900 F1000 3G modem Additional Hardware Options ¡ ¡ ¡ ¡ ¡ ¡ ¡ ¡ ¡ ¡ ¡ ¡ ¡ ¡ Built-in WiFi option l l l Network Module M801 l l Network Module M802 ¡ Network Module M804 ¡ Network Module M805 ¡ ¡ Network Module M1001 l Network Module M1002 ¡ Network Module M1003 l 19” rack mount shelf kit ¡ ¡ ¡ L-shape rackmount bracket (2x) ¡ ¡ Rail kit l l l l l l l ¡ ¡ l l l l l included BARRACUDA 3G MODEM [USB] The Barracuda 3G modem provides support for wireless third generation broadband communication using 3G/UMTS/HSDPA/ HSUPA technologies thus providing bandwidths of up to 7.2 Mbps. Especially for remote sites the Barracuda 3G modem is a cost effective, rapidly deployable and ultra-reliable WAN backup solution which can protect businesses and organizations against outages caused by accidental cable or fiber link cuts during construction, moves or maintenance work. Who can benefit from the Barracuda 3G modem? • Enterprises looking for a cost effective secondary link in order to quickly increase total overall bandwidth and to reduce traffic volume on the primary link • Enterprises relying on high quality WAN backup and WAN connectivity for business critical traffic • Branch offices and remote sites looking for a cost effective alternative to earth bound uplinks • Branch offices and remote sites looking to bridge the gap until cable connections become available • Branch offices and remote sites residing in areas without a good selection of affordable or reliable Internet uplinks • Construction sites, retail, rapid deployments and portable businesses requiring quick access to Internet connectivity Note: Barracuda Networks cannot guarantee signal reception. In case your server rooms are located in a basement or in a place with insufficient signal reception make sure that the signal quality is sufficient, especially prior to purchasing large quantities. The SIM card is not included and has to be obtained independently through a mobile phone provider. Barracuda NG Firewall ¡ optional l 32 BUILT-IN WI-FI OPTION The Barracuda NG Firewall appliances F101, F201, F280, and F301 offer built-in Wi-Fi. ITEM SPECIFICATION Standards IEEE 802.11b/g/n, CSMA/CA with ACK Frequency 2.4-2.4835 GHz 11n: Up to 300Mbps Signal Rate 11g: Up to 54Mbps 11b: Up to 11Mbps EIRP 20 dBm (MAX) 130Mbps: -68 dBm @10% PER 108 Mbps: -68 dBm @10% PER Radio receive sensitivity 54 Mbps: -68 dBm @10% PER 11 Mbps: -85 dBm @8% PER 6 Mbps: -88 dBm @10% PER 1 Mbps: -90 dBm @8% PER 64/128 bits WEP Wireless security WPA/WPA2 WPA-PSK/WPA2-PSK (TKIP/AES) Supported Barracuda Network Module Combinations (firmware release 6.0.x and newer) Barracuda NG Firewall Note: Transceivers have to be bought separately and are not included in the Network Modules M802-M805 and M1002-M1003. Note: All Barracuda Network Modules (M801-M805 and M1001-M1003) are covered by Instant Replacement and Warranty Extension subscriptions of the appliance at no extra charge. BARRACUDA NETWORK MODULE M801 Optional network module providing 8x1 GbE RJ45 copper ports. Available for Barracuda NG Firewall models F800 and F900. BARRACUDA NETWORK MODULE M802 Optional network module providing 4x1 GbE fiber slots for standard SFP type transceivers (compatible with SR and LR transceivers). Available for Barracuda NG Firewall models F800 for self-installed field upgrades. M801 M802 BARRACUDA NETWORK MODULE M804 Optional network module providing 8x1 GbE fiber ports for standard SFP type transceivers (compatible with SR and LR transceivers). Available for Barracuda NG Firewall model F900. M804 BARRACUDA NETWORK MODULE M805 Optional network module providing 4x10 GbE fiber ports for standard SFP+ type transceivers (compatible with SR and LR transceivers). Available for Barracuda NG Firewall models F800 and F900. M805 33 BARRACUDA NETWORK MODULE M1001 Optional network module providing 16x1 GbE RJ45 copper ports. Available for Barracuda NG Firewall model F1000. M1001 BARRACUDA NETWORK MODULE M1002 Optional network module providing 16x1 GbE fiber ports for standard SFP type transceivers (compatible with SR and LR transceivers). Available for Barracuda NG Firewall model F1000. M1002 BARRACUDA NETWORK MODULE M1003 Optional network module providing 4x10 GbE fiber ports for standard SFP+ type transceivers (compatible with SR and LR transceivers). Available for Barracuda NG Firewall model F1000. M1003 BARRACUDA 19” RACK MOUNT SHELF KIT The Barracuda Rack Mount Shelf Kit is a field upgrade to deploy Barracuda NG Firewall models F100, F101, F200, and F201 into a 19inch rack environment. 1 BARRACUDA L-SHAPE RACK MOUNT BRACKET The L-shape rack mount bracket enables Barracuda Firewall F280 to be mounted in a 1U Standard 19” Rack slot. The F400 standard model is always shipped with a total of 8 RJ45 network ports and single power supply. Other F400 model types provide different port and power supply combinations. Please see list below. Note: Network ports are built-in and not replaceable in the field. Spare parts for redundant power supply can be ordered separately. F400 MODEL TYPE ORDER NO. EMEA / ORDER NO. INTERNATIONAL NORTH AMERICA BNGIF400a BNGF400a BNGIF400a.F20 BNGF400a.F20 Rear Front Barracuda NG Firewall F400 standard model (8 RJ45 network ports and single power supply) Rear Front Barracuda NG Firewall F400 model F20 (8 RJ45 network ports, 4x1 GbE fiber ports, and dual power supply) The rack mount shelf kit will require 2 1U slots in a rack in height as the F100/F200 units themselves are larger than 1U. 1 Barracuda NG Firewall AVAILABLE F400 SUB-MODELS 34 AVAILABLE F600 SUB-MODELS The F600 standard model C10 is always shipped with a total of 12 RJ45 network ports and single power supply. Other F600 model types provide different port and power supply combinations. Please see list below. Note: Network ports are built-in and not replaceable in the field. Spare parts for redundant power supply can be ordered separately. F600 MODEL TYPE ORDER NO. EMEA / ORDER NO. INTERNATIONAL NORTH AMERICA BNGIF600a.C10 BNGF600a.C10 BNGIF600a.C20 BNGF600a.C20 BNGIF600a.F10 BNGF600a.F10 BNGIF600a.F20 BNGF600a.F20 BNGIF600a.E20 BNGF600a.E20 Rear Front Barracuda NG Firewall F600 model C10 (12 RJ45 network ports and single power supply) Rear Front Barracuda NG Firewall F600 model F10 (8 RJ45 + 4 SFP 1 GbE network ports and single power supply) Rear Front Barracuda NG Firewall F600 model F20 (8 RJ45 + 4 SFP 1 GbE network ports and dual power supply) Front Barracuda NG Firewall F600 model E20 (8 RJ45 + 2 SFP+ 10 GbE network ports and dual power supply) Rear Barracuda NG Firewall Rear Front Barracuda NG Firewall F600 model C20 (12 RJ45 network ports and dual power supply) 35 The F800 standard model CCC is always shipped with a total of 20x1 GbE network ports and dual power supply. Other F800 model types provide different port combinations. Please see list below. AVAILABLE F800 SUB-MODELS Note: Network ports are built-in and not replaceable in the field. Spare parts for redundant power supply can be ordered separately. ORDER NO. EMEA / ORDER NO. INTERNATIONAL NORTH AMERICA F800 MODEL TYPE Barracuda NG Firewall F800 model CCC (20x1 GbE network ports and dual power supply) BNGF800a.CCC BNGIF800a.CCF BNGF800a.CCF BNGIF800a.CCE BNGF800a.CCE Front BNGIF800a.CCC Front Barracuda NG Firewall F800 model CCF (12x1 GbE copper + 4x1 GbE SFP (fibre) network ports and dual power supply) Front Barracuda NG Firewall F800 model CCE (20x1 GbE + 2x10 GbE SFP+ (fibre) network ports and dual power supply) AVAILABLE F900 SUB-MODELS Other F900 model types provide different port combinations. Please see list below. Note: Network ports are built-in and not replaceable in the field. Spare parts for redundant power supply can be ordered separately. F900 MODEL TYPE ORDER NO. EMEA / ORDER NO. INTERNATIONAL NORTH AMERICA Front Barracuda NG Firewall F900 model CCC (24x1 GbE copper network ports) BNGIF900a.CCC BNGF900a.CCC BNGIF900a.CCE BNGF900a.CCE BNGIF900a.CFE BNGF900a.CFE Front Barracuda NG Firewall F900 model CCE (16x1 GbE copper + 4x1 GbE SFP (fibre) network ports) Front Barracuda NG Firewall F900 model CFE (8x1 GbE + 8x1 GbE SFP (fibre) + 4x10 GbE SFP+ (fibre) network ports) Barracuda NG Firewall The F900 standard model CCC is always shipped with a total of 24x1 GbE network ports and dual power supply. 