Internet Security

Skip to Main Content »

Have a Question? Call Us!
Toll Free: 866.892.5081

Welcome to BarracudaStore.com.

You're currently on:

Barracuda Web Application Firewall

Defends Web Sites and Web Applications From Attacks.

Barracuda Application Firewall
Request A Trial Unit of Barracuda Application Firewall

The Barracuda Application Firewall provides superior protection against hackers' attempts to exploit vulnerabilities in Web sites or Web applications to steal data, cause denial of service or deface Web sites.

At A Glance
» Comprehensive Web Site Protection
» Application Access Control
» Application Delivery and Acceleration
» Logging, Monitoring and Reporting

Request a Quote  

Download Datasheet 

8 Item(s)

per page
  1. Barracuda Web Application Firewall 360

    Barracuda Web Application Firewall 360

    » Backend Servers Supported: 1-5
    » Inbound Web Traffic: 25 Mbps
    » HTTP Transactions/sec: 3,000
    » SSL Transactions/sec: 2,000
    » Ethernet Ports: 3x10/100
    Note: This appliance requires an Energize Update subscription
  2. Barracuda Web Application Firewall 460

    Barracuda Web Application Firewall 460

    » Backend Servers Supported: 5-10
    » Inbound Web Traffic: 50 Mbps
    » HTTP Transactions/sec: 6,000
    » SSL Transactions/sec: 4,000
    » Ethernet Ports: 1x10/100, 2xGigabit
    Note: This appliance requires an Energize Update subscription
  3. Barracuda Web Application Firewall 660

    Barracuda Web Application Firewall 660

    » Backend Servers Supported:10-25
    » Inbound Web Traffic: 100 Mbps
    » HTTP Transactions/sec: 10,000
    » SSL Transactions/sec: 6,000
    » Ethernet Ports: 3xGigabit
    Note: This appliance requires an Energize Update subscription
  4. Barracuda Web Application Firewall 860

    Barracuda Web Application Firewall 860

    » Backend Servers Supported:25-150
    » Inbound Web Traffic: 600 Mbps
    » HTTP Transactions/sec: 25,000
    » SSL Transactions/sec: 12,000
    » Ethernet Ports: 3xGigabit
    Note: This appliance requires an Energize Update subscription
  5. Barracuda Web Application Firewall 960

    Barracuda Web Application Firewall 960

    » Backend Servers Supported:150-300
    » Inbound Web Traffic: 1 Gbps
    » HTTP Transactions/sec: 55,000
    » SSL Transactions/sec: 20,000
    » Ethernet Ports: 3xGigabit
    Note: This appliance requires an Energize Update subscription
  6. Barracuda Web Application Firewall 360Vx (Setup)

    Barracuda Web Application Firewall 360Vx (Setup)

    » Setup for Barracuda Web Application Firewall 360Vx
    » Backend Servers Supported: 1-5
    » Inbound Web Traffic: 25 Mbps
    » CPU Cores Allowed: 2
    » HTTP Transactions/sec: 3000
    » SSL Transactions/sec: 2000
  7. Barracuda Web Application Firewall 460Vx (Setup)

    Barracuda Web Application Firewall 460Vx (Setup)

    » Setup for Barracuda Web Application Firewall 460Vx
    » Backend Servers Supported: 5-10
    » Inbound Web Traffic: 50 Mbps
    » CPU Cores Allowed: 3
    » HTTP Transactions/sec: 6000
    » SSL Transactions/sec: 4000
  8. Barracuda Web Application Firewall 660Vx (Setup)

    Barracuda Web Application Firewall 660Vx (Setup)

    » Setup for Barracuda Web Application Firewall 660Vx
    » Backend Servers Supported: 10-25
    » Inbound Web Traffic: 100 Mbps
    » CPU Cores Allowed: 4
    » HTTP Transactions/sec: 9000
    » SSL Transactions/sec: 6000

8 Item(s)

per page

Features & Benefits of Barracuda Web Application Firewall

Traditionally, system administrators lock down host computers through a network firewall in order to ensure network security. While a typical network firewall can help restrict traffic to HTTP and HTTPS, as this traffic can contain command exploits leveraging vulnerabilities in the Web application itself. These exploits can result in data leakage, site defacement and other attacks by hackers that compromise both the privacy and integrity of vital data. Businesses of all sizes that operate their own Web applications should ensure that their Web sites are protected against application vulnerabilities.

