BARRACUDA WEB SECURITY GATEWAY Internet ntrols Co y olic P iltering and Rewriting URL F ntent Filter Database Co eb Site W us Check II r e ture Vi ar Database pplication Blocking yw A more than 150,000 collection points and analyzes the than 150,000 collection and analyzes points more data collected to develop defenses, rules, and signatures to and signatures rules, defenses, develop collected to data Barracuda emerge, network. As new threats your defend All products are products are Barracuda Barracuda All Networks Central: monitor to continuously works that center operations In than 80 countries. in more of collection located points Internet threats. Internet the latest definitions through Barracuda Energize Updates. Updates. Energize Barracuda definitions through the latest provides Security Gateway Web the Barracuda that and block the latest Internet threats. Barracuda Central Barracuda Central threats. Internet and block the latest from contributions gets data addition, Barracuda Central comprehensive and accurate protection against the latest against the latest protection and accurate comprehensive collects , URLs, and other data from tens of thousands tens from and other data URLs, collects email, supported by Barracuda Central, a 24x7 advanced security a 24x7 advanced supported Barracuda Central, by Central is quick to respond to early outbreaks and delivers delivers and early outbreaks to respond is quick to Central These updates require zero administration and ensure and ensure administration zero require updates These Sp y s y Architec s ru Vi I De nitions us Check r b Security Gatewa uthentication Vi otocol A We e Pr ar Database yw Sp eb Security Gatewa e W Barracuda Energize Update Barracuda e Signatur otocol ar Database e Pr yw ar ype Blocking Sp T Barracuda tion and Blocking yw ile Sp F tec De dministrator Noti cation A e Removal ar Database yw Sp ntrols ing Co y e Download ar Block olic yw IP P Sp Client outbreaks and delivers the latest definitions through automatic Barracuda Energize Updates. Energize Barracuda automatic definitions through the latest and delivers outbreaks

Barracuda Central monitors data 24x7 from more than 150,000 Barracuda Networks products in products Networks than 150,000 Barracuda more data 24x7 from monitors Central Barracuda over 80 countries and 17 languages. As new threats emerge, Barracuda Central quickly responds to to quickly responds Central Barracuda emerge, As new threats and 17 languages. 80 countries over

protect against malware. The Barracuda Web Security Gateway gives administrators granular control to manage bandwidth usage, visits to websites, websites, visits to manage bandwidth usage, to control granular administrators gives Security Gateway Web Barracuda The against malware. protect policy controls, include: IP-based measures The protocols. and application HTTPS, FTP, HTTP, including and the Internet, clients internal between requests to malicious websites. To ease deployment, Barracuda Web Security Gateway seamlessly integrates with existing network components and components network with existing seamlessly integrates Security Gateway Web Barracuda ease deployment, To websites. malicious to requests user authentication systems. Web-based threats evolve swiftly, so as new requirements emerge—e.g., social-networking control—the Barracuda control—the social-networking emerge—e.g., so as new requirements swiftly, evolve threats Web-based systems. user authentication detection and deep content inspection for virus checking, file type blocking, download blocking, and desktop spyware protection. spyware and desktop blocking, download spyware file blocking, type inspection checking, virus for detection and deep content Barracuda multilayered approach to Web Security Gatewaying includes a variety of technologies to regulate web usage and web regulate to includes a variety of technologies Security Gatewaying Web to approach Barracuda multilayered Approach: Layered and use of Internet applications to enforce corporate Internet usage policy. Several layers of defense protect against all forms of harmful traffic against all forms protect of defense layers Several usage policy. Internet corporate enforce to applications and use of Internet and unauthorized Internet applications, while its award-winning anti-malware technology blocks spyware downloads, prevents viruses, and blocks viruses, prevents downloads, blocks spyware technology anti-malware while its award-winning applications, Internet and unauthorized Comprehensive Web Security Gatewaying Web Comprehensive Web Security Gateway is automatically updated with new capabilities to meet those requirements, at no extra charge. With industry-leading With extra no charge. at requirements, those meet capabilitiesnew with to updated is automatically Security Gateway Web is the most cost-effective Security industry. solution in the Gateway Web the Barracuda fees, capabilities and no per-user licensing spyware protocol detection and blocking, user authentication, application protocol blocking, URL filtering, user/group-based policy controls, early user/group-based policycontrols, URL filtering, blocking, protocol application user authentication, detection and blocking, protocol spyware solution for businesses of all sizes. The Barracuda Web Security Gateway enforces Internet usage policies by blocking access to objectionable to content access blocking policies by usage Internet enforces Security Gateway Web Barracuda The of all sizes. businesses solution for

