It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda SecureEdge

How to Configure Additional IP Addresses to a Static WAN Interface

  • Last updated on

Barracuda SecureEdge now supports multiple IPs on a static WAN interface on a Site or a private Edge Service. The SecureEdge Manager allows you to configure additional WAN IPs in addition to the primary WAN IP. Static WAN interfaces can be configured either during deployment or later through the Sites / Private Edge Service configuration page. For more information on configuring during deployment, see How to Create a T/VT Site Configuration in Barracuda SecureEdge. For more information on different types of supported WAN connection, see WAN Connections

se_st_wan-01.png

Please note the following regarding this new feature:

  • You can add additional IP addresses to a static WAN interface for both Sites and private Edge Services. 
  • You are not allowed to add an additional IP address outside the network defined by the primary IP and the netmask.
  • You cannot add the primary IP address or the gateway IP address as an additional IP address.

    • If you configure multiple IPs to a static WAN interface for a Site or a private Edge Service:
      • The Barracuda SecureEdge Access Agent will receive only the primary IP for this interface as a point of entry (PoE).
      • The port (TCP 443) will not be usable as fallback for the SecureEdge Access Agent on the primary IP.
      • When selecting a static WAN interface as a destination of an ingress NAT rule or as a source of an IPsec tunnel, you need to select a single IP configured on this static WAN interface: either the primary IP address or an additional IP address.

Static WAN Configuration

  1. Go to https://se.barracudanetworks.com and log in with your existing Barracuda Cloud Control account.
  2. Select the workspace containing your site. 
  3. Go to Infrastructure > Sites. The Sites page opens.
  4. Select the site you want to edit. You can either search for the name or serial, or use filters to tailor the list of displayed sites. You can also simply scroll through the list. Click on the arrow icon next to the site you want to configure.
    site_page.png
  5. In the site menu, go to Settings > WAN and click Add WAN Interface.
    add_wan_interface.png
  6. The Add NEW WAN Interface window opens.
  7. In the BASIC tab, specify values for the following:
    • Name – Enter a unique name for your uplink.
    • Type – Select Static from the drop-down list as the network type.
    • Port – Select the port where your uplink is connected to. Default for DHCP connections is p4. Note: Port 1 is reserved for High Availability
    • Virtual LAN ID (Optional) – If required, enter the Virtual LAN ID this interface is connected to. Note: You can use if connecting to a switch with virtual LAN support.
    • IP Address – Enter the IP address assigned to your appliance.
    • Additional IP Addresses – Enter one or more valid additional IP addresses and click +. Note: You must enter valid and distinct additional IP addresses.
    • Netmask – Enter the CIDR netmask suffix.
    • Gateway – Enter the gateway IP address. 
    • Provider Pinning – Select a provider classification from the drop-down list.
    • HA Failover – Only available in a High Availability cluster. Click to enable. For more information, see How to Enable Interface Monitoring in a High Availability Cluster.
    • User Connectivity – For more information, see How to Enable User Connectivity on a Site.
      static_wan_902.png
  8. Click OK.
  9. Click Save.

After the configuration is complete, you can verify that changes to the static WAN setting in the Audit Log have been made and that notifications have been sent.

Edit an Existing Static WAN Configuration

If you configure multiple IPs for a static WAN interface for a Site or a private Edge Service, you can change an existing static WAN interface either to be a primary IP address or an additional IP address for a selected Site or a private Edge Service:

  1. Go to https://se.barracudanetworks.com and log in with your existing Barracuda Cloud Control account.
  2. In the left menu, click the Tenants/Workspaces icon and select the workspace containing your private Edge Service. 
  3. Go to Infrastructure > Edge Services. The Edge Services page opens.
  4. Select the private Edge Service you want to edit. Click on the arrow icon next to the private Edge Service you want to edit.
    edge_service_page.png
  5. In the Edge Services menu, go to Settings > WAN and click on the pencil icon next to the WAN interface you want to edit.
    private_edge_settings.png
  6. The Edit WAN Interface window opens. Edit the value you are interested in. For example, for a static WAN configuration, you can edit the primary IP address and an additional IP address. When adding or removing additional IP addresses, click + or -x accordingly.
    private_edge.png
  7. Click OK.
  8. Click Save.

