3
 B  A  R  R  A   C   U   D  A  W E   B  A  P  P  L  I    C  A  T  I    O  N F  I   R  E  W A  L  L  MODEL Barracuda Web Application Firewall Powerul application-lay er security or Web sites and Web servers The Baaua Web Appliati Fiewall ptets Web sites a Web appliatis m attakes leveagig ptl appliati vuleabilities t istigate ata thet, eial sevie, eaemet  a gaizatis Web sit e. Ulike taitial etwk ewalls itusi eteti sstems that simpl pass HTTP, HTTPS, FTP ta Web appliatis, the Baaua Web Appliati Fiewall pxies this ta a ispets it attaks t isulate Web seves m iet aess b hakes. Comprehensive Web Site Protection The Baaua Web Appliati Fiewall pvies awa-wiig pteti m all mm attaks Web appliatis, iluig SQL ijetis, ss-site siptig attaks, sessi tampeig a bue vews. As a ull px, the Baaua Web Appliati Fiewall blks laks attaks, while pevetig sesitive utbu ata leakage suh as eit a Sial Seuit umbes. I aiti, the Baaua Web Appliati Fiewall mitigates bke aess tl t appliatis b pevetig kie tampeig a upti  a appliati’s aess tl sstem. Ulike itusi eteti sstems that l aalze bte pattes, the Baaua Web Appliati Fiewall temiates HTTP ta behal the Web seve t ee haate sets, emve pae spaig, a malize agaist mm busati tehiques. F ae seuit, the Baaua Web Appliati Fiewall pvies ull PKI itegati use with liet etiates t vei ietities liets aessig the Web appliatis. Advanced Trafc Management and Accelerat ion T miimize gig amiistati assiate with ptetig Web sites agaist appliati vuleabilities, the Baaua Web Appliati Fiewall autmatiall eeives Eegize Upates with the latest pli, seuit a attak eitis. I aiti t the mpehesive seuit beets, thee ae als appliati elive apabilities suh as SSL faig, SSL aeleati a la balaig. These apabilities ae esige t impve the pemae, salabilit, a maageabilit ta’s mst emaig ata ete iastutues. Clients Barracuda Energize Updates Barracuda Web Application Firewall Architecture Policy Denitions Logging and Monitoring Secu rity Upd ates Att ack Den itio ns Barracuda Web Application Firewall Web Servers Protocol Termination and Validation Authentication and Authorization Trac Inspection and Security Checks Decryption Data Normalization Load Balancing Caching Encr yp ti on Compr es si on Data Theft Cloaking The Barracuda Web Application Firewall monitors and tracks common application attacks, performance statistics and bandwidth usage.

Barracuda Web App Firewall DS US

Embed Size (px)

Citation preview

Page 1: Barracuda Web App Firewall DS US

8/6/2019 Barracuda Web App Firewall DS US

http://slidepdf.com/reader/full/barracuda-web-app-firewall-ds-us 1/2

Page 2: Barracuda Web App Firewall DS US

8/6/2019 Barracuda Web App Firewall DS US

http://slidepdf.com/reader/full/barracuda-web-app-firewall-ds-us 2/2

MODEL

     B     A     R     R     A     C     U     D

     A     W     E     B     A     P     P     L     I     C     A

     T     I     O     N     F     I     R     E     W     A     L     L

Cpyight © 2011 Baacua Ntwks Inc. • 3175 S. Winchst Bv., Campb, CA 95008 • 1-888-ANTI-SPAM (1-888-268-4772) • www.baacua.c

Web ServerBarracuda Web Application FirewallNetwork FirewallInternet

Typical Deployment

TECHNICAL SPECIFICATIONSKey FeaturesSUPPorTEd WEB ProTocoLS• HTTP/S 0.9/1.0/1.1• FTP/S• XML• IPv6 Read

WEB APPLIcATIon SEcUrITy• OWASP Top-Ten Protection• Protection against common attacks

- SQL Ijeti- oS mma ijeti- css-site Siptig- ckie Fms Tampeig

• Form eld meta data validation• Adaptive securit• Web site cloaking• Response control