The Barracuda Web Application Firewall provides complete protection of Web applications and is designed to enforce policies for both internal and external data security standards, such as Payment Card Industry Data Security Standard (PCI DSS). At the same time the Barracuda Web Application Firewall 460 and higher models feature a comprehensive set of application delivery capabilities designed to improve the performance, scalability and manageability of today’s most demanding data center infrastructures.

Comprehensive Web Site Protection

The Barracuda Web Application Firewall proxies all of your Web site traffic, providing complete protection in front of your Web sites. Capabilities include:

  • » HTTP, HTTPS and FTP protocol compliance. At a basic level, the Barracuda Web Application Firewall verifies all inbound requests that comply with the HTTP, HTTPS and FTP specification. For example, inbound requests with more than one content-length header are typically the basis of HTTP request smuggling attacks; therefore they are illegal according to the HTTP specification and are blocked automatically.
  • » Protection against common, high-visibility attacks. Hackers can take advantage of vulnerabilities in your online Web forms to attack your applications. The Barracuda Web Application Firewall protects your Web applications against SQL injections, OS command injections and cross-site scripting attacks.
  • » Protection against attacks based on session state. The Barracuda Web Application Firewall protects your Web applications against any attacks based on session state, such as forms tampering or cookie tampering.
  • » Outbound data theft protection. In addition to inspecting the request traffic, the Barracuda Web Application Firewall also inspects all outbound packets for any data pattern expressible as a UNIX-style regular expression. Built-in policies protect all major credit cards and U.S. Social Security number patterns and new data patterns can be added at any time. Inspection for outbound leakage of these patterns can be applied to security policy on-the-fly.
  • » Web site cloaking. To prevent hackers from doing reconnaissance on your Web infrastructure, the Barracuda Web Application Firewall automatically strips identifying banners of Web server software and version numbers out of all transactions.
  • » Anti-crawling. While some Web crawlers, such as search engines are often desirable, you may wish to prevent all other users from downloading your entire site. The Barracuda Web Application Firewall can easily identify and allow legitimate crawlers while blocking more malicious ones.
  • » Fine-grained control. The Barracuda Web Application Firewall features automatic fine-grain rules creation based on both HTTP requests and responses down to the level of individual HTML elements.
  • » Application denial of service (DoS) protection. The Barracuda Web Application Firewall controls the rate of allowed operations that use an intense amount of resources, thus protecting against application-layer denial of service attacks.
  • » Cookie tampering. The Barracuda Web Application Firewall fully terminates and proxies every connection to insulate each unique user session from exposure and can stamp or encrypt the session cookies. Also included to prevent cookie tampering is the ability to ensure that all hidden or read-only form fields are not changed by the user.
  • » XML Firewall. The Barracuda Web Application Firewall has an integrated XML firewall improve the security of the XML based Web applications and Web services. The XML firewall detects and prevents XML specific attacks such as extremely large messages, highly nested elements, recursive passing, schema and WSDL poisoning.
  • » Integrated Anti Virus. All file uploads to the Web application can be scanned for embedded viruses and malware using the integrated anti virus engine of the Barracuda Web Application Firewall.
  • » Rate Control. Peak traffic or Denial of Service (Dos) attacks can impose significant load on the application servers, causing servers to overload and create very high response times. With the rate control feature, the Barracuda Web Application Firewall controls the rate of requests that are delivered to an application. This is crucial to prevent application servers from being overloaded.
  • » Adaptive Profiling. Inspects Web application requests and responses to understand the application structure which is utilized in the positive security model to provide zero-day protection.
  • » Exception Profiling. Reduces false positives by automatically creating or recommending policy changes by observing the request and response traffic.

