Barracuda NextGen Firewall F
The Next Generation Firewall for the Cloud-Era
Enterprise networks grow larger and more complex every day - and more critical to key business operations. The Barracuda NextGen Firewall F-Series is an essential tool to optimize the performance, security, and availability of today's dispersed enterprise WANs.
The Barracuda Advantage
Effective WAN Management
- Application-based traffic prioritization across the WAN
- Intelligent uplink balancing
- Intelligent traffic re-prioritization on uplink loss
Enterprise Readiness
- Industry-leading centralized management
- WAN optimization
- Global WAN monitoring with Barracuda Earth
Scalable Security
- Cloud Enablement and secure WAN Virtualization
- Drag-and-drop VPN graphical tunnel interface
Product Spotlight
- Powerful next-generation network firewall
- Advanced Threat Detection
- Built-in web security and IDS/IPS
- Dynamic mesh site-to-site VPN
- Client-to-Site VPN via browser (SSL VPN), mobile apps and desktop VPN clients
- Full application visibility and granular control
- Intelligent traffic regulation including application-based provider selection
- Tightly integrated Quality of Service (QoS) and link balancing
- Centralized management of all functionality
- Template-based and role-based con guration
Integrated Next-Generation Security
The Barracuda NextGen Firewall F-Series is designed and built from the ground up to provide comprehensive, next- generation firewall capabilities. Cloud-hosted content filtering and reporting offload compute-intensive tasks to the cloud for greater resource efficiency and throughput. Based on application visibility, user-identity awareness, intrusion prevention, and centralized management, F-Series is the ideal solution for today?s dynamic enterprises.
Regaining Control of User Activity
The Barracuda NextGen Firewall F-Series restores control to networks made opaque and unmanageable by mobile devices at work, Web 2.0 applications, increasing dispersion, and the growing integration and dependence on cloud- based resources. It extends security coverage beyond network boundaries, and makes it easy to monitor and regulate everything the network and its users are doing.
True Enterprise Readiness
The Barracuda NextGen Firewall F-Series meets the enterprise requirements for massive scalability and e cient management across distributed networks. Integrated WAN optimization and dedicated centralized management appliances
enable organizations to increase system availability while keeping administrative time and operation costs low.
Technical Specs
Firewall
- Stateful packet inspection and forwarding
- Full user-identity awareness
- Intrusion Detection and Prevention System (IDS/IPS)
- Application control and granular application enforcement
- Interception and decryption of SSL/TLS encrypted applications
- Antivirus and web filtering in single pass mode
- SafeSearch enforcement
- Google Accounts Enforcement
- Denial of Service protection (DoS/DDoS)
- Spoofing and flooding protection
- ARP spoofing and trashing protection
- DNS reputation filtering
- Transparent proxying (TCP)
- NAT (SNAT, DNAT), PAT
- Dynamic rules / timer triggers
- Single object-oriented rule set for routing, bridging, and routed bridging
- Virtual rule test environment
|
User Identity Awareness
- Terminal Server Agent
- Domain Controller Agent
- Authentication - supports x.509, NTLM, RADIUS, RSA SecurID, LDAP/LDAPS, Active Directory, TACACS+, SMS Passcode (VPN), local authentication database
- WiFi Access Point Authentication support
Intrusion Detection and Prevention
- Protection against exploits, threats and vulnerabilities
- Packet anomaly and fragmentation protection
- Advanced anti-evasion and obfuscation techniques
- Automatic signature updates
|
Traffic Optimization
- Link monitoring, aggregation, and failover
- Dynamic routing
- Application-based provider selection
- Traffic shaping and QoS
- On-the-fly flow reprioritization
- Stream and packet compression
- Byte-level data deduplication
- Protocol optimization (SMBv2)
|
Advanced Threat Detection
- Dynamic, on-demand analysis of malware programs (sandboxing)
- Dynamic analysis of documents with embedded exploits (PDF, O ce, etc.)
- Detailed forensics for both, malware binaries and web threats (exploits)
- Support for multiple operating systems (Windows, Android, etc.)
