Barracuda CloudGen Firewall F-Series
The Next-Generation Firewall for the Cloud-Era
Security
Data Protection
As you integrate a growing number of public-cloud platforms and environments Application Delivery
into your network, your firewalls have to do more than just secure your perimeter.
They also have to serve as the linchpin of your IT communications flow, ensuring
highly reliable and cost-effective connections. Barracuda CloudGen Firewall
was designed to optimize performance, security, and availability of today's
dispersed enterprise SD-WANs.
The Barracuda Advantage Product Spotlight
ENTERPRISE ADVANCED
• Simple pricing with no per-application • Full user/group awareness THREAT DEFENSE
or per-user/group licensing fees. • Full application visibility and granular access control
• Unlimited site-to-site and client-to-site VPN included • Advanced Threat Protection (incl. sandboxing)
• Deploy the way you want: hardware, virtual, or cloud • Built-in web security and IDS/IPS
• Configuration and lifecycle management • Full SD-WAN capabilities included
via one graphical user interface without the
need for a command-line interface • Cloud-ready application-based provider selection
Full Next-Generation Security Connecting The Dots
Barracuda CloudGen Firewall is designed and built from Barracuda CloudGen Firewall combines next-generation
the ground up to provide comprehensive, next-generation security and SD-WAN capabilities in one product that
firewall protection. Firewalling, IPS, URL filtering, dual that you can manage centrally using an intuitive, single-
antivirus and application control take place directly in the pane-of-glass solution. This lets you access the benefits
data path. More resource-intensive tasks like sandboxing — of the cloud safely, and to optimize cloud access from
required for protecting against ransomware—are seamlessly anywhere in the network. Low line costs and efficient
integrated in the cloud. All CloudGen Firewall platforms administration help to reduce operating costs significantly.
and models provide the same level of security, maintaining
maximum security from branch offices to headquarters.
Full SD-WAN Capability
In the cloud era, you need to connect branch offices with
the cloud in a direct and secure way. Backhauling traffic to
the central Internet gateway using MPLS can be very cost-
intensive. Barracuda CloudGen Firewalls let you replace
costly MPLS connections with cost-efficient broadband
connections. You can utilize up to 24 broadband connections Barracuda CloudGen Firewall's dashboard provides real-time information
per VPN tunnel for increased bandwidth at lower cost. and summaries of what is going on in an organization's network.
Barracuda CloudGen Firewalls are the perfect solution for central management, especially when it comes to distributed Alexander Maute
environments like ours. Performance problems? Not anymore! Director IT Infrastructure
Eissmann Group Automotive
Barracuda Networks • Barracuda CloudGen Firewall F-Series: The Next-Generation Firewall for the Cloud-Era
Technical Specs Support Options
Firewall Intrusion Detection and Prevention Traffic Intelligence & SD-WAN Barracuda Energize Updates
• Stateful packet inspection and forwarding • Protection against exploits, • Simultaneous use of multiple uplinks • Standard technical support
• Full user-identity awareness threats and vulnerabilities (transports) per VPN tunnel • Firmware updates
• IDS/IPS • Packet anomaly and • FIPS 140-2 certified cryptography • IPS signature updates
• Application control and granular fragmentation protection • Auto-VPN tunnel creation between remote • Application control definition updates
application enforcement • Advanced anti-evasion and spoke locations based on application type • Web filter updates
• Interception and decryption of SSL/ obfuscation techniques • Dynamic bandwidth detection Instant Replacement Service
TLS encrypted applications • Automatic signature updates • Performance-based transport selection • Replacement unit shipped
• Antivirus and web filtering • Application-aware traffic routing next business day
Advanced Threat Protection
in single pass mode • Adaptive session balancing • 24/7 technical support
• Dynamic, on-demand analysis of
• Email security across multiple uplinks • Free hardware refresh every four years
malware programs (sandboxing)
• SafeSearch enforcement • Traffic Replication (forward error correction)
• Dynamic analysis of documents with
• Google Accounts Enforcement • Application-based provider selection
• Denial of Service protection (DoS/DDoS)
embedded exploits (PDF, Office, etc.)
• Application-aware traffic routing (VPN)
Available Bundles
• Detailed forensic analysis • Advanced Threat and Malware
• Spoofing and flooding protection • Traffic shaping and QoS
• Botnet and spyware protection Protection combines gateway-based
• ARP spoofing and trashing protection • Built-in data deduplication
• TypoSquatting and link protection for email protection against malware, viruses with
• DNS reputation filtering
VPN Advanced Threat Protection's sandboxing
• NAT (SNAT, DNAT), PAT Central Management Options via
• Drag & drop VPN tunnel configuration to protect against network breaches,
• Dynamic rules / timer triggers Barracuda Firewall Control Center
• Network Access Control zero-day malware exploits and other
• Single object-oriented rule set for • Administration for unlimited firewalls
• iOS and Android mobile advanced malware like ransomware.
routing, bridging, and routed bridging • Support for multi-tenancy
device VPN support • Advanced Remote Access provides a
• Virtual rule test environment • Multi-administrator support & RCS
• Multi-factor authentication for customizable and easy-to-use portal-
• Zero-Touch Deployment
Protocol Support SSL VPN and CudaLaunch based SSL VPN as well as sophisticated
• Enterprise/MSP licensing
• IPv4, IPv6 Network Access Control (NAC)
• Template & repository-based management Infrastructure Services
• BGP/OSPF/RIP functionality and CudaLaunch support.