Application Access Control

The Barracuda Web Application Firewall implements a single point for policy enforcement and control, which includes authentication to ensure that users are known, access control policy for resources and protection against data leakage. Capabilities include:

  • » LDAP and RADIUS integration. For authentication and authorization, the Barracuda Web Application Firewall integrates with common authentication services, including Active Directory and other LDAP-compatible directories as well as RADIUS servers.
  • » Simple single sign-on (SSO) portal. By combining built-in authentication and authorization capabilities with Web address translation and cookie session management features, administrators utilize the Barracuda Web Application Firewall to present a simple front-end portal to back-end applications without requiring changes to source code, IP addressing or the server infrastructure. Authentications are logged and user credentials are forwarded in the HTML header making integration with back-end applications simple and scalable.
  • » Client Certificate Authentication. To verify a user’s identity, the Barracuda Web Application Firewall authenticates and grants access to users with valid client certificates.

Application Delivery and Acceleration

In addition to the comprehensive security benefits of the Barracuda Web Application Firewall, there are also additional operational capabilities available in the Barracuda Web Application Firewall. Capabilities include:

  • » Caching. The Barracuda Web Application Firewall can reduce load on back-end Web servers and increase performance by caching Web content and avoiding repeated requests to back-end Web servers.
  • » Compression. To reduce network traffic requirements, the Barracuda Web Application Firewall can automatically apply GZIP compression to renderable HTML content to be decompressed by the browser.
  • » Connection pooling. To reduce back-end server overhead for maintaining new TCP connections, the Barracuda Web Application Firewall can automatically pool multiple front-end connections into a single back-end connection. Connection pooling keeps the back-end servers focused on processing application logic rather than protocol termination.
  • » SSL offloading. The Barracuda Web Application Firewall includes SSL offloading, streamlining the encryption and decryption of SSL traffic to quickly process secure online transactions without additional burden on any servers.
  • » Load balancing. The Barracuda Web Application Firewall includes integrated load balancing capabilities to distribute traffic among multiple back-end servers. It supports both Layer 4 and Layer 7 cookie persistence and includes support for Layer 7 content switching based on URL pattern, parameter or HTTP header fields.
  • » High Availability. When inline in Bridge-path, the Ethernet Hard Bypass ensures reliable application delivery even with a single Barracuda Web Application Firewall. For Web applications with stringent security requirements, the Barracuda Web Application Firewall may be installed in a redundant pair configuration, providing real-time application state replication so that security and user sessions will not be compromised during a failover event.

Logging, Monitoring and Reporting

The Barracuda Web Application Firewall features advanced capabilities to provide immediate feedback to the operations team that deploy, manage and secure mission critical applications. Capabilities include:

  • » Comprehensive logging. The Barracuda Web Application Firewall maintains a rich set of logs on the appliance, including system activity, Web Firewall activity, Web services activity, network firewall activity and traditional Web logs.
  • » PCI reports. The Barracuda Web Application Firewall provides an easy-to-read snapshot of common application attacks, critical for securing credit card information and providing compliance to PCI DSS requirements.
  • » Syslog support. The Barracuda Web Application Firewall forwards logs to a syslog server for centralized and persistent storage or analysis by a third party tool.

