Datasheet
46
Barracuda NG Firewall
Features & Capabilities
MODEL F10
F100
F101
F200
F201
F280
F300
F301
F400
F600
F800
F900
VIRTUAL
APPLIANCES
INTRUSION PREVENTION SYSTEM CONTINUED
TCP stream segmentation check
l l l l l l l
URL obfuscation check
l l l l l l l
FTP evasion check
l l l l l l l
RPC defragmentation check
l l l l l l l
HTML decoding - - -
l
-
l l
HTML decompression - - -
l
-
l l
Regular online pattern updates
l l l l l l l
IPS exception (whitelisting)
l l l l l l l
ROUTING, NETWORKING
HA capable with transparent session failover
l l l l l l l
GbE ethernet support
l l l l l l l
Max number of physical interfaces 4 4 4 4 8
F400: 8
F600: 12
F800: 20
F900: 24
n/a
802.1q VLAN support
l l l l l l l
xDSL support (PPPoE, PPTP (multi-link))
l l l l l l l
3G/UMTS/HSDPA/HSUPA Barracuda 3G/UMTS USB Modem M10 -
DHCP client support
l l l l l l l
ISDN support (EuroISDN (syncppp, rawip)) -
l l l l
- -
Link monitoring (DHCP, 3G/UMTS, xDSL, ISDN)
l l l l l l l
Policy routing support
l l l l l l l
Ethernet channel bonding
l l l l l l l
Multiple networks on interface, IP aliases
l l l l l l l
Multiple provider / WAN link support
l l l l l l l
Configurable MTU size (per route)
l l l l l l l
Jumbo Frames (up to 8,000 bytes)
l l l l l l l
IPinIP and GRE tunnels
l l l l l l l
PPTP
l l l l l l l
BGP
l l l l l l l
Dynamic VPN routing
l l l l l l l
Integrated OSPF/RIP router
l l l l l l l
TRAFFIC MANAGEMENT
Maximum overall bandwidth per interface
l l l l l l l
On-the-fly reprioritisation via via firewall status GUI
l l l l l l l
Ingress shaping per interface
l l l l l l l
CENTRAL USER AUTHENTICATION
Supported services VPN, FW, HTTP Proxy VPN, FW, HTTP/FTP/SSH Proxy
Authentication methods MS NTLM, MS CHAP, RADIUS, RSA SecurID, LDAP/LDAPS, MS Active Directory, TACACS+, local
VPN
Encryption support (AES-128/256, 3DES, DES, Null)
l l l l l l l
Cryptohardware acceleration (VIA Padlock)
l l l
-
l
- -
Private CA (up to 4,096 bit RSA)
l l l l l l l
External PKI support
l l l l l l l
x.509v3 policy extensions (Fully recognised)
l l l l l l l
Certificate revocation (OCSP, CRL)
l l l l l l l
Site-to-site VPN with traffic intelligence
l l l l l l l
WAN traffic compression via data deduplication - -
l l l l l
Star (hub and spoke) VPN network topology
l l l l l l l