36 AVAILABLE F1000 SUB-MODELS The F1000 standard model CE0 is always shipped with a total of 16 RJ45 network ports and dual power supply. Fans and power supply blocks are hot swappable. Other F1000 model types provide different port combinations. Please see list below. Note: Network ports are built-in and not replaceable in the field. Spare parts for redundant power supply can be ordered separately. F1000 MODEL TYPE ORDER NO. EMEA / ORDER NO. INTERNATIONAL NORTH AMERICA Front Barracuda NG Firewall F1000 model CE0 (24x1 GbE copper network ports) BNGIF1000a.CE0 BNGF1000a.CE0 BNGIF1000a.CE2 BNGF1000a.CE2 BNGIF1000a.CFE BNGF1000a.CFE Barracuda NG Firewall F1000 IPMI CONSOLE USB USB MGMT Front Barracuda NG Firewall F1000 model CE2 (32x1 GbE copper + 8x1 GbE SFP+ (fibre) network ports) Barracuda NG Firewall F1000 IPMI CONSOLE USB MGMT Barracuda NG Firewall F1000 model CFE (16x1 GbE + 16x1 GbE SFP (fibre) + 8x10 GbE SFP+ (fibre) network ports) Front Barracuda NG Firewall USB Barracuda NG Firewall F1000 IPMI CONSOLE USB USB MGMT 37 Features & Capabilities BARRACUDA NG FIREWALL F10 F100 F101 F200 F201 F280 F300 F301 F380 to F1000 VIRTUAL APPLIANCES Stateful packet forwarding (per rule) l l l l l l l Transparent proxy (TCP; per rule) l l l l l l l Inline graphical packet analyser l l l l l l l NAT (src, dst, nets), PAT l l l l l l l Policy-based NAT (per rule) l l l l l l l Protocol support (IPv4, IPv6 1, ARP) l l l l l l l MODEL FIREWALL - - - l - l l Object oriented rule set l l l l l l l Virtual rule sets l l l l l l l Virtual rule test environment l l l l l l l Redirection to local application l l l l l l l Realtime connection status l l l l l l l Historical access caches l l l l l l l Event triggered notification l l l l l l l Load balancing for protected servers l l l l l l l Multipath load balancing l l l l l l l Firewall-to-firewall compression (stream & packet compression) l l l l l l l Dynamic rules with timer triggered deactivation ( per rule) l l l l l l l Bridging mode / routing mode (mixed) l l l l l l l Virtual IP (proxyARP) support l l l l l l l Transparent IP to user mapping l l l l l l l User authentication (x.509, Microsoft® NTLM, RADIUS, RSA SecurID, LDAP/LDAPS, Microsoft® Active Directory®, TACACS+, local) l l l l l l l RPC protocol support (ONC-RPC, DCE-RPC) l l l l l l l VoIP support (H.323, SIP, SCCP (skinny)) l l l l l l l DHCP relaying with packet loop protection and configurable agent-ID policy l l l l l l l Standby mode Active-Active (with external load balancer only) and Active-Passive Network notification on failover l l l l l l l Key-based authentication l l l l l l l Encrypted HA communication l l l l l l l Provider/link failover l l l l l l l Transparent failover without session loss l l l l l l l Deep Packet Inspection l l l l l l l Application Behavior Analysis l l l l l l l More than 1,400 applications and protocols supported (Skype, BitTorrent, etc.) l l l l l l l Social Media Application Support (Facebook, Google+, etc.) l l l l l l l Media Streaming Application Support (YouTube, Netflix, etc.) l l l l l l l APPLICATION CONTROL 1 IPv6 firewall forwarding traffic, IPS, and Application Control. Barracuda NG Firewall Gigabit performance 38 F10 F100 F101 F200 F201 F280 F300 F301 F380 to F1000 VIRTUAL APPLIANCES Proxy and Anonymizer Detection (Hide Me, Cyberghost, etc.) l l l l l l l Application Objects based on Category, Risk, Properties and Popularity l l l l l l l Predefined Categories such as Business, Conferencing, Instant Messaging, Media Streaming, etc. l l l l l l l Inspection of SSL encrypted traffic l l l l l l l SSL Lite Mode l l l l l l l Creation of Customized Application l l l l l l l Deep Application Context l l l l l l l Application Based Link Selection l l l l l l l Bandwidth and QoS Assignment l l l l l l l Application Logging l l l l l l l Application Blocking l l l l l l l Application Monitor and Drill-Down Function l l l l l l l Reporting l l l l l l l Inline Intrusion Prevention l l l l l l l Generic pattern filter l l l l l l l Active ARP handling l l l l l l l SYN / DoS / DDoS attack protection l l l l l l l Reverse routing path check l l l l l l l MODEL APPLICATION CONTROL (CONTINUED) Barracuda NG Firewall INTRUSION PREVENTION SYSTEM l, by size and rate limit ICMP flood ping protection Malformed packet check l l l l l l l TCP split handshake protection l l l l l l l TCP stream segmentation check l l l l l l l URL obfuscation check l l l l l l l FTP evasion check l l l l l l l RPC defragmentation check l l l l l l l HTML decoding - - - l - l l HTML decompression - - - l - l l SMB & NetBios Evasion Protection l l l l l l l Regular online pattern updates l l l l l l l IPS exception (whitelisting) l l l l l l l IPS exceptions based on Source / Destination l l l l l l l Port & Port Range l l l l l l l Signature / CVE l l l l l l l Single-Pass Mode - l l l l l l Proxy Mode - l l l l l l Configurable archive recursion depth - l l l l l l Quarantine functionality for proxy - l l l l l l Configurable unknown archive policy - l l l l l l Configurable maximum archive size - l l l l l l Archiver package support - l l l l l l Office file-types support - l l l l l l BARRACUDA NG MALWARE PROTECTION 39 F10 F100 F101 F200 F201 F280 F300 F301 F380 to F1000 VIRTUAL APPLIANCES Proactive detection of new threats - l l l l l l Advanced heuristics detection techniques - l l l l l l Number of signatures - Hundreds of thousands Frequency of signature updates - Multiple updates per day Dynamic, on-demand analysis of malware programs (sandbox) - MODEL BARRACUDA NG MALWARE PROTECTION - l l l l l BARRACUDA ADVANCED THREAT DETECTION Supported File Types Microsoft Office Documents - - l l l l l Adobe PDF Documents - - l l l l l Microsoft Executables (exe, msi, dll) - - l l l l l Android APK Installer - - l l l l l Dynamic analysis of documents with embedded exploits (PDF, Office, etc.) - - l l l l l Detailed forensics for both, malware binaries and web threats (exploits) - - l l l l l High resolution malware analysis (monitoring, execution from the inside) - - l l l l l Support for multiple operating systems (Windows, Android, etc.) - - l l l l l Flexible malware analysis in the cloud - - l l l l l HA capable with transparent session failover l l l l l l l GbE ethernet support l l l l l l l n/a ROUTING, NETWORKING 4 4 4 4 8 802.1q VLAN support l l l l l l l xDSL support (PPPoE, PPTP (multi-link)) l l l l l l l 3G/UMTS/HSDPA/HSUPA Barracuda 3G modem - DHCP client support l l l l l l l ISDN support (EuroISDN (syncppp, rawip)) - l l l l - - Link monitoring (DHCP, 3G/UMTS, xDSL, ISDN) l l l l l l l Policy routing support l l l l l l l Ethernet channel bonding l l l l l l l Multiple networks on interface, IP aliases l l l l l l l Multiple provider / WAN link support l l l l l l l