The Barracuda Web Security Gateway combines preventative, reactive, and proactive measures to form a complete content filtering and anti-malware and anti-malware filtering content a complete form to measures proactive and reactive, preventative, combines Security Gateway Web Barracuda The Barracuda Web Technology SecurityBarracuda Web Gateway Barracuda Networks Web Security Gateway Technology: A Look Inside CONTENT FILTERING

Recreational web browsing adversely impacts employee productivity and exposes the Business Category http://nielsen.com ALLOW network to malware threats. With Barracuda Web Security Gateway, administrators http://marketresearch.com ALLOW can create policies that control user access to websites using multiple methods, http://forbes.com ALLOW including URL content categories, URL by domain or pattern, and file type blocking. Internet Administrators can choose to block, allow, warn, or monitor access to these domains Content Filter based on corporate policies.

User Adult / Porn Category http://penthouse.com BLOCK http://playboy.com BLOCK http://hustler.com BLOCK Blocked by the Barracuda Block Page Web Security Gateway

APPLICATION FILTERING

The Barracuda Web Security Gateway provides extremely granular control over Web IM Category AIM BLOCK 2.0 sites and applications, which allows administrators to limit access based on activity Yahoo! Messenger BLOCK MSN BLOCK type within the same portal. For example, an organization may want to use Facebook ICQ BLOCK MySpace IM BLOCK or Twitter for viral marketing campaigns but prevent employees from playing games GoogleTalk BLOCK on Facebook or leaking confidential information through Twitter. (Traditional content filtering solutions either completely block or allow unrestricted access to these types of Application Blocking content and web applications.) In addition, administrators can configure the Barracuda Web Security Gateway to archive outbound social media communications, like Facebook Instant Messenger User posts, tweets, and web-based email, to a message archive solution like the Barracuda Blocked by the Message Archiver. These messages can be searched to comply with HR or litigation Barracuda Block Page Web Security Gateway requests. This level of functionality allows organizations to provide mission-critical access to Web 2.0 sites while restricting time and bandwidth wasting actions and applications.

GATEWAY MALWARE PROTECTION

The Barracuda Web Application Filter’s spyware protection engine blocks access to blacklisted sites in the extensive, up to date Barracuda Central Database. It also unpacks and examines individual files within 17 different types of archives for viruses and spyware. It can be configured to block password-protected archives that may contain harmful payloads. And, it scans inbound traffic for spyware, adware, trojans, and viruses.

Spyware Web Site Database

File Type Blocking Virus Check I Virus Check II Spyware Download Blocking

Blocked by the Spyware / Virus Barracuda Web Security Gateway

INTEGRATED DESKTOP SPYWARE PROTECTION

From inside the network, the Barracuda Web Security Gateway identifies and blocks communications from infected systems to the Internet. By monitoring traffic at Layer 4, the Spyware Protocol Detection and Blocking Barracuda Web Security Gateway detects and blocks outbound spyware activity across all protocols and ports. Once an infected machine is identified, the Barracuda Web Security Client Computer Gateway intercepts web browsing sessions and presents the user with the Barracuda Blocked by the Barracuda Spyware Removal Tool in the form of an ActiveX control. The Barracuda Web Security Gateway Spyware Web Security Gateway provides complete security, without the need to install client software on each workstation, Removal Tool by integrating powerful gateway and desktop spyware protection strategies. Administrator Notication TRANSPARENT USER AUTHENTICATION

