It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda CloudGen Firewall

This Firmware Version Is End-Of-Support

Documentation for this product is no longer updated. Please see for further information on our EoS policy.

How to Configure an ISP with UMTS/3G

  • Last updated on
For locations without land-based Internet connection, or as a backup in case the land-based ISP connections fail, you can use a UMTS/3G broadband modem to connect to a 3G network. Configure the connection settings and introduce a network route via the 3G WAN interface. You can operate the UMTS link in active or standby mode. With active mode, the link is automatically brought up with the network activation process. When operating the link in standby mode, the link is manually brought up and down by a command script.


In this article:

Before you Begin

  • Connect a supported (e.g., Barracuda 3G Modem) to the USB port of the Barracuda NG Firewall.
  • You need the APN configurations settings for your mobile broadband provider.
  • (optional) PIN code to unlock your SIM card.

Step 1. Configure Connection Details

Configure the settings for your UMTS card and specify the connection details.

  1. Open the Network page (Config > Full Config > Box).
  2. In the left menu, select UMTS/3G.
  3. Click Lock.
  4. Set UMTS/3G Enabled to Yes.

  5. To use the 3G modem as a backup connection, set Standby Mode to Yes.

    Standby connections must be started by a command line script. For more information, see Operating an UMTS/3G Link in Standby Mode.

  6. Select your UMTS/3G modem from the UMTS/3G Modem Card list. E.g., Barracuda 3G Modem
  7. Select the interface associated with the UMTS card from the Modem Interface list.
  8. Enter the Access Point Name (APN) as suggested by your provider.
  9. If your SIM card has a PIN code to unlock, enter the SIM PIN.

  10. If required, enter the Phone Number. (Do not enter the # sign.)

    If your mobile broadband provider does not assign a number that ends in 1, switch to Advanced Configuration Mode and change the Context Identifier setting in the PDP Context section accordingly.

Step 2. Configure Authentication

Select an authentication method and enter the PPP credentials provided by your ISP. You can also set up dynamic DNS.

  1. In the Authentication section, select the Authentication Method that is used for the connection.
  2. In the User Access ID field, enter the principal account name (PPP username) assigned to you by your provider.
  3. If your provider assigned a sub-ID to you, enter it in the User Access Sub-ID field. Do not enter the # sign.
  4. Enter the PPP Access Password assigned to you by your ISP.
  5. Select Use ProviderDNS to use the DNS servers assigned by your provider. To use dynamic DNS, select Use Dynamic DNS and click Set. The Dynamic DNS Params window opens.
    1. Select a dynamic DNS Service Type. For information on DynDNS service types, see
    2. Enter the Dyn DNS Name that was registered on
    3. Enter the User Access ID and Password for accessing the service.
  6. Click OK.

Step 3. Configure Routing Settings

Configure the routes and routing tables for the UMTS link.

  1. In the Routing section,
    • Disable Own Routing Table to only insert routes in the main and default tables, or
    • Enable Own Routing Table to use policy routing. With policy routing, a new table named 'umts1' is introduced to the main routing table where UMTS routes are inserted.
      1. To use the IP address dynamically assigned by your ISP as the source network for policy routing, select Use Assigned IP. Until the ISP has successfully assigned an address, the rule uses as a source address.
      2. In the Source Networks table, add source networks or single hosts that will point to the 'umts1' table (IP address/netmask notation; for a single host, enter 32 as netmask (e.g.,
  2. Enable Create Default Route to automatically introduce the default route assigned by the provider.
    • When disabling Create Default Route, you must add Target Networks that are supposed to be reachable through this link.
  3. Use the Remote Peer IP override mechanism if your provider does not assign a remote gateway IP address.
  4. If your default route should be set dynamically when the xDSL connection is established, add to the Target Networks table.
  5. When the OSPF/RIP/BGP service is used, select Advertise Route.
  6. Select a Trust Level to define which IP address types are counted by the firewall for traffic on this interface.
  7. Enable Clone Routes to clone the dynamic routes to the main or default table if Create Default Route is disabled. This setting is useful for setups where application-based selection (explicit binding in a firewall rule) of a traffic path is supposed to coexist with link failover (proxy dynamic).
  8. Specify a Route Metric to assign a preference number to the routes to the specified target networks or if multiple dynamic links are available. To use your UMTS uplink as a backup connection (provider failover), enter a value larger than 0.
  9. Enable GRE with Assigned IP to register the assigned IP address for IP protocol 47.

Step 4. Configure Connection Monitoring

Configure connection monitoring by entering a list of health check targets that are only reachable through this connection. Should the ping to these health check targets fail, the Barracuda NG Firewall will terminate and reestablish the connection until the monitoring target IP addresses are reachable again.

  1. In the Connection Monitoring section, select the Monitoring method:
    • LCP – If ping fails, the dial in daemon is probed directly via LCP.
    • ICMP – The Barracuda NG Firewall probes the Reachable IPs and. if there is no response, the gateway.

    • StrictLCP – No ICMP probing occurs.  

  2. Enter one or more Reachable IPs to monitor the availability of the connection. The target IP addresses should only be accessible via this connection.

    Do not use the Modem Error Policy setting for USB modems such as the Barracuda M10 USB modem. To reset the bus for PCMCIA type modems on persistent error conditions, select Reset-Modem.

  3. Select the Unreachable Action to be taken if the connection cannot be established. The following options are available:
    • Restart – Restarts the connection.
    • Increase-Metric – Changes the preference for UTMS/3G routes until the probe succeeds.
  4. Click OK.

  5. Click Send Changes and Activate.

Your UMTS/3G connection is now active and the IP address assigned by your ISP is visible on the CONTROL > Network page. All status icons next to the ppp5 interface are green, indicating an active connection. If the UMTS/3G connection is your primary uplink, the default route pointing to the ppp5 interface is also created. If more than one default route is present, the connection with the lowest route metric is used.

Step 5. Activate Network Changes

You must activate the network changes to bring up the xDSL connection.

  1. Open the Box page (Control > Box).
  2. In the left menu, expand the Network section and click Activate new network configuration.
  3. Select Failsafe. The 'Failsafe Activation Succeeded' message is displayed after your new network configurations have been successfully activated.

Your xDSL connection is now active and the IP address assigned by your ISP is visible on the CONTROL > Network page. All status icons next to the ppp1 interface are green, indicating an active connection. If the xDSL connection is your primary uplink, the default route pointing to the ppp1 interface is also created. If more than one default route is present, the connection with the lowest route metric is used.

Operating an UMTS/3G Link in Standby Mode

Enable Standby Mode in the link configuration if the UTMS/3G connection is used as a backup connection. In standby mode, the activation and subsequent monitoring of the link must be triggered externally. Standby mode also lets you combine HA setups for HA UMTS/3G connections.

  1. The UMTS/3G routes are set to pending, and the Barracuda NG Firewall does not check whether they are established.
  2. The configuration is completely run through but the connection is not yet established. 

Standby connection can only be started by a command line script. Example usage:

  • Start UMTS connections - /etc/phion/dynconf/network/openumts start first &
  • Stop UMTS connections - /etc/phion/dynconf/network/openumts stop first &

To enable link operation in standby mode,

  1. On the UMTS/3G page, enable Standby Mode.
  2. Select Register in Standby. This accelerates the dial-in process when the link is fully activated.
  3. In the UMTS/3G Connection Details, enable Active GSM Channel to register on the 3G network. No data connection is established when registering on the 3G network.
  4. Click Send Changes and Activate.

You can now use the command line scripts listed above to enable the UMTS/3G connection.

Last updated on