Barracuda Web Application Firewall Demo Video

Model Comparison of Barracuda Web Application Firewall

Model Comparison Model 360 360 Model 460460 Model 660660 Model 860860 Model 960960
CAPACITY*
Backend Servers Supported 1-5 5-10 10-25 25-150 150-300
Inbound Web Traffic 25 Mbps 50 Mbps 100 Mbps 600 Mbps 1 Gbps
HTTP Transactions/sec 3,000 6,000 10,000 25,000 55,000
SSL Transactions/sec 2,000 4,000 6,000 12,000 20,000
HARDWARE
Rackmount Chassis 1U Mini 1U Mini 1U Full Size 2U Full Size 2U Full Size
Dimensions (in.) 16.8x1.7x14 16.8x1.7x14 16.8x1.7x22.6 17.4x3.5x25.5 17.4x3.5x25.5
Dimensions (cm.) 42.7x4.3x35.6 42.7x4.3x35.6 42.7x4.3x57.4 44.2x8.9x64.8 44.2x8.9x64.8
Weight (lbs. /kg.) 12/5.4 12/5.4 26/11.8 46/20.9 52/23.6
Front Ethernet Ports 2x10/100 2xGigabit 2xGigabit 2xGigabit 2xGigabit
Back Ethernet Ports 1x10/100 1x10/100 1xGigabit 1xGigabit 1xGigabit
AC Input Current (Amps) 1.2 1.4 1.8 4.1 5.4
ECC Memory available available available
Redundant Power Supply available available
FEATURES
HTTP/HTTPS/FTP Protocol Validation available available available available available
Protection Against Common Attacks available available available available available
Form Field Meta Data Validation available available available available available
Web Site Cloaking available available available available available
Response Control available available available available available
Outbound Data Theft Protection available available available available available
Granular Policies to HTML Elements available available available available available
Protocol Limit Checks available available available available available
File Upload Control available available available available available
Logging, Monitoring and Reporting available available available available available
High Availability available available available available available
SSL Offloading available available available available available
Authentication and Authorization available available available available available
LDAP/RADIUS Integration available available available available
RSA SecurID available available available
CA SiteMinder available available available
Load Balancing available available available available
Content Routing available available available available
XML Firewall available available available

Barracuda Web Application Firewall FAQs

What does the Barracuda Web Application Firewall do?

The Barracuda Web Application Firewall protects your Web site from attackers leveraging protocol or application vulnerabilities to instigate unauthorized access, data theft, denial of service (DoS), or defacement of your Web site.

The Barracuda Web Application Firewall provides complete protection of Web applications and is designed to enforce policies for both internal and external data security standards, such as the Payment Card Industry Data Security Standard (PCI DSS). At the same time, the Barracuda Web Application Firewall features a number of traffic management capabilities designed to improve the performance, scalability and manageability of today’s most demanding data center infrastructures.

Why do I need a Web Application Firewall?

Businesses of all sizes that operate their own Web applications should deploy a powerful Web Application Firewall to protect their Web sites from application vulnerabilities.

Traditionally, security has been considered a network issue, where system administrators lock down host computers through a network firewall. While a typical network firewall can help restrict traffic to HTTP and HTTPS, this traffic can contain command exploits leveraging vulnerabilities in the Web application itself. Without the Barracuda Web Application Firewall acting as an application firewall, a hacker’s attack can result in unauthorized access, data leakage, site defacement and/or other attacks that compromise both the privacy and integrity of vital data.

What are the major capabilities and benefits of the Barracuda Web Application Firewall?

The major capabilities and benefits of the Barracuda Web Application Firewall include:

  • Comprehensive Web Site Protection: The Barracuda Web Application Firewall proxies all Web traffic, providing complete protection in front of your Web sites. Web site protection capabilities include: HTTP protocol compliance, protection against common/high-visibility attacks, protection against attacks based on session state, online form field validation, outbound data theft protection, Web site cloaking, anti-Web crawling and application denial of service (DoS) protection, as well as fine-grain controls.
  • Application Access Control: The Barracuda Web Application Firewall provides PKI support to provide certificate verification and prevents cookie tampering to ensure hidden or read-only form fields are not changed by the user.
  • Application Delivery and Acceleration: In addition to the security and access control benefits of Barracuda Web Application Firewall, there are also additional operational capabilities. Capabilities include SSL offloading, SSL acceleration, load balancing and high availability.
  • Logging, Monitoring and Reporting: The Barracuda Web Application Firewall features advanced capabilities to provide immediate feedback to operations teams that deploy, manage and secure mission critical applications. Besides a system log, Web firewall log, traditional Web log and audit log, the Barracuda Web Application Firewall also provides specific reports relevant to PCI compliance.