• REST API • DHCP server, relay
• VoIP (H.323, SIP, SCCP [skinny]) • Total Protect bundles the hardware
• SIP, HTTP, SSH, FTP proxies
• RPC protocols (ONC-RPC, DCE-RPC) High Availability unit with Energize Updates, Application
• SNMP and IPFIX support
• 802.1q VLAN • Active-passive Control, IPS, Web Filter, Malware
• DNS Cache
• Transparent failover without session loss Protection, Email Security, Warranty
• Wi-Fi (802.11n) on selected models
• Encrypted HA communication Extension, and 8x5 basic support.
• Total Protect PLUS adds Advanced
Threat and Malware Protection,
Advanced Remote Access, and 24x7
support to Total Protect bundle.
ENTRY AND BRANCH OFFICE MODELS F18 F80 F82.DSLA F180 F183 F280
PERFORMANCE
Firewall Throughput 1 1.0 Gbps 1.35 Gbps 1.35 Gbps 1.65 Gbps 2.0 Gbps 3.7 Gbps
VPN Throughput 2 190 Mbps 240 Mbps 240 Mbps 300 Mbps 300 Mbps 780 Mbps
IPS Throughput 3 400 Mbps 500 Mbps 500 Mbps 600 Mbps 600 Mbps 1.0 Gbps
NGFW Throughput 4 300 Mbps 400 Mbps 400 Mbps 550 Mbps 550 Mbps 1.0 Gbps
Threat Protection Throughput 5 320 Mbps 420 Mbps 420 Mbps 480 Mbps 480 Mbps 900 Mbps
Concurrent Sessions 80,000 80,000 80,000 100,000 100,000 250,000
New Session/s 8,000 8,000 8,000 9,000 9,000 10,000
HARDWARE
Form Factor Desktop Desktop Desktop Desktop Desktop Desktop
Copper Ethernet NICs 4x1 GbE 4x1 GbE 4x1 GbE 6x1 GbE 6x1 GbE 6x1 GbE
Fiber NICs (SFP) - - 1x1 GbE - 2x1 GbE -
Integrated Switch - - - 8-port - 8-port
Wi-Fi Access Point - • • • • •
Power Supply Single, external Single, external Single, external Single, external Single, external Single, external
FEATURES
Firewall incl. IPS • • • • • •
Application Control • • • • • •
Dynamic Routing • • • • • •
Application-based Provider Selection • • • • • •
Client-to-Site and Site-to-Site VPN (unlimited) • • • • • •
SSL Interception • • • • • •
SD-WAN • • • • • •
Web Filter • • • • • •
Zero-Touch Deployment • • • • • •
Advanced Threat and Malware Protection Optional Optional Optional Optional Optional Optional
Advanced Remote Access Optional Optional Optional Optional Optional Optional
Total Protect Optional Optional Optional Optional Optional Optional
Total Protect PLUS Optional Optional Optional Optional Optional Optional
Barracuda Networks • Barracuda CloudGen Firewall F-Series: The Next-Generation Firewall for the Cloud-Era
F400 F600
MID-RANGE MODELS F380 SUBMODELS SUBMODELS
STD F20 C10 C20 F10 F20 E20
PERFORMANCE
Firewall Throughput 1 4.8 Gbps 5.5 Gbps 6.0 Gbps 16.3 Gbps
VPN Throughput 2 810 Mbps 1.2 Gbps 1.2 Gbps 2.3 Gbps
IPS Throughput 3 1.6 Gbps 2.0 Gbps 2.0 Gbps 5.0 Gbps
NGFW Throughput 4 1.4 Gbps 1.2 Gbps 1.7 Gbps 4.6 Gbps
Threat Protection Throughput 5 1.2 Gbps 800 Mbps 1.6 Gbps 1.9 Gbps
Concurrent Sessions 400,000 500,000 500,000 2,100,000
New Session/s 15,000 20,000 20,000 115,000
HARDWARE
Form Factor 1U rack mount 1U rack mount 1U rack mount
Copper Ethernet NICs 8x1 GbE 8x1 GbE 8x1 GbE 12x1 GbE 12x1 GbE 8x1 GbE 8x1 GbE 8x1 GbE
Fiber NICs (SFP) - - 4x1 GbE - - 4x1 GbE 4x1 GbE -
Fiber NICs (SFP+) - - - - - - - 2x10 GbE
Power Supply Single, internal Single, internal Dual Hot Swap Single Internal Dual Hot Swap Single, internal Dual Hot Swap Dual Hot Swap
FEATURES
Firewall incl. IPS • • • • • • • •
Application Control • • • • • • • •
Dynamic Routing • • • • • • • •
Application-based Provider Selection • • • • • • • •
Client-to-Site and Site-to-Site VPN (unlimited) • • • • • • • •
SSL Interception • • • • • • • •
SD-WAN • • • • • • • •
Web Filter • • • • • • • •
Zero-Touch Deployment • • • • • • • •