Configurable MTU size (per route) l l l l l l l Jumbo Frames (up to 8,000 bytes) l l l l l l l IPinIP and GRE tunnels l l l l l l l PPTP l l l l l l l BGP l l l l l l l Dynamic VPN routing l l l l l l l Integrated OSPF/RIP router l l l l l l l Maximum overall bandwidth per interface l l l l l l l On-the-fly reprioritization via via firewall status GUI l l l l l l l TRAFFIC MANAGEMENT Barracuda NG Firewall Max number of physical interfaces F380: 8 F400: 12 F600: 12 F800: 20 F900: 24 F1000: 40 40 MODEL F10 F100 F101 F200 F201 F280 F300 F301 F380 to F1000 VIRTUAL APPLIANCES l l l l l l l TRAFFIC MANAGEMENT (CONTINUED) Ingress shaping per interface CENTRAL USER AUTHENTICATION Supported services VPN, FW, HTTP Proxy VPN, FW, HTTP/FTP/SSH Proxy Authentication methods MS NTLM, MS CHAP, RADIUS, RSA SecurID, LDAP/LDAPS, MS Active Directory, TACACS+, local Barracuda NG Firewall VPN Encryption support (AES-128/256, 3DES, DES, Null) l l l l l l Cryptohardware acceleration l l l - l l Private CA (up to 4,096 bit RSA) l l l l l l l External PKI support l l l l l l l x.509v3 policy extensions (Fully recognized) l l l l l l l Certificate revocation (OCSP, CRL) l l l l l l l Site-to-site VPN with traffic intelligence l l l l l l l 2 3 l - WAN traffic compression via data deduplication - - l l l l l Star (hub and spoke) VPN network topology l l l l l l l Client VPN l l l l l l l Microsoft® domain logon (Pre-logon) l l l l l l l Strong user authentication l l l l l l l Replay protection l l l l l l l NAT traversal l l l l l l l HTTPS and SOCKS proxy compatible l l l l l l l Redundant VPN gateways l l l l l l l Native IPsec for third-party connectivity l l l l l l l PPTP/L2TP (IPsec; client VPN only) l l l l l l l OSPF via VPN l l l l l l l Central management l l l l l l l Local management l l l l l l l Comprehensive GUI-based configuration mgmt l l l l l l l Command-line interface (CLI) available l l l l l l l SSH-based access l l l l l l l Multiple administrators l l l l l l l Role-based administrators l l l l l l l SYSTEM MANAGEMENT Real-time accounting and visualization - - l l l l l Easy roll-out and recovery l l l l l l l USB installation and recovery l l l l l l l Full life-cycle management l l l l l l l In-band management l l l l l l l Dedicated management interface l l l l l l l Serial interfaces l l l l l l l Central management interface l l l l l l l All management via VPN tunnel l l l l l l l System health, activity monitoring l l l l l l l Monitoring of network environment l l l l l l l Dynamic routing table updates l l l l l l l Firewall connection monitoring l l l l l l l LOGGING/MONITORING/ACCOUNTING 2 3 VIA Padlock F800 and F900: Cavium 41 F10 F100 F101 MODEL F200 F201 F280 F300 F301 F380 to F1000 VIRTUAL APPLIANCES l l l l LOGGING/MONITORING/ACCOUNTING (CONTINUED) l l l Real-time accounting and reporting - - - l l l l Syslog streaming (fully GUI configurable) l l l l l l l SNMP queries l l l l l l l SMS control l l l l l l l NTP4 time server and client l l l l l l l l l l l l l l l l l l l l l - - l l l l l Human readable log files Active event notification UPD/Email/SNMP trap ADDITIONAL FUNCTIONS DNS Multi-domain support DNS operation types DNS doctoring Master, slave, forwarder, cacher SSH-GATEWAY Termination of SSHv2 terminal access sessions (not supported: remote execution/secure copy/secure FTP) Central user authentication MSNT, MSAD, LDAP, RADIUS, RSA-ACE, TACACS+ User specific / group specific restrictions - - l l l l l Public key authentication on target system - - l l l l l Session / activity tracing - - l l l l l Customizable login greeting text - - l l l l l DHCP server l l l l l l l DHCP relay l l l l l l l Lease DB visualization & management l l l l l l l Multi-homing, multi-netting l l l l l l l Class-based filtering l l l l l l l Dynamic DNS support l l l l l l l Restrict active/passive data transfer - - l l l l l Restrict non-RFC FTP commands - - l l l l l Full integration with Barracuda NG Malware Protection - - l l l l l Buffer overflow protection - - l l l l l DHCP Central user authentication MSNT, MSAD, LDAP, RADIUS, RSA-ACE, TACACS+ Customizable login greeting text - - l l l l l User specific / group specific restrictions - - l l l l l Destination redirection / specific restrictions - - l l l l l Time restrictions - - l l l l l Deny file up/download - - l l l l l Deny file/directory modifications - - l l l l l Deny specific file extensions - - l l l l l Activity visualization & reporting - - l l l l l Supported protocols - - Multi-domain support - - l l l l l Configurable relaying policy per domain - - l l l l l MAIL SECURITY & SPAM FILTER SMTP, POP3 Barracuda NG Firewall FTP GATEWAY 42 MODEL F10 F100 F101 F200 F201 F280 F300 F301 F380 to F1000 VIRTUAL APPLIANCES Barracuda NG Firewall MAIL SECURITY & SPAM FILTER (CONTINUED) DSN generation - - l l l l l Spool-queue visualization & management - - l l l l l Visualization of mail activity backlog - - l l l l l Spool-queue synchronization for HA - - l l l l l Restrictable mail reception - - l l l l l Configurable maximum mail data size - - l l l l l Configurable maximum number of mail recipients - - l l l l l Support for external virus scanning - - l l l l l Activity visualization & reporting - - l l l l l Mail delivery - - Accept policies - - l l l l l Recipient database - - l l l l l Configurable block criteria (host, subject, sender, recipient) - - l l l l l Attachment and/or header stripping - - l l l l l Subject rewriting - - l l l l l Cloning - - l l l l l Grey listing - - l l l l l Supports a scripting language for configuration - - l l l l l Subject modification on spam - - l l l l l White lists / black lists - - l l l l l Online tests - - Auto learning / training - - l l l l l Customizable rules for spam rating - - l l l l l Supports cache hierarchies (parenting, neighboring) l4 l l l l l l Cache hierarchies supporting protocols (ICP, HTCP, CARP, Cache Digest, WCCP) l4 l l l l l l Proxying and caching (HTTP, FTP, and others) l4 l l l l l l Proxying for SSL (no inspection) l4 l l l l l l Transparent caching l 4 l l l l l l HTTP server acceleration l4 l l l l l l Caching of DNS lookups l 4 l l l l l l Central user authentication (Native NTLM, RADIUS, l4 l l l l l l Support for external virus scanning (ICAP) l4 l l l l l l Access control mechanisms (Extensive ACL) l4 l l l l l l Use proxy authentication for firewall l 4 l l l l l l Support of external redirector programs l4 l l l l l l Upload blocking (POST) l l l l l l l l l l l l l Explicit, MX DCC, RBL WEB PROXY RSA ACE, LDAP, MS Active Directory, TACACS+) 4 BARRACUDA WEB FILTER Black lists/White lists (per rule) - Filter categories - Temporal constraints - l l l l l l User specific / group specific restrictions - l l l l l l Online category database - l l l l l l 4 95 While technically feasible to use the web proxy on the F10 hardware it is recommended to only to use it to forward web traffic to the Barracuda Web Security Service in the cloud. 