Barracuda BARRACUDA NETWORKS

Barracuda Networks • DATASHEET • Barracuda CloudGen Firewall F-Series NETWORK SECURITY Barracuda CloudGen Firewall F-Series Protect cloud-connected users, network workloads,

Barracuda CloudGen Firewall F-Series - Barracuda Networks

As you integrate public-cloud platforms and environments into your network, your firewalls must go beyond perimeter security and serve as the linchpins of your.

PDF barracuda cloudgen firewall
DATASHEET

Barracuda CloudGen Firewall F-Series
Protect cloud-connected users, network workloads, and devices wherever they reside.
As you integrate public-cloud platforms and environments into your network, your firewalls must go beyond perimeter security and serve as the linchpins of your IT communications flow, ensuring reliable, cost-effective connections. Barracuda CloudGen Firewall was designed to optimize the performance, security, and availability of today's dispersed enterprise SD-WANs.
Barracuda CloudGen Firewall combines a complete security stack, powerful SDWAN capabilities, and simple centralized management for hundreds or thousands of firewalls. Zero-touch hardware deployment and native cloud integration get you up and running quickly and easily in any environment.

BARRACUDA NETWORKS
CloudGen Firewall F800.CCE v7.2.3 NEXT GENERATION FIREWALL
RECOMMENDED
JULY 2019
BARRACUDA NETWORKS
Barracuda CloudGen Firewall F82 v7.2.3 SOFTWARE DEFINED WIDE AREA NETWORK
RECOMMENDED
JUNE 2019

Full next-generation security
Barracuda CloudGen Firewall is built to provide comprehensive, next-generation firewall protection. Firewalling, IPS, URL filtering, dual antivirus, and application control take place in the data path. Sandboxing and other resourceintensive tasks are offloaded seamlessly to the cloud. All platforms and models include the same comprehensive security feature-set.

Secure SD-WAN connectivity
In the cloud era, you need to connect branch offices with the cloud directly and securely. Connecting through a single, central gateway is costly and renders cloud based applications unresponsive. Optimized direct internet uplink selection ensures fast cloud-hosted SaaS applications. CloudGen Firewall lets you replace costly MPLS connections with up to 24 bonded broadband connections per VPN tunnel for increased application performance and built-in redundancy.

Cloud automation
The big advantage of going to the cloud is greater agility and flexibility. This requires high degrees of automation. All components, including the infrastructure for security and connectivity, need to adapt to the way this works. CloudGen Firewall provides fully automated protection across multi-cloud deployments, including VPN automation across multiple cloud providers, on-site and virtual.

Barracuda Networks · DATASHEET · Barracuda CloudGen Firewall F-Series

NETWORK SECURITY

Technical specs
Firewall
· Stateful packet inspection and forwarding
· Full user-identity awareness · IDS/IPS · Application control and granular
application enforcement · Interception and decryption of
SSL/TLS encrypted applications · Antivirus and web filtering in
single pass mode · Email security · SafeSearch enforcement · Google Accounts Enforcement · Denial of Service protection
(DoS/DDoS) · Spoofing and flooding protection · ARP spoofing and trashing protection · DNS reputation filtering · NAT (SNAT, DNAT), PAT · Dynamic rules / timer triggers · Single object-oriented rule set for
routing, bridging, and routed bridging · Virtual rule test environment
Protocol support
· IPv4, IPv6 · BGP/OSPF/RIP · VoIP (H.323, SIP, SCCP [skinny]) · RPC protocols (ONC-RPC, DCE-RPC) · 802.1q VLAN · Industrial protocols and
subprotocols (S7, S7+, IEC 60870-5104, IEC 61850, MODBUS, DNP3)
Intrusion detection and prevention
· Protection against exploits, threats and vulnerabilities
· Packet anomaly and fragmentation protection
· Advanced anti-evasion and obfuscation techniques
· Automatic signature updates
Infrastructure services
· DHCP server, relay · SIP and HTTP proxies · SNMP and IPFIX support · JSON lifecycle automation API · Auto VPN via API and script control · Authoritative DNS server · DNS server · DNS cache · Wi-Fi (802.11n) on selected models · Built-in support for · Azure Virtual WAN

VPN & Zero Trust Access
· Drag & drop VPN tunnel configuration · Network access control · iOS and android mobile device
VPN support · Two-factor authentication via time-
based one-time passwords (TOTP), Radius, or RSA MFA (requires an active Advanced Remote Access subscription) for VPN / NAC clients · Multi-factor authentication for SSL VPN and CudaLaunch · Barracuda CloudGen Access Proxy for Zero Trust Access to applications (requires an active Advanced Remote Access subscription)
Advanced threat protection
· Dynamic, on-demand analysis of malware programs (sandboxing)
· Dynamic analysis of documents with embedded exploits (PDF, Office, etc.)
· Detailed forensic analysis · Botnet and spyware protection · TypoSquatting and link protection
for email
Central management options via Barracuda Firewall Control Center
· Administration for unlimited firewalls · Support for multi-tenancy · Multi-administrator support & RCS · Zero-touch deployment · Enterprise/MSP licensing · Template & repository-based
management · REST API
High Availability
· Active-passive · Transparent failover without
session loss · Encrypted HA communication