2 Domain controller veri es identity with Authentication Server The Barracuda Web Security Gateway integrates with popular LDAP 1 User logs into domain servers including Microsoft Active Directory, Novell eDirectory, and IBM Lotus Domino Directory. It transparently authenticates workers using their Windows credentials over NTLM or Kerberos when IP- Primary Domain Authentication Controller Server based authentication is not feasible. This is useful in terminal services, User Network Address Translation (NAT), or other thin client environments User makes Internet request Login event notication User credential lookup such as Citrix, where multiple clients share one IP address. 3

Barracuda Web Security Gateway Internet 4 Barracuda Web Security Gateway transparently applies policy based on user and group membership

POLICY MANAGEMENT

Policies A powerful policy engine supports granular policies by user, group, IP address ranges, 1. Allow HR to 2. Block job sites 3. Block social networking or time. The Barracuda Web Security Gateway allows custom creation of allow and job sites to all users category for all users block lists, specification of URL patterns, and restriction of Internet downloads based on MIME type, e.g., executables, streaming media, or videos. Administrators can control Internet access from specific client machines or external servers based on http://www.myspace.com Barracuda

source or destination IP address and ports. In addition, exception rules can be cre- We b Security Gatewa ated to override global policies and further refine Internet access policy. Web request Human Resources

http://www.hotjobs.com y Po li cy Engine

Employee http://www.hotjobs.com

SSL VISIBILITY

The combination of SSL Filtering and SSL Inspection lets customers filter SSL (HTTPS) Adult / Porn Category https://penthouse.com BLOCK websites subject to the same filtering rules and policies applied to HTTP traffic. With https://playboy.com BLOCK https://hustler.com BLOCK https://sex.com BLOCK SSL Filtering, the Barracuda Web Security Gateway monitors Domain Name System https://porn.com BLOCK (DNS) traffic generated by HTTPS requests and stores an internal database that maps https://adult.com BLOCK IP addresses to domain names. Using this database, the Barracuda Web Security Web request Gateway can apply policies based on the IP addresses without actually decrypting SSL Filtering the traffic to identify domain names. Also, if users require more of granular control, SSL Inspection would decrypt and scan user HTTPS web requests, enabling malware detection and web policy enforcement. It does this by acting as a secure intermediary Client Computer Blocked by the Barracuda between user HTTPS web requests and the destination web server (i.e., Facebook, Web Security Gateway YouTube). After processing, this HTTPS traffic will be re-encrypted on the fly by the Barracuda Web Security Gateway and routed to the destination web server.

REMOTE FILTERING

The Barracuda Web Security Gateway extends protection beyond the network perimeter with the Barracuda Web Security Agent (WSA) and the Barracuda Safe Browser (BSB).