43 F10 F100 F101 F200 F201 F300 F301 F280 MODEL F380 to F1000 VIRTUAL APPLIANCES BARRACUDA WEB FILTER (CONTINUED) Local update interval - N/A Online update interval - Customizable block pages - l l l l l l Black lists / White lists (per rule) - l l l l l l Filter categories - Number of entries - Temporal constraints - l l l l l l User specific / group specific restrictions - l l l l l l Category database - Local update interval - hourly Online update interval - continuously Customizable block pages - l l continuously BARRACUDA NG WEB FILTER 69 ~ 100 million Local or online l l l l Barracuda NG Firewall 44 BARRACUDA VPN & NETWORK ACCESS CLIENTS BARRACUDA NG NAC SUBSCRIPTION BARRACUDA VPN CLIENT BARRACUDA NETWORK ACCESS CLIENT BARRACUDA SSL VPN TRANSPARENT CLIENT Integrated VPN client l l l Integrated health agent - l l Managed personal firewall - l l Full NAC policy support - l l Customizable user interface l l - Low power consumption network stack l l - Microsoft Windows XP (32-bit only) l l l Microsoft Windows Vista (32-bit, 64-bit) l l l Microsoft Windows 7 (32-bit, 64-bit) l l l Microsoft Windows 8 (32-bit, 64-bit) l l l Linux (kernel 2.4, kernel 2.6) l - - Mac OS X (10.6.x, 10.7.x, 10.8.x), Mac OS XI l - - Central management of VPN configuration l l l VPN diagnostic log l l l VPN system diagnostics report l l l VPN status monitoring l l l Attack access cache l l l Packet log (capture) l l l VPN groups l l l Silent client setup l l l l l l Microsoft® Certificate Management (Crypto API) l1 l l Microsoft® Active Directory l1 l l l l l RADIUS l l l MSNT 2 l1 l l RSAACE 2 l l l External X509 certificates l l l SMS PASSCODE 2 l l l RSA tokens 2 l l l Smart cards 3 l1 l l Microsoft domain logon support (prelogon) l1 l - Dynamic adapter object handling l l l Dynamic user object handling l l - RPC handling l l l Multiple rule sets support l l - Client side policy enforcement l l l Application control l l - Adapter control l l l User context enforcement l l l NetBIOS protection l l l SOFTWARE FEATURES ARCHITECTURE SUPPORTED OS VARIANTS Barracuda NG Firewall MANAGEMENT Password protection of settings 1, 4 AUTHENTICATION SUPPORT 2 LDAP 2 2 PERSONAL FIREWALL CAPABILITIES 1 2 Only for Microsoft operating systems Queried by Barracuda NG Firewall VPN server on behalf of client 3 4 For manufacturer with Microsoft Crypto Service Provider. Also prevents changes to client settings by users with administrator rights. 45 BARRACUDA VPN CLIENT BARRACUDA NETWORK ACCESS CLIENT BARRACUDA SSL VPN TRANSPARENT CLIENT DoS attack protection l l l Executable scripts l l l ID-based policies l l l Support for ID-based exemptions (health condition, software update) - l l Date and time conditions l l l Access type (internal and external category support) - l l Separate machine policies - l - Separate quarantine policies - l l Machine properties - l l User properties - l l Personal firewall active - l l Antivirus (AV) product installed (by vendor) 5 - l l AV active SOFTWARE FEATURES BARRACUDA NG NAC SUBSCRIPTION PERSONAL FIREWALL CAPABILITIES (CONTINUED) POLICY MATCHING CAPABILITIES - l l AV real-time protection active 5 - l l Last AV scan time 5 - l l Enforce overdue AV scan 5 - l l AV engine version - l l - l l - l l 5 5 AV pattern version 5 AV pattern max age 5 l l - l l AS active - l l AS real-time protection active5 - l l Last AS scan time 5 - l l Enforce overdue AS scan 5 - l l AS engine version 5 - l l AS pattern version 5 - l l - l l - l l Personal firewall rule set - l l Registry entries - l - Welcome message, welcome picture - l l Corporate-ID support - l l ID-based exemption from enforced client updates - l l Gateway network access roles - l l Raw ESP l l l UDP encapsulation l l l TCP encapsulation l l l Hybrid encapsulation l l l l l l l l l 5 AS pattern max age 5 Enforce overdue AS engine/pattern update 5 POLICY ASSIGNMENTS VPN PROPERTIES DHCP-based parameter assignment Cryptography 5 6 6 If supported by AV / AS product Involves routes, WINS & DNS adresses, IP address & network mask, domain & firewall rule set. Barracuda NG Firewall - Anti-Spyware (AS) product installed (by vendor) 5 Enforce overdue AV engine/pattern update 5 46 BARRACUDA NG NAC SUBSCRIPTION BARRACUDA VPN CLIENT BARRACUDA NETWORK ACCESS CLIENT BARRACUDA SSL VPN TRANSPARENT CLIENT AES-128/AES-256 l l l 3DES and DES l l l CAST and BLOWFISH l l l Authentication only (null encryption) l l l SHA-1 and MD5 hashing l l l Redundant gateway support l l l NAT traversal l l l HTTPS proxy compatible l l l SSL handshake simulation l l l SOCKS4/5 proxy compatible l l l Pathfinder best gateway finder l l - WLAN roaming support l l - Always connect technology l l - Fast reconnect technology l l - Full server side control l l l Split DNS l l l Split tunnel mode l l l Exclusive Network Access ENA l l l SOFTWARE FEATURES VPN PROPERTIES (CONTINUED) VPN CONNECTION INTELLIGENCE Barracuda NG Firewall SECURITY FEATURES 7 7 ENA function is only available if the full Barracuda Network Access Client is chosen during the installation procedure. 47 SOFTWARE FEATURES STANDARD EDITION (C400 AND VC400) BARRACUDA NG CONTROL CENTER ENTERPRISE EDITION (C610 AND VC610) GLOBAL EDITION (VC820) CONFIGURATION MANAGEMENT 1 1 5 Configuration groups 1 1 No limit No limit No limit [20] No limit [200] No limit [1000+ depending on HW] Configuration templates (repositories) l l l Shared configuration data l l l Operating system parameters l l l Networking/routing parameters l l l FW/VPN policies, application gateway parameters l l l Flat file data storage l l l Database characteristics (transaction orientation, locking, etc.) l l l Backup and restore functionality l l l Gateway configuration archive for speed install l l l Configuration update monitoring l l l Full RCS versioning l l l VPN graphical tunnel interface l l l Barracuda Network Access Client policy management l l l Multi-release management - l l Multi-platform management l l l Gateway health state l l l Launch pad functionality l l l Customizable layout l l l Barracuda NG Earth support - l l Gateway x.509 certificate CA l l l Gateway SSH key management l l l VPN server for management tunnels to gateways l l l Virtual IP addresses for gateways (ProxyARP) l l l Dynamic gateway IP address support l l l License timestamp server l l l License status display l l l Central event message list l l l Event forwarding (SNMP, mail) l l l Event log l l l Central activation of managed units l l l Central license retrieval for managed units l l l Central license extension for managed units l l l Offline (unit) activation for managed units l l l Offline (unit) license retrieval for managed units l l l Maximum managed gateways [recommended] STATUS MONITORING TRUST CENTER LICENSE CENTER BARRACUDA ACTIVATION 1 Note that “Configuration Groups“ (named “cluster“ in the firmware) refers to an administratively bundled group of Barracuda NG Firewall appliances and not to a load sharing cluster. Barracuda NG Firewall Tenants 48 SOFTWARE FEATURES STANDARD EDITION (C400 AND VC400) ENTERPRISE EDITION (C610 AND VC610) GLOBAL EDITION (VC820) BARRACUDA ACTIVATION (CONTINUED) Offline (unit) license extension for managed units l l l Activation properties per cluster - l l Activation properties per range - - l Full automatic activation l l l Manual activation l l l Activation of Vx units with license token l l l Activation of HA unit l l l Session display l l l Session termination l l l Real-time version display l l l Kernel and OS updates l l l Barracuda NG Firewall updates l l l Update log viewer l l l Job scheduling l l l Script management l l l Execution log viewer l l l Fully GUI-based access (NG Admin management tool) l l l Strong authentication & AES encryption l l l Role-based administration l l l Configurable roles l l l Adjustable view on configuration tree l l l Configurable administrative domains - l l Multiple domains per administrator - l l Configurable access on OS level l l l Configurable access notification l l l Historical reports on gateway activity l l l Customer-based gateway activity reports l l l Policy distribution l l l