How does the Barracuda Web Application Firewall detect and mitigate threats?

The Barracuda Web Application Firewall provide award-winning protection from all common attacks on Web applications, including SQL injections, cross-site scripting attacks, session tampering and buffer overflows. As a full proxy, the Barracuda Web Application Firewall provides comprehensive inbound and outbound protection. By inspecting request traffic, the Barracuda Web Application Firewall can block inbound attacks and cloak Web sites from hackers, while response traffic inspection prevents sensitive data leakage, such as credit card or Social Security numbers.

In addition, the Barracuda Web Application Firewall secures applications from unauthorized user access a full PKI integration for use with client certificates.

Can the Barracuda Web Application Firewall help my company comply with the Payment Card Industry Data Security Standard (PCI DSS)?

Yes, the Barracuda Web Application Firewall assists organizations that store, process and/or transmit credit card numbers to comply with the Payment Card Industry - Data Security Standard (PCI DSS) requirements.

As major credit card companies are increasing pressure on merchants to comply with the PCI DSS, many e-commerce businesses are seeking solutions to meet requirement 6.6 of PCI DSS calling for either detailed custom application code reviews or installation of a Web Application Firewall by June 30, 2008. Failure to comply with these security standards may result in fines, restrictions or permanent expulsion from card acceptance programs. Through multiple advanced features, the Barracuda Web Application Firewall can help organizations easily become PCI DSS compliant.

What logging, monitoring and reporting features are available with the Barracuda Web Application Firewall?

Logging monitoring and reporting capabilities of Barracuda Web Application Firewall include:

  • Comprehensive logging. The Barracuda Web Application Firewall maintains a rich set of logs on the appliance, including system activity, Web Firewall activity, Web services activity, network firewall activity and traditional Web logs.
  • PCI reports. The Barracuda Web Application Firewall provides a quick snapshot of application attacks defined in the PCI DSS Section 6.5, including unvalidated input, broken access control, cross-site scripting and so on.
  • Syslog support. The Barracuda Web Application Firewall forwards logs to a syslog server for centralized and persistent storage or analysis by a third party tool.

Will the Barracuda Web Application Firewall fit into my existing network environment?

Yes, the Barracuda Web Application Firewall is designed to easily fit into any existing data center environment and to rapidly secure and accelerate new and existing Web applications. Barracuda Networks offers the most flexible array of Barracuda Web Application Firewall deployment options, including both Bridge-path and Route-path.

How do I know which Barracuda Web Application Firewall model is best suited to my needs?

A regional Barracuda Networks sales representative can evaluate your network environment and Web usage needs to help determine which model(s) is the best fit for your company.

What if I have more questions about the Barracuda Web Application Firewall?

For additional assistance or for a product demonstration of the Barracuda Web Application Firewall, please contact barracudastore at 866.892.5081 (Toll-Free)

Barracuda Web Application Firewall Online Demo

Protects Web applications from vulnerabilities, data theft, and fraud.
Go To Demo» » »
login with Username "guest". Password is not required.

4.65 out of 5 based on 28 reviews
Did you find this page helpful? Reviews : 28Rating :
4.65 out of 5
BUY WITH CONFIDENCE

Customer Service

» Have a product question?
» Prefer to order by phone?
» Call Toll-Free 866.892.5081
 Dreaming Tree Technology, Inc. BBB Business Review

Fast Delivery

Same day shipping when ordered before 3PM EST.


Hassle-Free Returns

Your order receives a full 30-day, 100% money back guaranteed details


Secure Checkout

» 2048-bit encryption
» Certified Authorize merchant
» Our security is verified daily.


Best Price Assured

We offer you the best price. If you find it cheaper let us know.


Payment Options


» PayPal & Google Checkout
» Company purchase orders
» Company check
» Wire transfers