Single Services per F-Series Firewall
You can only use one Forwarding or Distributed Firewall service per F-Series Firewall. Running a Distributed and Forwarding Firewall service on the same F-Series Firewall, automatically disables the Forwarding Firewall service.
Dependent Services
The functionality of certain services depends on additional services on the Barracuda NextGen Firewall F-Series.
- The VPN service interacts with the Forwarding Firewall and only works in combination with the Firewall service.
- When using Application Control, the Firewall service interacts with the Virus Scanner and URL Filter service and must be on the same server.
- The DHCP Relay service can interact with the DHCP service if introduced. You can create a DHCP server on the same system as a DHCP relay agent. However, the services cannot use the same interface.
Interacting Services
In order to function or interact properly, some services require the same virtual server.
- The URL Filter service must be always be on the same virtual server as the HTTP Proxy service.
- When using the Mail Gateway service together with the Spam Filter service, make sure that you introduce them on the same virtual server. Virus Scanner service, when configured, should also be on that server because these services all interact with each other. This setup is required when using Application Control 2.0.
- When using VPN, make sure that you introduce the VPN service on the same virtual server as the Forwarding Firewall service.
Multiple Service Setup
Some services can be run multiple times on the Barracuda NextGen Firewall F-Series.
- Configuring multiple HTTP Proxy services is possible, e.g., to proxy HTTP/S traffic using different modes. You can introduce the HTTP Proxy services in forward, reverse, and transparent mode, depending on your network requirements.
Service Setup in HA Environments
When setting up HA clusters, you can create virtual servers with services to run only on the secondary unit that, in case of a failover, are transferred to the primary unit and vice versa. This is possible for independent services such as DHCP, DNS, and HTTP Proxy. When introducing the latter in combination with the URL Filter service, both services must be configured on the same virtual server on the secondary unit.