Traffic intelligence & SD-WAN
· Optimized direct internet uplink selection
· VPN-based SD-WAN · Simultaneous use of multiple uplinks
(transports) per VPN tunnel · FIPS 140-2 certified cryptography · On-demand direct VPN tunnel
creation between remote spoke locations based on application type · Dynamic bandwidth detection · Performance-based transport selection · Application-aware traffic routing · Adaptive session balancing across multiple uplinks · Traffic replication (forward error correction) · Application-based provider selection · Application-aware traffic routing (VPN) · Traffic shaping and QoS · Built-in data deduplication
Support options
Barracuda Energize Updates
· Standard technical support · Firmware updates · IPS signature updates · Application control definition updates · Web filter updates
Instant Replacement Service
· Replacement unit shipped next business day
· 24/7 technical support · Free hardware refresh every
four years

Available subscriptions
Barracuda Firewall Insights Consolidates security, application flow, and connectivity information from hundreds or even thousands of firewalls on the extended wide area network ­ regardless of whether they are hardware, virtual, or cross-cloudbased deployments.
Malware Protection Provides gateway-based protection against malware, viruses, spyware, and other unwanted programs inside SMTP/S, HTTP/S, and FTP/S traffic.
Advanced Threat Protection Prevents from network breaches, identifies zero-day malware exploits, targeted attacks, advanced persistent threats and other advanced malware.
Advanced Remote Access Provides a customizable and easy-touse portal-based SSL VPN as well as sophisticated network access control (NAC) functionality and CudaLaunch support. This subscription is required to enable the Barracuda CloudGen Access Proxy service on CloudGen Firewall deployments.

Barracuda CloudGen Firewall's SD-WAN dashboard provides real-time information and summaries of what is going on in an organization's network.
Barracuda Networks · DATASHEET · Barracuda CloudGen Firewall F-Series

NETWORK SECURITY

Basic features
Firewall incl. IPS Application control Dynamic routing Application-based provider selection SSL interception SD-WAN Cloud connectivity automation with Azure Virtual WAN Web filter Zero-touch deployment Client-to-site and site-to-site VPN

ENTRY AND BRANCH OFFICE / RUGGED      

  Unlimited

MID-RANGE      

  Unlimited

HIGH-END      

  Unlimited

Optional features
Firewall Insights Advanced threat protection Malware protection Advanced remote access

ENTRY AND BRANCH OFFICE / RUGGED Optional Optional Optional 1 Optional 2

MID-RANGE Optional Optional Optional Optional

HIGH-END Optional Optional Optional Optional

Entry & branch office / rugged models

PERFORMANCE Firewall throughput 3 VPN throughput 4 IPS throughput 5 NGFW throughput 6 Threat protection throughput 7 Concurrent sessions New session/s HARDWARE
Form factor
Copper ethernet NICs [1 GbE] Fiber ethernet NICs (SFP) [1 GbE] Integrated switch
Integrated modem
Wi-Fi access point

ENTRY AND BRANCH OFFICE

F12A

F18B

F80B

F82A.DSLA F180A

F183A

F280C

1.2 Gbps 220 Mbps 400 Mbps 250 Mbps 230 Mbps 80,000 8,000

2.0 Gbps 720 Mbps 600 Mbps 400 Mbps 380 Mbps 80,000 12,000

2.0 Gbps 720 Mbps 600 Mbps 400 Mbps 380 Mbps 80,000 12,000

1.5 Gbps 240 Mbps 400 Mbps 240 Mbps 380 Mbps 80,000 8,000

1.7 Gbps 300 Mbps 500 Mbps 550 Mbps 480 Mbps 100,000 9,000

2.0 Gbps 300 Mbps 580 Mbps 700 Mbps 600 Mbps 100,000 9,000

6.0 Gbps 1.8 Gbps 2.0 Gbps 1.6 Gbps 1.5 Mbps 300,000 12,000

Compact 5x -

Desktop 5x -

Desktop 5x 

Desktop
4x 1x Annex A, RJ11 

Desktop 6x 8-port 

Desktop 6x 2x 

Desktop 12x 4x 

Power supply

Single, external

Single, external

Single, external

Single, external

Single, external

Single, external

Single, external

RUGGED F93A

F183RA

1.5 Gbps 240 Mbps 400 Mbps 400 Mbps 380 Mbps 80,000 8,000

2.1 Gbps 320 Mbps 790 Mbps 800 Mbps 700 Mbps 100,000 9,000

Compact, DIN rail 2x 1x -
-
Phoenix 4-pin or dual, external

Compact, DIN rail 5x 2x -
-
Phoenix 6-pin or dual, external

Barracuda Networks · DATASHEET · Barracuda CloudGen Firewall F-Series

NETWORK SECURITY

Mid-range models
PERFORMANCE Firewall throughput 3 VPN throughput 4 IPS throughput 5 NGFW throughput 6 Threat protection throughput 7 Concurrent sessions New session/s HARDWARE Form factor Copper ethernet NICs [1 GbE] Fiber ethernet NICs (SFP) [1 GbE] Fiber ethernet NICs (SFP+) [10 GbE]
Power supply

