The Barracuda SSL VPN is an integrated hardware and software solution enabling secure, clientless remote access to internal network resources from any Web browser. Designed for remote employees and road warriors, the Barracuda SSL VPN provides comprehensive control over file systems and Web-based applications requiring external access..
|
Today’s global economy demands employees to be increasingly more mobile and flexible in meeting business needs. An inherent challenge is enabling secure remote access to network resources with an audit trail. Typical users require the use of email, file servers, intranet Web sites, databases and desktop access to office workstations. With conventional VPN solutions such as IPSec or PPTP, secure access to resources are often difficult or impossible to manage.
Accessible from any Web browser on any operating system, the Barracuda SSL VPN is an integrated hardware and software solution with the power of an enterprise-class solution and affordability demanded by organizations of all sizes. The Barracuda SSL VPN includes all of the features needed to enable resource access from a powerful policy-based permissions framework and maintains network hygiene by scanning for viruses before uploading files back to the network. Designed for remote employees and road warriors, the Barracuda SSL VPN provides an audit log of all activity during a VPN session.
| SSL Tunneling |
From any Web browser, users gain secure remote access to internal Web applications and network files shares. Richer support for SSL tunneling is enabled through the Barracuda SSL VPN agent, a lightweight Java tunneling client that supports common remote applications, including Remote Desktop Services, Citrix XenApp, VNC, NX, SSH and Telnet.
| Barracuda Network Connector |
Designed for applications using UDP, the Barracuda Network Connector is a secure IP tunneling client installed on a user’s workstation or laptop. When the Barracuda Network Connector is started, a full IP connection is created to the Barracuda SSL VPN appliance. The Barracuda Network Connector has a fully routed VPN connection off t the remote network, enabling content to stream off the remote network and allowing the use of any TCP or UDP application, such as legacy client/server applications.
| Intranet Web Forwarding |
The Barracuda SSL VPN acts as a Web proxy for most intranet Web sites. There are a number of methods available to proxy intranet Web sites. The choice is determined by the complexity of the Web site.
| Windows Explorer Mapped Drives |
When connecting using Windows 2000 or later, administrators configure the Barracuda SSL VPN Agent to automatically map network drives directly to file systems authorized for VPN access. These mapped drives are used like other network drives and are safely removed after the session ends. The Barracuda SSL VPN Agent transparently encrypts all files copied to and from mapped drives.
| Single Sign-On |
The Barracuda SSL VPN integrates with existing user databases via LDAP, RADIUS, Active Directory and NIS. This ensures user account maintenance is centralized and eliminates the duplication of user data across the organization. Additionally, the Barracuda SSL VPN authenticates certain services using credentials, including:
| Antivirus |
All files uploaded during a Barracuda SSL VPN session to the network file system or from a proxied intranet Web application, are automatically scanned for viruses, spyware and other forms of malware. Virus definitions are maintained via Barracuda Energize updates to prevent compromised files from being uploaded to the network.
| Application Launching |
Using Application Launching, administrators can customize which applications are deployed to VPN users. The Barracuda SSL VPN includes a number of applications by default, such as SSH/SFTP, Telnet and Remote Desktop clients. With the Remote Desktop application, users are able to access their desktops with ease.
| Virtual Keyboard |
The virtual keyboard is an on-screen keyboard used as a security feature to defend against key logging attacks. The virtual keyboard echoes the character clicked on with the mouse.
| Tiered Authentication Schemes |
Tiered authentication schemes ensure the entry portal to an organization’s network is protected by comprehensive security. When using Active Directory authentication, the administrator can elect to implement a PIN authentication module before prompting for the user’s Active Directory password. This additional security layer decreases account lockouts from happening as a result of brute force password attacks on the domain.
| Hardware Token Authentication |
The Barracuda SSL VPN supports RSA SecurID, VASCO, Safeword and CryptoCard authentication servers through RADIUS integration. The use of hardware token authentication allows for access using a one-time password token.
| Client Access Controls |
Administrators can enforce policies to restrict client access based on operating system or Web browser version. These policies can be used to ensure that end user computers are updated to the latest versions and free of known vulnerabilities prior to gaining access to network resources.
| Automatic Cache Cleaning |
When enabled, a cache cleaning utility automatically runs when users logout or disconnect, clearing all traces of the secure session from the Web browser cache and history. Cache cleaning is recommended when remote users access the Barracuda SSL VPN from public or shared computers.
| Site-to-Site Connectivity |
The Barracuda SSL VPN Server Agent streamlines connections to services at remote sites without the security risks and overhead related with configuring and maintaining a fully routed IPSec connection. The Barracuda SSL VPN Server Agent directly connects to services hosted on remote sites from the Barracuda SSL VPN. Once installed at a remote site, shortcuts to services access resource via the Web portal interface.
| Auditing and Reporting |
All resource access via the Barracuda SSL VPN is audited. Reports are available in real time showing a comprehensive look at privilege usage, failed logons, file and intranet use. Additionally, the status page provides statistics showing resource use.
| Multiple User Realms |
Realms are used where multiple user databases exist within an organization. By using realms, the Barracuda SSL VPN can be configured to authenticate against multiple domain servers and other directories, such as LDAP and NIS at once.
| Customizable User Profiles |
Users can create profiles that store configuration settings unique to a session. Profiles are useful in the case where a user may connect to the Barracuda SSL VPN from a number of different locations. In these cases, proxy servers are preset and configured for the Barracuda SSL VPN Agent to use depending upon the location.
