Datasheet

22
Barracuda NG Firewall
Network Access Clients
Network Access Clients
for the Barracuda NG Firewall
Every Barracuda NG Firewall unit supports an unlimited number of VPN
clients at no extra cost. The optional Barracuda NG Firewall SSL VPN and NAC
subscription adds a customizable and easy-to-use web-based SSL VPN as well
as sophisticated Network Access Control (NAC) functionality.
NAC allows enforcement of minimum Windows client security prerequisites
before being allowed access to the network or access to a quarantine network.
Security posture can be specified according to available Windows patch level,
availability of anti-virus and/or anti-spyware, and user ID. Access restrictions
are enforced locally on the client by the centrally managed personal Windows
firewall as well as at the gateway.
IPv6 SECURITY ENFORCEMENT
Besides providing full IPv6 support for the personal firewall, the Barracuda
Network Access Client also introduces IPv6 Router Advertisement Guard,
which monitors and controls IPv6 Router Advertisement (RA) messages of
the IPv6 Neighbor Discovery Protocol. This effectively enables companies to
protect against potential denial of service, Man-in-the-Middle, and malformed
RA message attacks. Rogue Internet access points that may be appearing
when using smartphones or other 3G devices connected to client machines
are no longer advertised and thus sealed from the network.
Using existing Barracuda NG Firewall appliances, Barracuda Networks offers
a ready-to-use Network Access Control framework without expensive
investments into the basic network infrastructure.
All Barracuda Network Access Clients, as well as all Barracuda NG Firewall units
acting as policy servers can be administered, monitored, and reviewed from a
single Barracuda NG Control Center.
If the Barracuda NG Firewall is deployed as virtual appliance, then the
respective capacity counter is used, e.g., the Barracuda NG Firewall VF25
provides up to 25 VPN clients, the Barracuda NG Firewall VF50 provides up to
50 VPN clients, and so on.
KEY BENEFITS
• Network Access based on client health
status, patch level, or presence and update
status of antivirus/anti-spyware options
• Blocks or quarantines unhealthy or
unknown clients
• Provides the ability to create guest
networks with limited or specially defined
connectivity policies
• Auto-remediation functionality makes
sure antivirus/anti-spyware options at the
client are up to date
Integrated Personal Firewall to enforce
access restriction rules for programs and
users
Endpoint IPv6 Router Advertisement Guard
• Provides reporting on client health status
• Provides reporting on client VLAN & port
connection locations
Compatible with