The WSA is a tamper-proof client software for off-network Windows and Mac OS X Remote User Web Security computers, while the BSB is a fully-functional mobile browser for iOS-based devices. Agent Software In both cases, web traffic from remote clients is filtered through a central Barracuda Web Security Gateway to apply the same web policies to users on and off the network. Both the WSA and the BSB can be centrally configured from the administrator interface. Barracuda Web Security Gateway Together, these powerful solutions let organizations implement a consistent web policy Internet Network O ce User across local and distributed workforces without purchasing additional tools. BARRACUDA WEB SECURITY GATEWAY US 2.0•Copyright Networks, 2016 Barracuda •3175S. Inc. Winchester Blvd., •barracuda.com 95008 •408-342-5400/888-268-4772 (US& Canada) Campbell, CA Barracuda Networks and the Barracuda Networks logo are registered Networks andthe Barracuda intheUnited Networks Inc. Networks, States. oftheir respectiveBarracuda of Barracuda owners. trademarks Allothernames are theproperty engineers at Central, Barracuda theBarracuda Web Gateway Security offers themostsophisticated andeffective Gatewaying Security Web Barracuda Barracuda Web Gateway Security Core Technologies Barracuda NetworksBarracuda Commitment to Innovation technology intheindustry. technology. Through Networks’ Barracuda proven multilayered approach backed by thededicated andconstant vigilance ofthehighly-trained Barracuda NetworksBarracuda iscommitted to providing you withthemostadvanced andcomprehensive Web Gatewaying Security andanti-spyware For more information abouttheBarracuda Web Gateway, Security visithttp://www.barracuda.com//products/websecuritygateway Security Gateway the Security alsosupports Web Cache Communication Protocol (WCCP). WCCP provides for loadbalancing, fault Clustered systems begeographically can dispersedanddonotneedto be co-located Barracuda onthesamenetwork. Gateway are reports generated natively withouttheneedfor additionalsoftware management. These provide reports Clustering andScalability: The Barracuda Web Gateway clustering ofmultipleunitsfor both Security supports Barracuda Central Barracuda Security: leverages web crawling technologies, points, itsnetwork ofspamcollection and system-level control andto definitionandenforcement delegate for security policy to individualdepartments. system anditsassociated utilities. While oftechnology thevast intheBarracuda majority Web Gateway Security is security researchers,security theBarracuda Web Gateway Security operating system ishardened for maximumsecurity Web Gateways Security beplaced can onredundant network paths for highavailability deployments. Barracuda Web configuration across thecluster andpolicy andadministrators across theclustercan changepolicy from any unit. Web Gateway Security alsoprovides real-time viewsofcontent andapplication filtering activity. Each web traffic request comprehensive details about all Web Gatewaying Security areand spyware activity. detection available Reports on customers implement security strategies.customers implement security continually vendors work to withsecurity uncover andresolve potential vulnerabilities inboththeLinuxoperating to handletheneedsoflargest enterprise environments. tolerance, across andlinearscalability multipleBarracuda Web Gateways. Security Through thesefeatures, it’s equipped and assignedcontrol over specificusersandgroups. These useraccountscan be restricted to onlygenerating reports and customized to provide maximumflexibility to administrators. BarracudaThe Gateway Security Web supports and application filtering,Barracuda the Gateway Security Web effectively shieldsagainstnetwork threats andhelps and stability. In addition to internal testing, Networks Barracuda credits the “white hat” research who community through interface. asimpleweb-based The Barracuda Web Gateway’s Security management enginesupports policy demand or can bescheduledfordemand orcan automatic onadaily, delivery weekly, ormonthly basis. reports, theBarracuda Besides of reports. Unlike solutionsthat require dedicated clients ordatabase reporting servers,Barracuda Web Security Reporting: The Barracuda Web Gateway more than30types Security enginethat supports includesareporting or creating policiesfor specificusersorgroups administration ofusers. letsITadministrators Role-based maintain organization based on a combination of criteria. Access lists, IP-based policies, and exception rules be combined can at severalgranular policy userlevels. control Itcan Internet access by individuals, groups, ormachineswithinthe Management: The Barracuda Web Gateway Security is designed to satisfy the diverse needs of small and medium database ofmalware definitionsandURLs. With spyware andvirus protection at thegateway combined with content Hardened Operating System: onthepopularLinuxopensource Based kernel that hasstood upto scrutiny among management andscalability. For centralized management, Barracuda Web Gateways Security linktogether to share processed isalsorecorded insyslogmessages, bedirected whichcan processing. to aremote for further syslogserver role-based administrationrole-based through which multiple administrative user accounts be delegated can to specific roles businesses, enterprises, educational institutions, andgovernment agencies. Administrators managethedevice proprietary, Networks Barracuda doesleverage secure andproven opensource alternatives whenever possible. feedback from Networks’ Barracuda installedbaseofmore than150,000customers, to buildthemosteffective