Barracuda CloudGen WAN VT3000:
Barracuda CloudGen WAN provides easy to use secure SD-WAN and Firewall-asa-Service. Everything is centrally managed from one portal regardless how many users, locations, or cloud services need to be secured and connected.
To harness the power of Microsoft Azure and the Azure Global network it is easily deployed directly from the Azure Marketplace. With Barracuda CloudGen WAN you can create a pragmatic SASE solution on your terms.
Traditional data centers are going away
More than ten percent of organizations have already shut theirs down, and Gartner has predicted that will rise to 80 percent by 2025.
Eliminate costly MPLS leased lines
Get fast, effortless access to the Microsoft Global Network backbone for high-performance site-to-site and site-to-cloud connections.
Deploy to all your sites rapidly and easily
Zero-touch deployment for all CloudGen WAN site devices requires no local expertise. Just plug them in and they self-configure.
Fully leverage all your cloud and SaaS solutions
CloudGen WAN eliminates latency and bandwidth shortfalls that can degrade performance of apps you rely on, such as Office 365.
Easy to establish and maintain
CloudGen WAN works out-of-the-box with smart default configurations for cloud and SaaS applications. The CloudGen WAN management portal provides the most intuitive way to centrally orchestrate SD-WAN connectivity, security, and networking with minimal overhead.
In a nutshell: With Barracuda CloudGen WAN you can deploy, secure and manage a global high performance WAN without the need for specialized SD-WAN or expert enterprise firewall knowledge.
The solution extends SD-WAN connectivity and next-generation firewall security beyond users and office locations. Dedicated Industrial IoT and rugged form factor devices for shop and factory floors extend the pragmatic SASE concept to cover users, sites and things.
True cloud native
CloudGen WAN was built from the ground up as a cloud service to provide secure SD-WAN globally. Unlike other solutions in the market, it was not built as a pure-play SD-WAN with attached security and then moved to cloud.
Running natively as a SaaS service, CloudGen WAN establishes a fast overlay SD-WAN backbone automatically. For even better WAN experience, the solution provides an SDWAN enabled on ramp to the Microsoft Global Network. Other than traditional MPLS or Network-as-a-Service solutions, Barracuda CloudGen WAN provides dynamic sizing of networking and security throughput to match your actual workload requirements
Connectivity and security
CloudGen WAN is based on the security technology of Barracuda CloudGen Firewall. Barracuda’s enterprise network firewall is the most secure and most scalable SD-WAN solution available.
CloudGen WAN provides SD-WAN technology formerly only available on dedicated network optimization solutions.
Deploy CloudGen WAN either next to an existing firewall solution or as standalone solution that provides battle-tested network connectivity and security, IPS/ IDS, deep SSL inspection, and Advanced Threat Protection – all built right into the core of the solution.
Features:
Connectivity and SD-WAN
Global secure SD-WAN service
CloudGen WAN brings full SD-WAN functionality to Azure Virtual WAN, Microsoft’s native hybrid cloud service. Secure SD-WAN dynamically selects the most suitable uplink for each application in real time, based on traffic characteristics, available bandwidth, and latency between VPN endpoints. This lets you replace MPLS lines by globally connecting your sites via the Microsoft Global Network, the world’s fasted private network. Purpose-built for the cloud, CloudGen WAN provides seamless, automated access to your business-critical resourses, leveraging a rich feature-set including:
- Adaptive bandwidth protection
- Adaptive session balancing
- Forward error correction (FEC)
- SD-WAN breakout
- Dynamic bandwidth and latency detection
- Performance-based transport selection
- TINA—Barracuda’s proprietary VPN protocol
- Site-to-site connectivity
- Failover link support
- Dynamic quality of service
- WAN compression
Azure Virtual WAN
Directly deployed from Azure marketplace, the CloudGen WAN gateway becomes a part of Microsoft’s Azure Virtual Hub and, together with CloudGen WAN site devices, ensures optimized connectivity from every branch office to the nearest Azure Cloud entry point. Barracuda supports dynamic path selection across multiple ISPs for Azure Virtual WAN, giving you failsafe, always-on cloud connectivity. The close integration with native Azure services seamlessly integrates Barracuda CloudGen WAN into your Azure cloud infrastructure.
Dynamic bandwidth and latency detection
To achieve the best possible user experience across the WAN, CloudGen WAN onsite devices proactively measure the available bandwidths and quality of all internet uplinks and between VPN endpoints. The results are directly available to the security and SD-WAN policy engine to select the best suitable uplink per application or to disqualify an uplink if the bandwidth or latency fall outside of acceptable limits.