F400C SUBMODELS

F600D SUBMODELS

F380B

STD

F20

C10

C20

F10

F20

E20

8.5 Gbps 2.1 Gbps 2.5 Gbps 2.0 Gbps 1.7 Gbps 400,000 15,000

13 Gbps 3.6 Gbps 4.2 Gbps 3.7 Gbps 3.1 Gbps 500,000 20,000

13 Gbps 3.6 Gbps 4.2 Gbps 3.7 Gbps 3.1 Gbps 500,000 20,000

15 Gbps 3.8 Gbps 4.8 Gbps 4.2 Gbps 4.0 Gbps 2,100,000 115,000

15 Gbps 3.8 Gbps 4.8 Gbps 4.2 Gbps 4.0 Gbps 2,100,000 115,000

20 Gbps 6.8 Gbps 8.0 Gbps 6.4 Gbps 5.8 Gbps 2,100,000 115,000

1U rack mount 1U rack mount

8x

8x

8x

-

-

4x

2x

2x

2x

Single, internal

Single, internal

Dual, hot swap

1U rack mount

18x

18x

-

-

-

-

Single, internal

Dual, hot swap

10x 8x Single, internal

10x 8x Dual, hot swap

10x 8x 2x Dual, hot swap

High-end models
PERFORMANCE Firewall throughput 3 VPN throughput 4 IPS throughput 5 NGFW throughput 6 Threat protection throughput 7 Concurrent sessions New session/s HARDWARE Form factor Copper ethernet NICs [1 GbE] Fiber ethernet NICs (SFP) [1 GbE] Fiber ethernet NICs (SFP+) [10 GbE] Fiber ethernet NICs (QSFP+) [40 GbE] Power supply

F800C SUBMODELS

CCC

CCF

CCE

F900B SUBMODELS

CCC

CCE

CFE

30 Gbps 7.5 Gbps 8.3 Gbps 7.7 Gbps 7.6 Gbps 2,500,000 180,000

35 Gbps 9.3 Gbps 11.3 Gbps 8.0 Gbps 8.0 Gbps 4,000,000 190,000

1U rack mount

1U rack mount

24x

16x

16x

32x

16x

8x

-

8x

-

-

-

8x

-

-

4x

-

8x

8x

-

-

-

-

-

-

Dual hot swap

Dual hot swap

CFEQ

F1000A SUBMODELS

CE0

CE2

CFE

45 Gbps 40 Gbps 13.5 Gbps 10 Gbps 13 Gbps 13 Gbps 12 Gbps 10.2 Gbps 11.5 Gbps 4.0 Gbps 4,000,000 10,000,000 190,000 250,000

2U rack mount

8x

16x

32x

16x

8x

-

-

16x

4x

4x

8x

8x

2x

-

-

-

Dual hot swap

All performance values are measured under optimized conditions and are to be considered as "up to" values and may vary depending on system configuration and infrastructure: 1 For model F12A, malware protection utilizes cloud-based malware protection as part of an active Advanced Threat Protection subscription. 2 For model F12A, this feature is not available. 3 Firewall throughput measured with large packets (MTU1500) UDP packets, bi-directional across multiple ports, utilizing highest available port density. 4 VPN performance is based on 1415 Byte UDP packets, bidirectional using BreakingPoint traffic generator. 5 IPS throughput is measured using large packets (MTU1500) UDP traffic and across multiple ports, utilizing highest available port density. 6 NGFW throughput is measured with IPS, application control, and web filter enabled, based on BreakingPoint Realworld-IPS-
Enterprise-Traffic-Mix, bidirectional across multiple ports, utilizing highest available port density. 7 Threat protection throughput is measured with IPS, application control, web filter, antivirus, and SSL inspection enabled,
based on BreakingPoint Realworld-IPS-Enterprise-Traffic-Mix, bidirectional across multiple ports. Specifications subject to change without notice.

CFEQ
46 Gbps 10.3 Gbps 14 Gbps 13 Gbps 12 Gbps 10,000,000 250,000
16x 16x 6x 2x

DATASHEET · US 3.5 · Copyright 2020 Barracuda Networks, Inc. · 3175 S. Winchester Blvd., Campbell, CA 95008 · 408-342-5400/888-268-4772 (US & Canada) · barracuda.com Barracuda Networks and the Barracuda Networks logo are registered trademarks of Barracuda Networks, Inc. in the United States. All other names are the property of their respective owners.


Adobe PDF Library 15.0 Adobe InDesign 16.0 (Windows)