Control Center resource utilization l l l Gateway-resource utilization l l l Central log host l l l Streaming/relaying to external log host l l l NTP4 time server for gateways l l l Integrated DNS server l l l Optional Optional HA license included SIEM syslog interface l l l Public Key Infrastructure - l l Revision Control System l l l Barracuda NG Access Monitor l l l CENTRAL SESSION TRACKING CENTRAL SOFTWARE UPDATE SECURE REMOTE EXEC. ENVIRONMENT (SSHV2) Barracuda NG Firewall ADMINISTRATION MODEL REPORTING AND ACCOUNTING ADDITIONAL FUNCTIONS High availability 49 Subscriptions AVAILABILITY MATRIX F100/ F200/ F300/ F280 F380 F101 F201 F301 BARRACUDA NG FIREWALL F10 Energize Updates Mandatory Instant Replacement Optional Warranty Extension Optional Premium Support Optional NG Web Security Optional NG Web Filter NG Malware Protection NG SSL VPN & NAC Advanced Threat Detection Optional F400 F600 F800 F900 F1000 VX Optional Optional Optional High Availability (“HA”): All subscriptions have to be licensed separately for the HA partner. For further information, please contact your local partner or Barracuda sales at [email protected] ENERGIZE UPDATES Barracuda Energize Updates provide your Barracuda Networks product with protection from the latest Internet threats. The team at Barracuda Central continuously monitors the Internet for new trends in network security threats and develops strategies to mitigate those threats. • Security updates to patch or repair any security vulnerabilities. • Barracuda Web Filter online URL categorization • All released updates for the Application Control database. • IPS signature and pattern updates. • Basic Support, which includes 24/7 email support and phone support between the hours of 9:00 a.m. and 5:00 p.m. Monday through Friday. Note: Energize Updates are available for all Barracuda NG Firewall hardware and virtual models. Available as 1, 3, and 5 year subscriptions. Purchasing at least 1 year of Energize Updates is required with every Barracuda NG Firewall. Barracuda NG Firewall Energize Updates includes: • Firmware maintenance, which includes new firmware updates with feature enhancements and bug fixes as they are made available. 50 INSTANT REPLACEMENT Provides an extended warranty, ships a replacement unit on the same or next business day with express mail upon notification of a failed unit, assists with data migration to new unit, and provides a RAID hard disk replacement as applicable. In addition, the Instant Replacement service includes: • Enhanced Support, which provides phone and email support 24/7. • Hard disk replacement on Barracuda Networks models that have swappable RAID drives. Barracuda Networks will ship via standard shipping a hard disk replacement. Customer must return the failed hard disk to Barracuda Networks. • After four years of continuous IR coverage, customer is entitled to a free hardware refresh. Note: Available for all Barracuda NG Firewall hardware models. Instant Replacement must be purchased within 60 days of hardware purchase and is a continuous subscription from date of activation. Available as 1, 3, and 5 year subscriptions. WARRANTY EXTENSION Provides an extended warranty, ships a replacement unit on the next business day (best effort) with standard mail upon notification of a failed unit, assists with data migration to new unit, and provides a RAID hard disk replacement as applicable. In addition, the Warranty Extension service includes: • Standard Support, which provides phone and email support 8x5. Barracuda NG Firewall • Hard disk replacement on Barracuda Networks models that have swappable RAID drives. Barracuda Networks will ship via standard shipping a hard disk replacement. Customer must return the failed hard disk to Barracuda Networks. Note: Available for all Barracuda NG Firewall hardware models. Warranty Extension must be purchased within 60 days of hardware purchase and is a continuous subscription from date of activation. Available as 1 and 3 year subscriptions with a maximum coverage of 5 years. Comparison “Instant Replacement - Warranty Extension” Instant Replacement Replacement Shipment Hard disk replacement (swappable RAID) Support Available subscriptions Free hardware refresh after 4 years Warranty Extension Same day or next business day Next business day (best effort) Express Standard Standard shipping 24/7 Enhanced Support 8/5 Basic Support 1, 3, 5 years 1, 3 years l PREMIUM SUPPORT Barracuda Premium Support ensures that an organization’s network is running at its peak performance by providing the highest level of 24/7 technical support for mission-critical environments. Customers will benefit from a dedicated account manager and a team of technical engineers who will provide fast resolution of high-priority support issues, ensuring that equipment maintains continuous uptime. KEY BENEFITS Note: Available for all Barracuda NG Firewall hardware and virtual models. Premium Support for Barracuda NG Firewall hardware appliances can only be purchased in combination with Instant Replacement. Premium Support may be purchased on Barracuda NG Firewall virtual appliances without Instant Replacement. Available as 1, 3, and 5 year subscriptions. For more information on Premium Support please visit www.barracuda.com/support. • 24/7 global support • Priority response time to resolve mission-critical issues • Service Level Agreements (SLAs) to guarantee that issues are resolved quickly • Dedicated support team that is familiar with your environment • Proactive monitoring for optimal performance 51 BARRACUDA NG WEB SECURITY The Barracuda NG Web Security subscription option for Barracuda NG Firewall models F100 and higher bundles the Barracuda NG Malware Protection and Barracuda NG Web Filter, offering complete web security. Available as 1, 3, and 5 years subscriptions. BARRACUDA NG MALWARE PROTECTION The Barracuda NG Malware Protection provides gatewaybased protection against malware, viruses, spyware, and other unwanted programs inside SMTP, HTTP, POP3, and FTP traffic. KEY FEATURES • Configurable archive recursion depth • Quarantine functionality for proxy Compatibility and Licensing: Available for Barracuda NG Firewall models F100 and higher, as well as all Barracuda NG Firewall virtual appliances. Unlimited user license if purchased with a Barracuda NG Firewall hardware appliance. If purchased for a virtual appliance the number of protected IPs (capacity) applies. Available as 1, 3, and 5 years subscriptions. In High Availability (HA) environments each unit needs to be licensed separately. • Configurable unknown archive policy • Configurable maximum archive size • Archiver package support • Office file-types support • Proactive detection of new threats • Advanced heuristics detection techniques • Hundreds of thousands signatures • Multiple signature updates per day BARRACUDA NG WEB FILTER The Barracuda NG Web Filter enables highly granular, real-time visibility into online activity, broken down by individual users and applications, letting administrators create and enforce effective Internet content and access policies. KEY FEATURES • Customizable blacklists and whitelists • Filter entire URL string beyond FQDN • Multiple category selection Compatibility and Licensing: Available for Barracuda NG Firewall models F100 and higher, as well as all Barracuda NG Firewall virtual appliances. Unlimited user license if purchased with a Barracuda NG Firewall hardware appliance. If purchased for a virtual appliance the number of protected IPs (capacity) applies. Available as 1, 3, and 5 years subscriptions. In High Availability (HA) environments each unit needs to be licensed separately. • ~100 million entries • ~100,000 new URL database entries per day • Temporal constraints • User specific / group specific restrictions • Category database • Local or online updates • Hourly intervals or continuous updates • Customizable block pages BARRACUDA WEB FILTER The Barracuda Web Filter enables highly granular, real-time visibility into online activity, broken down by individual users and applications, letting administrators create and enforce effective Internet content and access policies. The Barracuda Web Filter is included in the Energize Updates subscription. Compatibility and Licensing: Included with Energize Updates subscriptions for Barracuda NG Firewall models F100 and higher, as well as all Barracuda NG Firewall virtual appliances. Unlimited user license with a Barracuda NG Firewall hardware unit. For virtual appliances, the number of protected IPs (capacity) applies. In High Availability (HA) environments, each unit needs to be licensed separately. The Barracuda Web Filter and the Barracuda NG Web Filter cannot be run at the same time and have to be activated separately, one at a time on the Barracuda NG Firewall units. KEY FEATURES • Customizable blacklists and whitelists • 95 content categories • Multiple category selection • Temporal constraints • User specific / group specific restrictions • Online categorization lookup • Persistent local cache • Customizable block pages Barracuda NG Firewall • 69 content categories 52 BARRACUDA NG SSL VPN & NAC Every Barracuda NG Firewall unit supports an unlimited number of VPN clients at no extra cost. The optional Barracuda NG Firewall SSL VPN and NAC subscription adds a customizable and easy-to-use web-based SSL VPN as well as sophisticated Network Access Control (NAC) functionality. NAC allows enforcement of minimum Windows client security prerequisites before being allowed access to the network or access to a quarantine network. Security posture can be specified according to available Windows patch level, availability of anti-virus and/or anti-spyware, and user ID. Access restrictions are enforced locally on the client by the centrally managed personal Windows firewall as well as at the gateway. Barracuda NG Firewall ADVANCED THREAT DETECTION Monthly File Capacity HARDWARE ENVIRONMENTS F200/ F201 F280 F300/ F301 F380 F400 F600 F800 F900 F1000 Number of files inspected per month 100,000 200,000 100,000 260,000 300,000 540,000 750,000 1,000,000 on request VIRTUALIZED ENVIRONMENTS VF25 VF50 VF100 VF250 VF500 Number of files inspected per month 40,000 100,000 200,000 300,000 430,000 VF1000 VF2000 VF4000 VF8000 540,000 640,000 750,000 1,000,000 PUBLIC CLOUD ENVIRONMENTS AWS LEVEL 2 AWS LEVEL 4 AWS LEVEL 6 AWS LEVEL 8 AZURE LEVEL 2 AZURE LEVEL 4 AZURE LEVEL 6 AZURE LEVEL 8 Number of files inspected per month 40,000 100,000 200,000 300,000 430,000 540,000 640,000 750,000 Compatibility and Licensing: Available for Barracuda NG Firewall models F200 and higher, as well as all Barracuda NG Firewall virtual appliances. Available as 1, 3, and 5 years subscriptions. Requires a valid Web Security or Malware Protection subscription. In case the monthly file capacity is reached, the system stops forwarding files to the ATD cloud for the rest of the current month. KEY FEATURES • Prevent malicious files—even unknown ones— from entering the organization and avoid network breaches. • Identify zero-day malware exploits, targeted attacks, advanced persistent threats and other advanced malware which routinely bypass traditional signature based IPS and antivirus engines. • Granular Control over PDFs, EXEs/MSIs/DLLs, Android APKs, Microsoft Office files, and compressed files and archives • Full interoperability with the integrated SSL Inspection files can be extracted and checked in order to detect advanced malware in the encrypted stream. • Cloud based emulation – resource intensive file emulation is offloaded to the Barracuda Cloud. • Learning local cryptographic hash database for emulation optimization • Multiple and simultaneous OS environments for emulated files • Automatic email notifications in case malware activity has been identified can help minimizing the time for reaction of the administrator in order to mitigate the network breach. • Available for hardware and virtual appliances as well as for Microsoft Azure and the Amazon AWS Cloud 53 Ordering Information Calculation of co-terminus subscriptions: To allow customers to consolidate their maintenance and subscription offerings to a single end or renewal date, daily rates for all subscription types are offered. These daily rates should be used to extend expiring subscriptions to coincide with the dates of subscriptions expiring in the future. Barracuda Networks does credit early termination of subscriptions using these daily rates. BARRACUDA NG FIREWALL APPLIANCES PRODUCT ORDER NO. EMEA / INTERNATIONAL ORDER NO. NORTH AMERICA BNGIF10a BNGF10a Barracuda NG Firewall F10 Barracuda NG Firewall Model F10 Energize Updates (1Y, 3Y, 5Y) BNGIF10a-e1,3,5 BNGF10a-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF10a-h1,3,5 BNGF10a-h1,3,5 Warranty Extension (1Y, 3Y) BNGIF10a-we1,3 BNGF10a-we1,3 Premium Support (1Y, 3Y, 5Y) BNGIF10a-p1,3,5 BNGF10a-p1,3,5 BNGIF10a-c BNGF10a-c BNGIF100a BNGF100a Barracuda NG Firewall Cold Spare F10 Barracuda NG Firewall F100 Barracuda NG Firewall Model F100 Energize Updates (1Y, 3Y, 5Y) BNGIF100a-e1,3,5 BNGF100a-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF100a-h1,3,5 BNGF100a-h1,3,5 BNGIF100a-we1,3 BNGF100a-we1,3 Premium Support (1Y, 3Y, 5Y) BNGIF100a-p1,3,5 BNGF100a-p1,3,5 Barracuda NG Web Security (1Y, 3Y, 5Y) BNGIF100a-w1,3,5 BNGF100a-w1,3,5 Barracuda NG Web Filter (1Y, 3Y, 5Y) BNGIF100a-u1,3,5 BNGF100a-u1,3,5 Barracuda NG Malware Protection (1Y, 3Y, 5Y) BNGIF100a-m1,3,5 BNGF100a-m1,3,5 BNGIF100a-c BNGF100a-c Barracuda NG Firewall Cold Spare F100 Barracuda NG Firewall F101 (Wifi Bundle) Barracuda NG Firewall Model F101 (Wifi Bundle) BNGIF101a BNGF101a Energize Updates (1Y, 3Y, 5Y) BNGIF101a-e1,3,5 BNGF101a-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF101a-h1,3,5 BNGF101a-h1,3,5 Warranty Extension (1Y, 3Y) BNGIF101a-we1,3 BNGF101a-we1,3 Premium Support (1Y, 3Y, 5Y) BNGIF101a-p1,3,5 BNGF101a-p1,3,5 Barracuda NG Web Security (1Y, 3Y, 5Y) 1 BNGIF101a-w1,3,5 BNGF101a-w1,3,5 Barracuda NG Web Filter (1Y, 3Y, 5Y) BNGIF101a-u1,3,5 BNGF101a-u1,3,5 Barracuda NG Malware Protection (1Y, 3Y, 5Y) BNGIF101a-m1,3,5 BNGF101a-m1,3,5 BNGIF101a-c BNGF101a-c BNGIF200a BNGF200a Barracuda NG Firewall Cold Spare F101 Barracuda NG Firewall F200 Barracuda NG Firewall Model F200 Energize Updates (1Y, 3Y, 5Y) BNGIF200a-e1,3,5 BNGF200a-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF200a-h1,3,5 BNGF200a-h1,3,5 Warranty Extension (1Y, 3Y) BNGIF200a-we1,3 BNGF200a-we1,3 Premium Support (1Y, 3Y, 5Y) BNGIF200a-p1,3,5 BNGF200a-p1,3,5 Barracuda Advanced Threat Detection (1Y, 3Y, 5Y) BNGIF200a-a1,3,5 BNGF200a-a1,3,5 Barracuda NG Web Security (1Y, 3Y, 5Y) 1 BNGIF200a-w1,3,5 BNGF200a-w1,3,5 Barracuda NG Web Filter (1Y, 3Y, 5Y) BNGIF200a-u1,3,5 BNGF200a-u1,3,5 Barracuda NG Malware Protection (1Y, 3Y, 5Y) BNGIF200a-m1,3,5 BNGF200a-m1,3,5 Includes Barracuda NG Web Filter and Barracuda NG Malware Protection BNGIF200a-v1,3,5 BNGF200a-v1,3,5 BNGIF200a-c BNGF200a-c 1 Barracuda NG SSL VPN and NAC (1Y, 3Y, 5Y) Barracuda NG Firewall Cold Spare F200 Barracuda NG Firewall Warranty Extension (1Y, 3Y) 54 ORDER NO. EMEA / INTERNATIONAL PRODUCT ORDER NO. NORTH AMERICA Barracuda NG Firewall F201 (Wifi Bundle) Barracuda NG Firewall Model F201 (Wifi Bundle) BNGIF201a BNGF201a Energize Updates (1Y, 3Y, 5Y) BNGIF201a-e1,3,5 BNGF201a-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF201a-h1,3,5 BNGF201a-h1,3,5 Warranty Extension (1Y, 3Y) BNGIF201a-we1,3 BNGF201a-we1,3 Premium Support (1Y, 3Y, 5Y) BNGIF201a-p1,3,5 BNGF201a-p1,3,5 Barracuda Advanced Threat Detection (1Y, 3Y, 5Y) BNGIF201a-a1,3,5 BNGF201a-a1,3,5 Barracuda NG Web Security (1Y, 3Y, 5Y) BNGIF201a-w1,3,5 BNGF201a-w1,3,5 Barracuda NG Web Filter (1Y, 3Y, 5Y) BNGIF201a-u1,3,5 BNGF201a-u1,3,5 Barracuda NG Malware Protection (1Y, 3Y, 5Y) BNGIF201a-m1,3,5 BNGF201a-m1,3,5 Barracuda NG SSL VPN and NAC (1Y, 3Y, 5Y) BNGIF201a-v1,3,5 BNGF201a-v1,3,5 BNGIF201a-c BNGF201a-c BNGIF280a BNGF280a 1 Barracuda NG Firewall Cold Spare F201 Barracuda NG Firewall F280 Barracuda NG Firewall Model F280 Energize Updates (1Y, 3Y, 5Y) BNGIF280a-e1,3,5 BNGF280a-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF280a-h1,3,5 BNGF280a-h1,3,5 Warranty Extension (1Y, 3Y) BNGIF280a-we1,3 BNGF280a-we1,3 Premium Support (1Y, 3Y, 5Y) BNGIF280a-p1,3,5 BNGF280a-p1,3,5 Barracuda Advanced Threat Detection (1Y, 3Y, 5Y) BNGIF280a-a1,3,5 BNGF280a-a1,3,5 Barracuda NG Web Security (1Y, 3Y, 5Y) 1 BNGIF280a-w1,3,5 BNGF280a-w1,3,5 Barracuda NG Web Filter (1Y, 3Y, 5Y) BNGIF280a-u1,3,5 BNGF280a-u1,3,5 Barracuda NG Malware Protection (1Y, 3Y, 5Y) BNGIF280a-m1,3,5 BNGF280a-m1,3,5 Barracuda NG SSL VPN and NAC (1Y, 3Y, 5Y) BNGIF280a-v1,3,5 BNGF280a-v1,3,5 BNGIF280a-c BNGF280a-c Barracuda NG Firewall Barracuda NG Firewall Cold Spare F280 Barracuda NG Firewall F300 Barracuda NG Firewall Model F300 BNGIF300a BNGF300a Energize Updates (1Y, 3Y, 5Y) BNGIF300a-e1,3,5 BNGF300a-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF300a-h1,3,5 BNGF300a-h1,3,5 Warranty Extension (1Y, 3Y) BNGIF300a-we1,3 BNGF300a-we1,3 Premium Support (1Y, 3Y, 5Y) BNGIF300a-p1,3,5 BNGF300a-p1,3,5 Barracuda Advanced Threat Detection (1Y, 3Y, 5Y) BNGIF300a-a1,3,5 BNGF300a-a1,3,5 Barracuda NG Web Security (1Y, 3Y, 5Y) BNGIF300a-w1,3,5 BNGF300a-w1,3,5 1 Barracuda NG Web Filter (1Y, 3Y, 5Y) BNGIF300a-u1,3,5 BNGF300a-u1,3,5 Barracuda NG Malware Protection (1Y, 3Y, 5Y) BNGIF300a-m1,3,5 BNGF300a-m1,3,5 Barracuda NG SSL VPN and NAC (1Y, 3Y, 5Y) BNGIF300a-v1,3,5 BNGF300a-v1,3,5 BNGIF300a-c BNGF300a-c BNGIF301a BNGF301a Barracuda NG Firewall Cold Spare F300 Barracuda NG Firewall F301 (Wifi Bundle) Barracuda NG Firewall Model F301 (Wifi Bundle) Energize Updates (1Y, 3Y, 5Y) BNGIF301a-e1,3,5 BNGF301a-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF301a-h1,3,5 BNGF301a-h1,3,5 Warranty Extension (1Y, 3Y) BNGIF301a-we1,3 BNGF301a-we1,3 Premium Support (1Y, 3Y, 5Y) BNGIF301a-p1,3,5 BNGF301a-p1,3,5 Barracuda Advanced Threat Detection (1Y, 3Y, 5Y) BNGIF301a-a1,3,5 BNGF301a-a1,3,5 Barracuda NG Web Security (1Y, 3Y, 5Y) 1 BNGIF301a-w1,3,5 BNGF301a-w1,3,5 Barracuda NG Web Filter (1Y, 3Y, 5Y) BNGIF301a-u1,3,5 BNGF301a-u1,3,5 Barracuda NG Malware Protection (1Y, 3Y, 5Y) BNGIF301a-m1,3,5 BNGF301a-m1,3,5 Barracuda NG SSL VPN and NAC (1Y, 3Y, 5Y) BNGIF301a-v1,3,5 BNGF301a-v1,3,5 BNGIF301a-c BNGF301a-c Barracuda NG Firewall Cold Spare F301 Includes Barracuda NG Web Filter and Barracuda NG Malware Protection Available F400 models: standard and .F20 sub model 1 2 55 ORDER NO. NORTH AMERICA BNGIF380a.<sub model> 2 BNGF380a.<sub model> 2 Energize Updates (1Y, 3Y, 5Y) BNGIF380a.<sub model>-e1,3,5 BNGF380a.<sub model>-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF380a.<sub model>-h1,3,5 BNGF380a.<sub model>-h1,3,5 Extended Warranty (1Y, 3Y) BNGIF380a.<sub model>-we1,3 BNGF380a.<sub model>-we1,3 Premium Support (1Y, 3Y, 5Y) BNGIF380a.<sub model>-p1,3,5 BNGF380a.<sub model>-p1,3,5 Barracuda Advanced Threat Detection (1Y, 3Y, 5Y) BNGIF380a.<sub model>-a1,3,5 BNGF380a.<sub model>-a1,3,5 Barracuda NG Web Security (1Y, 3Y, 5Y) ORDER NO. EMEA / INTERNATIONAL PRODUCT Barracuda NG Firewall F380 Barracuda NG Firewall Model F380 BNGIF380a.<sub model>-w1,3,5 BNGF380a.<sub model>-w1,3,5 Barracuda NG Web Filter (1Y, 3Y, 5Y) BNGIF380a.<sub model>-u1,3,5 BNGF380a.<sub model>-u1,3,5 Barracuda NG Malware Protection (1Y, 3Y, 5Y) BNGIF380a.<sub model>-m1,3,5 BNGF380a.<sub model>-m1,3,5 Barracuda NG SSL VPN and NAC (1Y, 3Y, 5Y) BNGIF380a.<sub model>-v1,3,5 BNGF380a.<sub model>-v1,3,5 BNGIF380a.<sub model>-c BNGF380a.<sub model>-c BNGIF400a.<sub model> 2 BNGF400a.<sub model> 2 1 Barracuda NG Firewall Cold Spare F380 Barracuda NG Firewall F400 Barracuda NG Firewall Model F400 Energize Updates (1Y, 3Y, 5Y) BNGIF400a.<sub model>-e1,3,5 BNGF400a.<sub model>-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF400a.<sub model>-h1,3,5 BNGF400a.<sub model>-h1,3,5 Extended Warranty (1Y, 3Y) BNGIF400a.<sub model>-we1,3 BNGF400a.<sub model>-we1,3 Premium Support (1Y, 3Y, 5Y) BNGIF400a.<sub model>-p1,3,5 BNGF400a.<sub model>-p1,3,5 Barracuda Advanced Threat Detection (1Y, 3Y, 5Y) BNGIF400a.<sub model>-a1,3,5 BNGF400a.<sub model>-a1,3,5 Barracuda NG Web Security (1Y, 3Y, 5Y) 1 BNGIF400a.<sub model>-w1,3,5 BNGF400a.<sub model>-w1,3,5 BNGIF400a.<sub model>-u1,3,5 BNGF400a.<sub model>-u1,3,5 Barracuda NG Malware Protection (1Y, 3Y, 5Y) BNGIF400a.<sub model>-m1,3,5 BNGF400a.<sub model>-m1,3,5 Barracuda NG SSL VPN and NAC (1Y, 3Y, 5Y) BNGIF400a.<sub model>-v1,3,5 BNGF400a.<sub model>-v1,3,5 BNGIF400a.<sub model>-c BNGF400a.<sub model>-c BNGIF600a.<sub model> 2 BNGF600a.<sub model> 2 Energize Updates (1Y, 3Y, 5Y) BNGIF600a.<sub model>-e1,3,5 BNGF600a.<sub model>-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF600a.<sub model>-h1,3,5 BNGF600a.<sub model>-h1,3,5 Extended Warranty (1Y, 3Y) BNGIF600a.<sub model>-we1,3 BNGF600a.<sub model>-we1,3 Barracuda NG Firewall Cold Spare F400 Barracuda NG Firewall F600 Barracuda NG Firewall Model F600 Premium Support (1Y, 3Y, 5Y) BNGIF600a.<model>-p1,3,5 BNGF600a.<sub model>-p1,3,5 Barracuda Advanced Threat Detection (1Y, 3Y, 5Y) BNGIF600a.<sub model>-a1,3,5 BNGF600a.<sub model>-a1,3,5 Barracuda NG Web Security (1Y, 3Y, 5Y) BNGIF600a.<sub model>-w1,3,5 BNGF600a.<sub model>-w1,3,5 Barracuda NG Web Filter (1Y, 3Y, 5Y) BNGIF600a.<sub model>-u1,3,5 BNGF600a.<sub model>-u1,3,5 Barracuda NG Malware Protection (1Y, 3Y, 5Y) BNGIF600a.<sub model>-m1,3,5 BNGF600a.<sub model>-m1,3,5 Barracuda NG SSL VPN and NAC (1Y, 3Y, 5Y) BNGIF600a.<sub model>-v1,3,5 BNGF600a.<sub model>-v1,3,5 BNGIF600a.<sub model>-c BNGF600a.<sub model>-c BNGIF800a.<sub model> 3 BNGF800a.<sub model> 3 1 Barracuda NG Firewall Cold Spare F600 Barracuda NG Firewall F800 Barracuda NG Firewall Model F800 Energize Updates (1Y, 3Y, 5Y) BNGIF800a.<sub model>-e1,3,5 BNGF800a.<sub model>-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF800a.<sub model>-h1,3,5 BNGF800a.<sub model>-h1,3,5 Extended Warranty (1Y, 3Y) BNGIF800a.<sub model>-we1,3 BNGF800a.<sub model>-we1,3 Premium Support (1Y, 3Y, 5Y) BNGIF800a.<sub model>-p1,3,5 BNGF800a.<sub model>-p1,3,5 Barracuda Advanced Threat Detection (1Y, 3Y, 5Y) BNGIF800a.<sub model>-a1,3,5 BNGF800a.<sub model>-a1,3,5 Barracuda NG Web Security (1Y, 3Y, 5Y) BNGIF800a.<sub model>-w1,3,5 BNGF800a.<sub model>-w1,3,5 Barracuda NG Web Filter (1Y, 3Y, 5Y) 1 BNGIF800a.<sub model>-u1,3,5 BNGF800a.<sub model>-u1,3,5 Barracuda NG Malware Protection (1Y, 3Y, 5Y) BNGIF800a.<sub model>-m1,3,5 BNGF800a.<sub model>-m1,3,5 Barracuda NG SSL VPN and NAC (1Y, 3Y, 5Y) BNGIF800a.<sub model>-v1,3,5 BNGF800a.<sub model>-v1,3,5 BNGIF800a.<sub model>-c BNGF800a.