- Blk liet- reset eti

- reiet- custm espse

• Outbound data theft protection- ceit a umbes- Sial Seuit umbes- custm patte mathig (egex)

• Granular policies to HTML elements• Protocol limit checks

• File upload control• Brute force protection• Session tracking

AUTHEnTIcATIon AndAUTHorIZATIon• LDAP/RADIUS/local user database• Client certicates• Single Sign-On• RSA SecurID2

• CA SiteMinder2

LOGGING, MONITORING ANDREPORTING• Sstem log• Web Firewall log• Access log• Audit log

SIEM Integrations• ArcSight

rSA EnVISIon• Splunk• Smantec

APPLIcATIon dELIVEry AndAccELErATIon• High availabilit• SSL ooading• Load balancing• Content routing

XML FIREWALL• XML DOS protection• Schema / WSDL enforcement• WS-I conformance checks

System Features• Graphical user interface• Role-based administration

• Secure remote administration• Optional Ethernet bpass• Trusted host exemption• Vulnerabilit scanner integration

Hardware FeaturesconnEcTorS• WAN/LAN/MGMT por ts• Serial Port (DB-9) for console

HArdWArE SECURITy MODUL

• FIPS 140-2 HSM Model AvailabPOWER REQUIREMENTS• AC Input Voltage - 110-240 V A• Frequenc - 50 / 60 Hz

Virtual Appliance Mode• VMware ESX/ESXi• VMware Server/Fusion/

Workstation/Plaer• Citrix Xenserver• Microsoft Hper-V• Oracle VirtualBox

Support Options

• Energize Updates Subscription• Instant Replacement Service

Model CoMPArISoN Model 360 Model 460 Model 660 Model 860 Model 960

CAPACITY*

Bake Seves Suppte

Thughput

HARDWARE

rakmut chassis

dimesis (i)

dimesis (m)

Weight (lbs/kg)

data Path PtsCopper NIC (Standard)

Fiber NIC (Optional) 1

Management Port

Ac Iput cuet (Amps)

ECC Memor

FEATURES

HTTP/HTTPS/FTP Protocol Validation

Pteti Agaist cmm Attaks

Form Field Metadata Validation

Web Site clakig

respse ctl

outbu data Thet Pteti

Granular Policies to HTML Elements

File Upla ctl

Logging, Monitoring and Reporting

High Availabilit

SSL ofaig

Authetiati a Authizati

Vuleabilit Sae Itegati

Centralized Management

cahig a cmpessi

LDAP/RADIUS Integration

La Balaig

ctet rutig

Aaptive Plig

AV File Uplas

XML Firewall

1-5

25 Mbps

1U Mini

16.8 x 1.7 x 14

42.7 x 4.3 x 35.6

12 / 5.4

2 x 10/100

1 x 10/100

1.2

P

P

P

P

P

P

P

P

P

P

P

P

P

P

5-10

50 Mbps

1U Mini

16.8 x 1.7 x 14

42.7 x 4.3 x 35.6

12 / 5.4

2 x Gigabit

1 x 10/100

1.4

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

10-25

100 Mbps

1U Fullsize

16.8 x 1.7 x 22.6

42.7 x 4.3 x 57.4

26 / 11.8

2 x Gigabit

1 x Gigabit

1.8

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

25-150

600 Mbps

2U Fullsize

17.4 x 3.5 x 25.5

44.2 x 8.9 x 64.8

46 / 20.9

2 x Gigabit

2 x Gigabit

1 x Gigabit

4.1

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

150-300

1 Gbps

2U Fullsize

17.4 x 3.5 x 25

44.2 x 8.9 x 64

52 / 23.6

2 x Gigabit

2 x Gigabit

1 x Gigabit

5.4

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

P

US 15.2 Specications subject to change without notice. * Capacit depends on environment and selected 1

Fiber NIC option replaces the standard 2x Copper Gigabit ports with 2x Fiber Gigabit Ports.2

Available on models 660 an