- Botnet and Spyware Protection
- Flexible malware analysis in the cloud
|
VPN
- Drag & drop VPN tunnel configuration
- Secure site-to-site, client-to-site VPN
- Dynamic mesh site-to-site VPN
- Supports AES-128/256, 3DES, DES, Blow sh, CAST, null ciphers
- SPrivate CA or external PKI
- VPNC certified (basic interoperability)
- Application-aware traffic routing
- IPsec VPN / SSL VPN / TINA VPN/ L2TP / PPTP
- Network Access Control
- iOS and Android mobile device VPN support
|
Support Options
|
Barracuda Energize Updates
- Standard technical support
- Firmware updates
- IPS signature updates
- Application control definition updates
- Web filter updates
|
Instant Replacement Service
- Replacement unit shipped next business day
- 24/7 technical support
- Free hardware refresh every four years
|
Security Options
- Advanced Threat Detection provides le- type-based protection against advanced malware and cloud-based sandboxing
- Malware Protection
|
MODEL COMPARISON |
F18 |
F80 |
F180 |
F280 |
F380 |
CAPACITY |
Firewall Throughput (Gb/sec) |
1 |
1,35 |
1.65 |
3.0 |
3.8 |
VPN Throughput (Mb/sec)** |
190 |
240 |
300 |
1,000 |
1,200 |
IPS Throughput (Mb/sec) |
400 |
500 |
600 |
1,000 |
1,400 |
Concurrent Sessions |
80.000 |
80.000 |
100.000 |
250.000 |
400.000 |
New session/sec |
8.000 |
8.000 |
9.000 |
10.000 |
15.000 |
Hardware |
Form Factor |
Desktop |
Desktop |
Desktop |
Desktop |
1U |
1GbE Copper NIC |
4x |
4x |
6x |
6x |
8x |
1GbE Fiber NIC(SFP) |
|
|
|
|
|
10GbE Fiber NIC(SFP+) |
|
|
|
|
|
Integrated Switch |
|
|
8-port |
8-port |
|
Wi-Fi Access Point |
|
|
|
|
|
Features |
Firewall |
|
|
|
|
|
Application Control |
|
|
|
|
|
IPS |
|
|
|
|
|
Dynamic Routing |
|
|
|
|
|
App-based Provider Selection |
|
|
|
|
|
VPN |
|
|
|
|
|
SSL Interception |
|
|
|
|
|
WAN Optimization |
|
|
|
|
|
Web Filter |
|
|
|
|
|
Mail Gateway & Spam Filter |
|
|
|
|
|
Malware Protection |
Optional |
Optional |
Optional |
Optional |
Optional |
Advanced Threat Detection |
Optional |
Optional |
Optional |
Optional |
Optional |
Premium Remote Access |
|
Optional |
Optional |
Optional |
Optional |
MODEL COMPARISON |
F400 STD|F20 |
F600 C10|F10|E20 C20|F20| |
F800 CCC|CCF|CCE |
F900 CCC|CCE|CFE |
F1000 CE0|CE2|CFE |
Capacity |
Firewall Throughput (Gb/sec) |
5,5 |
16,3 |
19,6 |
35 |
40 |
VPN Throughput (Gb/sec)** |
1,2 |
2,3 |
7,3 |
9,3 |
10 |
IPS Throughput (Gb/sec) |
2 |
5 |
6,3 |
11,3 |
13 |
Concurrent Sessions (million) |
0,5 |
2,1 |
2,5 |
4 |
10 |
New session/sec |
20.000 |
115.000 |
150.000 |
190.000 |
250.000 |
HARDWARE |
Form Factor |
1U |
1U |
1U |
1U |
2U |
1GbE Copper NIC |
8x|8x |
12x|8x|8x |
20x|12x|12x |
32x|16x|8x |
16x|32x|16x |
1GbE Fiber NIC(SFP) |
---|4x |
---|4x|--- |
---|4x|--- |
---|---|8x |
16x|32x|16x |
10GbE Fiber NIC(SFP+) |
--- |
---|---|2x |
---|---|4x |
---|8x|8x |
4x|8x|8x |
Integrated Switch |
|
|
|
|
|
Wi-Fi Access Point |
|
|
|
|
|
Features |
Firewall |
|
|
|
|
|
Application Control |
|
|
|
|
|
IPS |
|
|
|
|
|
Dynamic Routing |
|
|
|
|
|
App-based Provider Selection |
|
|
|
|
|
VPN |
|
|
|
|
|
SSL Interception |
|
|
|
|
|
WAN Optimization |
|
|
|
|
|
Web Filter |
|
|
|
|
|
Mail Gateway & Spam Filter |
|
|
|
|
|
Malware Protection |
Optional |
Optional |
Optional |
Optional |
Optional |
Advanced Threat Detection |
Optional |
Optional |
Optional |
Optional |
Optional |
Premium Remote Access |
Optional |
Optional |
Optional |
Optional |
Optional |
* Measured with UDP; large packets
** Measured with AES; MD5
|