Advanced Threat and Malware Protection Optional Optional Optional Optional Optional Optional Optional Optional
Advanced Remote Access Optional Optional Optional Optional Optional Optional Optional Optional
Total Protect Optional Optional Optional Optional Optional Optional Optional Optional
Total Protect PLUS Optional Optional Optional Optional Optional Optional Optional Optional
F800 F900 F1000
HIGH-END MODELS SUBMODELS SUBMODELS SUBMODELS
CCC CCF CCE CCC CCE CFE CFEQ CE0 CE2 CFE
PERFORMANCE
Firewall Throughput 1 30 Gbps 35 Gbps 45 Gbps 40 Gbps
VPN Throughput 2 7.5 Gbps 9.3 Gbps 12 Gbps 10 Gbps
IPS Throughput 3 8.3 Gbps 11.3 Gbps 13 Gbps 13 Gbps
NGFW Throughput 4 7.0 Gbps 8.0 Gbps 12 Gbps 10.2 Gbps
Threat Protection Throughput 5 7.6 Gbps 8.0 Gbps 11.5 Gbps 4.0 Gbps
Concurrent Sessions 2,500,000 4,000,000 4,000,000 10,000,000
New Session/s 180,000 190,000 190,000 250,000
HARDWARE
Form Factor 1U rack mount 1U rack mount 2U rack mount
Copper Ethernet NICs 24x1 GbE 16x1 GbE 16x1 GbE 32x1 GbE 16x1 GbE 8x1 GbE 8x1 GbE 16x1 GbE 32x1 GbE 16x1 GbE
Fiber NICs (SFP) - 8x1 GbE - - - 8x1 GbE 8x1 GbE - - 16x1 GbE
Fiber NICs (SFP+) - - 4x10 GbE - 8x10 GbE 8x10 GbE 4x10 GbE 4x10 GbE 8x10 GbE 8x10 GbE
Fiber NICs (QSFP+) - - - - - - 2x40 GbE - - -
Power Supply Dual Hot Swap Dual Hot Swap Dual Hot Swap
FEATURES
Firewall incl. IPS • • • • • • • • • •
Application Control • • • • • • • • • •
Dynamic Routing • • • • • • • • • •
Application-based Provider Selection • • • • • • • • • •
Client-to-Site and Site-to-Site VPN (unlimited) • • • • • • • • • •
SSL Interception • • • • • • • • • •
SD-WAN • • • • • • • • • •
Web Filter • • • • • • • • • •
Zero-Touch Deployment • • • • • • • • • •
Advanced Threat and Malware Protection Optional Optional Optional Optional Optional Optional Optional Optional Optional Optional
Advanced Remote Access Optional Optional Optional Optional Optional Optional Optional Optional Optional Optional
Total Protect Optional Optional Optional Optional Optional Optional Optional Optional Optional Optional
Total Protect PLUS Optional Optional Optional Optional Optional Optional Optional Optional Optional Optional
All performance values are measured under optimized conditions and are to be considered as „up to“ values and may vary depending on system configuration and infrastructure:
1
Firewall throughput measured with large packets (MTU1500) UDP packets, bi-directional across multiple ports, utilizing highest available port density.
2
VPN performance is based on Barracuda TINA VPN protocol, 1415 Byte UDP packets using AES128 NOHASH, bidirectional using BreakingPoint traffic generator.
3
IPS throughput is measured using large packets (MTU1500) UDP traffic and across multiple ports, utilizing highest available port density.
4
NGFW throughput is measured with IPS, application control, and web filter enabled, based on BreakingPoint Realworld-IPS-Enterprise-Traffic-Mix, bidirectional across multiple ports, utilizing highest available port density.
5
Threat Protection throughput is measured with IPS, application control, web filter, and antivirus enabled, based on BreakingPoint Realworld-IPS-Enterprise-Traffic-Mix, bidirectional across multiple ports.
Specifications subject to change without notice.
Datasheet US 1.0 • Copyright © Barracuda Networks, Inc. • 3175 S. Winchester Blvd., Campbell, CA 95008 • 408-342-5400/888-268-4772 (US & Canada) • www.barracuda.com
Barracuda Networks and the Barracuda Networks logo are registered trademarks of Barracuda Networks, Inc. in the United States. All other names are the property of their respective owners.