Application-based routing
A unique combination of next-generation security and adaptive WAN routing technology allows Barracuda CloudGen WAN to dynamically assign available bandwidth, uplink, and routing information based on protocol, user, location, and content as well as application, application categories, and even web content categories. This keeps expensive, highly available lines free for business- and mission-critical applications, while significantly reducing response times and freeing up additional bandwidth.
Management and Automation
Simple to deploy
CloudGen WAN is easy to set up and does not require specialized IT skills. Directly deployed from Azure marketplace, the service works out of the box with smart default configuration, suitable for all cloud and SaaS applications. CloudGen WAN runs natively as a SaaS service inside one or multiple Azure Virtual WAN regions and provides easy, automated access to the Microsoft Global Network. The service can either be rolled out to all locations as a pure SD-WAN solution alongside existing firewalls or as a secure SD-WAN solution replacing existing firewalls.
Zero-touch site deployment
Zero-touch deployment lets you deploy CloudGen WAN site devices directly from the factory to the desired remote location without requiring on-site IT personnel. Simply connect the unit and power it up. With no need for manual configuration on-site, zero-touch deployment allows you to deploy CloudGen WAN site devices across widely distributed organizations easily, rapidly, and at very low cost.
Simple to operate
Directly managed via the CloudGen WAN management portal for all regions and all sites across your global WAN, regardless of the number of cloud entry points or locations. The central cloud portal offers the highest degree of automation and unparalleled ease of use. CloudGen WAN continuously monitors and optimizes network performance to ensure uninterrupted always-on connectivity and high quality of service levels for your business-critical traffic and applications.
Once only central management
The CloudGen WAN management portal hosts security, networking, and SD-WAN connectivity rules that are applied and enforced automatically across all site devices and endpoints hosted with your CloudGen WAN subscription. Define an SD-WAN or security policy once and CloudGen WAN automatically distributes and enforces it across all locations and users.
Security
Advanced multi-layered security
CloudGen WAN is built on the same technology as CloudGen Firewall, Barracuda’s battle-tested enterprise firewall (“Recommended” in NSS Labs NGFW Group Test 2019). Purpose-built for the cloud, CloudGen WAN provides advanced multi-layered security to protect your business-critical resourses, leveraging a rich feature-set including:
- Advanced Threat Protection
- Intrusion detection and prevention
- Malware protection
- SSL inspection
- Stateful deep packet inspection
- Single pass architecture
- URL filtering--application-based ACL
URL filtering
The URL filtering feature of CloudGen WAN lets you create and enforce effective internet content and access policies by enabling highly granular, real-time visibility into online activity broken down by individual users and applications. It protects user productivity, blocks malware downloads and other web-based threats, and supports compliance by blocking access to unwanted websites and servers, providing an important additional layer of security alongside application control.
Advanced Threat Protection
The malware protection functionality built into Barracuda CloudGen WAN shields the internal network from malicious content by scanning web content (HTTP and HTTPs), email (SMTP, POP3), and file transfers (FTP/SFTP) via integrated malware protection based on Barracuda Advanced Threat Protection. It covers viruses, worms, trojans, malicious java applets, and programs using known exploits on PDF, picture and office documents, macro viruses, and many more, even when using stealth or morphing techniques for obfuscation. Resource-intensive sandboxing is offloaded to the Barracuda ATP Cloud with its multiple datacenters in the Americas, mainland Europe, and the UK. A hash fingerprint of each file and the good/bad classification of all sandboxed files are stored and cached for future use, effectively speeding up processing and guaranteeing near instantaneous results.
SSL interception
Barracuda CloudGen WAN can apply IPS, virus protection, application control, URL filtering, and even Advanced Threat Protection to SSL-encrypted web traffic using the standard 'trusted man-in-the-middle' approach. SSL interception can be fine-tuned to exempt local networks, users/groups, URL filter categories, or custom defined domains from SSL inspection.
SASE
Practical SASE
Barracuda CloudGen WAN provides a practical SASE solution that is easy to deploy in Azure. While other SASE vendors use their own cloud and their own network, CloudGen WAN allows leveraging the global presence and power of Azure data centers and Microsoft’s global network. For all organizations leveraging Azure or planning to adopt Azure it makes perfect sense to deploy a SASE offering on the same public cloud platform.
For organizations having certain geopolitical requirements or using applications requiring an organization’s IP address as source IP address, every CloudGen WAN site device serves as a private enforcement node for SWG, FWaaS enforcement and as entry point to the cloud service for remote endpoints. The SASE enforcement points in Azure, as well as the private enforcement points on the site devices, are controlled by security policies defined centrally in the CloudGen WAN management portal, without requiring administrators to know where the traffic enters the service.