<sub model>-c Barracuda NG Firewall Cold Spare F800 2 3 4 5 1 Includes Barracuda NG Web Filter and Barracuda NG Malware Protection Available F600 models: C10, C20, F10, F20, E20; please see page 34 for details Available F800 models: standard and .CCC, .CCF, .CCE sub models; please see page 35 for details Available F900 models: standard and .CCC, .CCE, and .CFE sub models; please see page 35 for details Available F1000 models: standard and .CE0, .CE2, and .CFE sub models, please see page 36 for details Barracuda NG Firewall Barracuda NG Web Filter (1Y, 3Y, 5Y) 56 ORDER NO. EMEA / INTERNATIONAL ORDER NO. NORTH AMERICA BNGIF900a.<sub model> 4 BNGF900a.<sub model> 4 Energize Updates (1Y, 3Y, 5Y) BNGIF900a.<sub model>-e1,3,5 BNGF900a.<sub model>-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF900a.<sub model>-h1,3,5 BNGF900a.<sub model>-h1,3,5 Extended Warranty (1Y, 3Y) BNGIF900a.<sub model>-we1,3 BNGF900a.<sub model>-we1,3 Premium Support (1Y, 3Y, 5Y) BNGIF900a.<sub model>-p1,3,5 BNGF900a.<sub model>-p1,3,5 Barracuda Advanced Threat Detection (1Y, 3Y, 5Y) BNGIF900a.<sub model>-a1,3,5 BNGF900a.<sub model>-a1,3,5 NG Web Security (1Y, 3Y, 5Y) PRODUCT Barracuda NG Firewall F900 Barracuda NG Firewall Model F900 BNGIF900a.<sub model>-w1,3,5 BNGF900a.<sub model>-w1,3,5 NG Web Filter (1Y, 3Y, 5Y) BNGIF900a.<sub model>-u1,3,5 BNGF900a.<sub model>-u1,3,5 NG Malware Protection (1Y, 3Y, 5Y) BNGIF900a.<sub model>-m1,3,5 BNGF900a.<sub model>-m1,3,5 NG SSL VPN and NAC (1Y, 3Y, 5Y) BNGIF900a.<sub model>-v1,3,5 BNGF900a.<sub model>-v1,3,5 BNGIF900a.<sub model>-c BNGF900a.<sub model>-c BNGIF1000a.<sub model> 5 BNGF1000a.<sub model> 5 1 Barracuda NG Firewall Cold Spare F900 Barracuda NG Firewall F1000 Barracuda NG Firewall Barracuda NG Firewall Model F1000 Energize Updates (1Y, 3Y, 5Y) BNGIF1000a.<sub model>-e1,3,5 BNGF1000a.<sub model>-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNGIF1000a.<sub model>-h1,3,5 BNGF1000a.<sub model>-h1,3,5 Extended Warranty (1Y, 3Y) BNGIF1000a.<sub model>-we1,3 BNGF1000a.<sub model>-we1,3 Premium Support (1Y, 3Y, 5Y) BNGIF1000a.<sub model>-p1,3,5 BNGF1000a.<sub model>-p1,3,5 Barracuda Advanced Threat Detection (1Y, 3Y, 5Y) BNGIF1000a.<sub model>-a1,3,5 BNGF1000a.<sub model>-a1,3,5 NG Web Security (1Y, 3Y, 5Y) 1 BNGIF1000a.<sub model>-w1,3,5 BNGF1000a.<sub model>-w1,3,5 NG Web Filter (1Y, 3Y, 5Y) BNGIF1000a.<sub model>-u1,3,5 BNGF1000a.<sub model>-u1,3,5 NG Malware Protection (1Y, 3Y, 5Y) BNGIF1000a.<sub model>-m1,3,5 BNGF1000a.<sub model>-m1,3,5 NG SSL VPN and NAC (1Y, 3Y, 5Y) BNGIF1000a.<sub model>-v1,3,5 BNGF1000a.<sub model>-v1,3,5 BNGIF1000a.<sub model>-c BNGF1000a.<sub model>-c Barracuda NG Firewall Cold Spare F1000 BARRACUDA NG FIREWALL HARDWARE OPTIONS ORDER NO. EMEA / INTERNATIONAL ORDER NO. NORTH AMERICA BNGIM11a BNGM11a Barracuda 19” rack mount shelf kit for F10x-F20x BPNGIRAC-01 BPNGRAC-01 Barracuda rail kit for F380-F600 BPNGIRAC-02 BPNGRAC-02 Barracuda rail kit for F1000 BPNGRAC-04 BPNGRAC-04 Barracuda L-shape rack mount bracket (2x) for F280 BPIRAC-02 BPRAC-02 Barracuda Maintenance Kit for F1000 (including two fans and one power supply brick) BPNGIKITF1000 BPNGKITF1000 PRODUCT Barracuda 3G modem for models F10-F1000 3 4 5 1 2 Includes Barracuda NG Web Filter and Barracuda NG Malware Protection Available F600 models: C10, C20, F10, F20, E20; please see page 34 for details Available F800 models: standard and .CCC, .CCF, .CCE sub models; please see page 35 for details Available F900 models: standard and .CCC, .CCE, and .CFE sub models; please see page 35 for details Available F1000 models: standard and .CE0, .CE2, and .CFE sub models, please see page 36 for details 57 PRODUCT Barracuda NG Firewall VF25, VF50, VF100, VF250, VF500, VF1000, VF2000, VF4000, VF8000 Energize Updates (1Y, 3Y, 5Y) Premium Support (1Y, 3Y, 5Y) NG Web Security (1Y, 3Y, 5Y) NG Web Filter (1Y, 3Y, 5Y) NG Malware Protection (1Y, 3Y, 5Y) NG SSL VPN and NAC (1Y, 3Y, 5Y) BARRACUDA NG FIREWALL VIRTUAL APPLIANCES ORDER NO. EMEA / INTERNATIONAL ORDER NO. NORTH AMERICA BNGIVF25a,….BNGIVF8000a BNGVF25a,….BNGVF8000a BNGIVF<user>-e<subscription duration>, e.g. BNGIVF25a-e1 BNGIVF<user>-p<subscription duration>, e.g. BNGIVF25a-p1 BNGIVF<user>-w<subscription duration>, e.g. BNGIVF25a-w1 BNGIVF<user>-u<subscription duration>, e.g. BNGIVF25a-u3 BNGIVF<user>-m<subscription duration>, e.g. BNGIVF25a-m1 BNGIVF<user>-s<subscription duration>, e.g. BNGIVF25a-v1 BNGVF<user>-e<subscription duration>, e.g. BNGVF25a-e1 BNGVF<user>-p<subscription duration>, e.g. BNGVF25a-p1 BNGVF<user>-w<subscription duration>, e.g. BNGVF25a-w1 BNGVF<user>-u<subscription duration>, e.g. BNGVF25a-u3 BNGVF<user>-m<subscription duration>, e.g. BNGVF25a-m1 BNGVF<user>-s<subscription duration>, e.g. BNGVF25a-v1 BARRACUDA NG CONTROL CENTER APPLIANCES PRODUCT ORDER NO. EMEA / INTERNATIONAL ORDER NO. NORTH AMERICA BNCIC400a BNCC400a Barracuda NG Control Center C400 Barracuda NG Control Center C400 - Standard Edition BNCIC400a-e1,3,5 BNCC400a-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNCIC400a-h1,3,5 BNCC400a-h1,3,5 Extended Warranty (1Y, 3Y) BNCIC400a-we1,3 BNCC400a-we1,3 Premium Support (1Y, 3Y, 5Y) BNCIC400a-p1,3,5 BNCC400a-p1,3,5 BNCIC400a-c BNCC400a-c BNCIC610a BNCC610a Barracuda NG Control Center Cold Spare C400 Barracuda NG Control Center C610 Barracuda NG Control Center C610 - Enterprise Edition Energize Updates (1Y, 3Y, 5Y) BNCIC610a-e1,3,5 BNCC610a-e1,3,5 Instant Replacement (1Y, 3Y, 5Y) BNCIC610a-h1,3,5 BNCC610a-h1,3,5 Extended Warranty (1Y, 3Y) BNCIC610a-we1,3 BNCC610a-we1,3 Premium Support (1Y, 3Y, 5Y) BNCIC610a-p1,3,5 BNCC610a-p1,3,5 BNCIC400a-c BNCC400a-c Barracuda NG Control Center Cold Spare C610 BARRACUDA NG CONTROL CENTER VIRTUAL APPLIANCES PRODUCT ORDER NO. EMEA / INTERNATIONAL ORDER NO. NORTH AMERICA BNCIVC400a BNCVC400a Barracuda NG Control Center VC400 Barracuda NG Control Center VC400 - Standard Edition Energize Updates (1Y, 3Y, 5Y) BNCIVC400a-e1,3,5 BNCVC400a-e1,3,5 Premium Support (1Y, 3Y, 5Y) BNCIVC400a-p1,3,5 BNCVC400a-p1,3,5 BNCIVC610a BNCVC610a Barracuda NG Control Center VC610 Barracuda NG Control Center VC610 - Enterprise Edition Energize Updates (1Y, 3Y, 5Y) BNCIVC610a-e1,3,5 BNCVC610a-e1,3,5 Premium Support (1Y, 3Y, 5Y) BNCIVC610a-p1,3,5 BNCVC610a-p1,3,5 Barracuda NG Control Center VC820 Barracuda NG Control Center VC820 - Global Edition BCCIVC820a BCCVC820a Energize Updates (1Y, 3Y, 5Y) BCCIVC820a-e1,3,5 BCCVC820a-e1,3,5 Premium Support (1Y, 3Y, 5Y) BCCIVC820a-p1,3,5 BCCVC820a-p1,3,5 BNCI-b1 BNC-b1 Additional Tenant (Range) for Barracuda NG Control Center VC820 (monthly) Barracuda NG Firewall Energize Updates (1Y, 3Y, 5Y) Barracuda NG Firewall 58 Notes 59 Notes Barracuda NG Firewall Version 1.0 Barracuda Networks, Inc. barracuda.com © Barracuda Networks, Inc. Specifications subject to change without notice. All other brands and names are the property of their respective owners.©All logos, brand names, Inc. campaign statements, and product images contained herein are copyright notare be used and/or of their Barracuda Networks Specifications subject to change without notice, All other brands and andmay names the property reproduced, in whole or innames, part, without express written permission by Barracuda Networks Marketing. respective owners. All logos, brand campaign statements, and product images contained herein are copyright and may not be reprinted and/or reproduced, in whole or in art, without express written permission by Barracuda Networks Marketing.
* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project
advertisement