Model Comparison |
Model 180 |
Model 280 |
Model 380 |
Model 480 |
Model 680 |
| CAPACITY* | |||||
| Maximum Concurrent Users | 15 | 25 | 50 | 100 | 500 |
| HARDWARE | |||||
| Rackmount Chassis | 1U Mini | 1U Mini | 1U Mini | 1U Mini | 1U Fullsize |
| Dimensions (in.) | 16.8x1.7x9.1 | 16.8x1.7x14 | 16.8x1.7x14 | 16.8x1.7x14 | 16.8x1.7x22.6 |
| Dimensions (cm.) | 42.7x4.3x23.1 | 42.7x4.3x35.6 | 42.7x4.3x35.6 | 42.7x4.3x35.6 | 42.7x4.3x57.4 |
| Weight (lbs. /kg.) | 8/3.6 | 12/5.4 | 12/5.4 | 12/5.4 | 26/11.8 |
| Ethernet | 1x10/100 | 1x10/100 | 1x10/100 | 1x10/100 | 2xGigabit |
| AC Input Current (Amps) | 1.0 | 1.0 | 1.2 | 1.4 | 1.8 |
| Redundant Disk Array (RAID) | ![]() |
![]() |
|||
| ECC Memory | ![]() |
||||
| FEATURES | |||||
| SSL Tunneling | ![]() |
![]() |
![]() |
![]() |
![]() |
| Barracuda Network Connector | ![]() |
![]() |
![]() |
![]() |
![]() |
| Intranet Web Forwarding | ![]() |
![]() |
![]() |
![]() |
![]() |
| Network File Access | ![]() |
![]() |
![]() |
![]() |
![]() |
| Windows Explorer Mapped Drives | ![]() |
![]() |
![]() |
![]() |
![]() |
| Citrix XenApp/VNC/NX/Telnet/SSH/RDP Applications | ![]() |
![]() |
![]() |
![]() |
![]() |
| Remote Desktop Single Sign-on | ![]() |
![]() |
![]() |
![]() |
![]() |
| Antivirus | ![]() |
![]() |
![]() |
![]() |
![]() |
| Virtual Keyboard | ![]() |
![]() |
![]() |
![]() |
![]() |
| Active Directory/LDAP Integration | ![]() |
![]() |
![]() |
![]() |
![]() |
| Layered Authentication Schemes | ![]() |
![]() |
![]() |
![]() |
![]() |
| Multiple User Realms | ![]() |
![]() |
![]() |
||
| Barracuda SSL VPN Server Agent | ![]() |
![]() |
![]() |
||
| Hardware Token Support | ![]() |
![]() |
![]() |
||
| RADIUS Authentication | ![]() |
![]() |
![]() |
||
| SNMP / API | ![]() |
![]() |
|||
| Syslog Logging | ![]() |
![]() |
|||
The purpose of this article is to help you make a decision as far as which Barracuda SSL VPN device would be best for your organization.
When deciding which Barracuda SSL VPN device will be best for your organization you will first want to figure out the maximum amount of concurrent users will need remote access. The following table will give you a guide as far as which device will support the amount of remote users you have.
| Model Comparison | Model 280 | Model 380 | Model 480 |
| Capacity* | |||
| Maximum Concurrent Users | 25 | 50 | 100 |
| Hardware | |||
| Rackmount Chassis | 1U Mini | 1U Mini | 1U Mini |
| Dimensions (in.) | 16.8x1.7x14 | 16.8x1.7x14 | 16.8x1.7x14 |
| Dimensions (cm.) | 42.7 x 4.3 x 35.6 | 42.7 x 4.3 x 35.6 | 42.7 x 4.3 x 35.6 |
| Weight (lbs./kg.) | 12/5.4 | 12/5.4 | 12/5.4 |
| Ethernet | 1 x 10/100 | 1 x 10/100 | 1 x 10/100 |
| AC Input Current (Amps) | 1.0 | 1.2 | 1.4 |
| Redundant Disk Array (RAID) | x | ||
| Features | |||
| SSL Tunneling | X | X | X |
| Barracuda Network Connector | X | X | X |
| Intranet Web Forwarding | X | X | X |
| Network File Access | X | X | X |
| Windows Explorer Mapped Drives | X | X | X |
| VNC/NX/Telnet/SSH/RDP Applications | X | X | X |
| Remote Desktop Single Sign On | X | X | X |
| Antivirus | X | X | X |
| Virtual Keyboard | X | X | X |
| Active Directory/ LDAP Integration | X | X | X |
| Layered Authentication Schemes | X | X | X |
| Multiple User Realms | X | x | |
| Barracuda SSL VPN Server Agent | X | x | |
| Hardware Token Support | X | ||
| RADIUS Authentication | X | ||
| SNMP/API | X | ||
| Syslog Logging | X | ||
| • | Multiple User Realms and the Barracuda SSL VPN Support Agent are available on models 380 and above. |
| • | Hardware Token Support, RADIUS Authentication, SNMP/API, and Syslog Logging are available on only the model 480. |
Subscriptions
Energize Updates- Energize Updates are required for the first year. Include Virus Definition updates, application updates, security updates, basic technical support, and firmware updates. Energize Updates are required for the first year.
Instant Replacement- Instant Replacement is an optional subscription. Will extend the hardware warranty on the device and upgrade the technical support to 24x7. In the event of failure a replacement unit will be shipped overnight.
Premium Support- Not available on the Barracuda SSL VPN devices at this time.
![]() |
Barracuda SSL VPN Online DemoSecure clientless remote access to internal network resources from any Web browser.Go To Demo» » » |
| login with Username "guest". Password is not required. | |
![]()
![]()
![]()
![]()
![]()