After you set up Barracuda WAF-as-a-Service for one or more of your applications, ensure that users cannot access your application server directly, without going through Barracuda WAF-as-a-Service.
For accounts created on or after November 5, 2019
Barracuda WAF-as-a-Service provides the IP ranges you need to accept.
To locate the IP ranges:
- Log into Barracuda WAF-as-a-Service and navigate to Applications.
- Click the application name.
- In the left panel, select Endpoints.
- On the Endpoints page, locate the IP Ranges to Allow section. Click Show IPs, then copy the IP ranges listed.
- Configure your backend server to accept traffic only from those IP ranges. See sections below for guidance.
For accounts created before November 5, 2019
Configure your application server to accept traffic only from the following Barracuda IP ranges.
64.113.48.0/20
34.228.125.58/32
51.103.8.8/31
52.142.154.84/31
Configuring Your Backend Server
Consult your backend server documentation for specific instructions on this process. Here are links to some backend server documentation sets.
Application Servers
Host-Based Network Firewall
Cloud-Based Networks and Firewalls
- Barracuda CloudGen Firewall Access Rules
- Microsoft Azure Network Security Groups
- Amazon Web Services Security Groups
- Google Cloud Platform VPC Firewall Rules