(Optional) Ingress NAT - Edit Static WAN Configuration 

If you configure multiple IPs for a static WAN interface for a Site or a private Edge Service, you must select one of the IP addresses configured on the static WAN interface. In other words, you can select either a primary IP address or an additional IP address for a selected Site or a private Edge Service. By default, the primary IP address is used. For more information, see How to Create Ingress NAT Rules. To edit static WAN interface settings on an existing ingress NAT rule:

  1. Go to https://se.barracudanetworks.com and log in with your existing Barracuda Cloud Control account.
  2. Select the workspace containing your Site or private Edge Service, and click the Security Policy icon. 
  3. Expand the Network ACL menu and select Ingress NAT
  4. The Ingress NAT window opens. Click on the pencil icon next to the rule you want to edit.
    edit_NAT_rule.png
  5. The Edit Rule window opens. Edit the value you are interested in. 

    • Note that in the DESTINATION CRITERIA section of an ingress NAT rule, you can now choose either a Primary Address or Additional Addresses to be configured on this static WAN interface. In other words, when selecting a static WAN interface as the destination of an ingress NAT rule, you need to select a single IP configured on this static WAN interface: either the primary IP address or an additional IP address. For example, in this case, the selected Additional Address = 15.45.125.7.
      staticwan_NAT.png

      By default, the primary IP address is used on the static WAN interface.

      edit_nat_static.png

  6. Click Save.

(Optional) IPsec VPN Tunnel - Selection of an IP address for a Static WAN Configuration 

If you configure multiple IPs for a static WAN interface for a Site or a private Edge Service, you must select one of the IP addresses configured on the static WAN interface. You can select either the primary IP address or an additional IP address on an IPsec VPN tunnel. By default, the primary IP address is used.

  1. Go to https://se.barracudanetworks.com and log in with your existing Barracuda Cloud Control account.

  2. In the left menu, click the Tenants/Workspaces icon and select the workspace you want to configure the IPsec IKEv2 tunnel for.
  3. Go to Integration > IPsec VPN.

  4. The IPsec VPN page opens. To add a tunnel, click Add IPsec Tunnel.
  5. The Create IPsec Tunnel window opens. 
  6. After completing the General tab configuration, click Next.
  7. In the Source/Destination tab, specify values for the following:

    • Enable BGP – Click to disable.

    • In the SOURCE section, specify values for the following:

      • Type – Select the type from the drop-down list. You can choose either Edge Service or Site.

      • Peer – Select the peer from the drop-down list.

      • WAN Interface – Select the WAN interface from the drop-down list. 

        • If you select Static WAN, specify the value for the following: 
          • Address – Select the address from the drop-down menu. You can choose either a Primary Address or Additional Addresses. For example, in this case, the Edge Service is a private Edge Service called Austria, the WAN Interface is Wan1, and the Primary Address is 15.45.125.5.

            By default, the primary IP address is used on the static WAN interface.


            source_ipsec.png

      • Local ID – Enter the local ID.
      • Network Addresses – Add the IP address of the local network, and click +.
    • In the DESTINATION section, specify values for the following:

      • Remote Gateway – Enter a remote gateway.

      • Remote ID – Enter a unique ID. VPN tunnels without remote ID will not establish successfully.

      • Network Address – Add the IP address of the remote network, and click +.
        ipsec_create.png

  8. Click Next.
  9. Complete all remaining configuration steps for the Phases and Network tabs.
  10. Click Save.

After the configuration is complete, you can see a new IPsec tunnel is shown on the IPsec VPN page, and the status of the IPsec tunnel can be verified. For more information, see IPsec VPN.

Further Information