We use cookies on our website to ensure we provide you with the best experience on our website. By using our website, you agree to the use of cookies for analytics and personalized content.This website uses cookies. More Information
It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda CloudGen Firewall

This Firmware Version Is End-Of-Support

Documentation for this product is no longer updated. Please see End-of-Support for CloudGen Firewall Firmware for further information on our EoS policy.

Best Practice - Changing the VIP Address of a Managed F-Series Firewall

  • Last updated on

To change the virtual IP (VIP) address of a centrally managed Barracuda NextGen Firewall F-Series, edit the VIP settings and back up the firewall configuration in the Barracuda NextGen Control Center. Then, directly connect to the Barracuda NextGen Firewall F-Series and restore it with the configuration backup that includes the new VIP settings.

In this article


Step 1. Add the New VIP Network Range

On the Barracuda NextGen Control Center, add the network range of the new VIP address. Keep the existing VIP network range.

  1. Go to CONFIGURATION > Configuration Tree > Multi-Range > Global Settings > Box VIP Network Ranges.
  2. In the left menu, select VIP Networks.
  3. Click Lock.
  4. In the VIP Networks table, add an entry for the network range. Configure the following settings for the entry: 
    • Name – A name for the network range.  
    • Network Address – The first IP address in the network range.
    • Netmask – The netmask.
  5. Click OK.
  6. Click Send Changes and Activate.

Step 2. Change the Virtual IP Address of the Barracuda NextGen Firewall F-Series

On the Barracuda NextGen Control Center, change the VIP address of the Barracuda NextGen Firewall F-Series.

  1. Go to CONFIGURATION > Configuration Tree > Multi-Range > your range > your cluster > your box > Network.
  2. In the left menu, select Management Access.
  3. Click Lock.
  4. Write down the existing Virtual IP (VIP) address. You will need this address later.
  5. Change the Virtual IP (VIP) address. 
  6. Click Send Changes and Activate.

Step 3. Create a PAR File for the Barracuda NextGen Firewall F-Series

On the Barracuda NextGen Control Center, back up the configuration of the Barracuda NextGen Firewall F-Series to a PAR file. For instructions, see How to Back Up and Restore Your Systems.

Step 4. Modify the Management Access Firewall Rule for the Barracuda Control Center

To ensure that the Barracuda NextGen Control Center can still connect to the old VIP address of the Barracuda Firewall, edit its MANAGEMENT-ACCESS-TO-BOXES forwarding firewall rule to allow access to the old VIP address. 

In the Destination table of the MANAGEMENT-ACCESS-TO-BOXES rule, add the old VIP address of the firewall.

VIP Change.png 

After you successfully change VIP addresses, Barracuda Networks recommends that you remove the old VIP address.

Step 5. Restore the Barracuda NextGen Firewall F-Series

From the Barracuda NextGen Control Center, directly connect to the Barracuda NextGen Firewall F-Series with the old VIP address because the firewall is still using this VIP address. Then, assign the new VIP address to the Barracuda NextGen Firewall F-Series by restoring the firewall with the PAR file that you created in Step 3. Create a PAR File for the Barracuda NextGen Firewall F-Series.

For more instructions on how to restore a Barracuda NextGen Firewall F-Series with a PAR file, see How to Back Up and Restore Your Systems.

After restoring the configuration, go to the Control > Box page and execute a Soft network activation.

Last updated on