We use cookies on our website to ensure we provide you with the best experience on our website. By using our website, you agree to the use of cookies for analytics and personalized content.This website uses cookies. More Information
It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda CloudGen Firewall

Best Practice - Hostname List for Barracuda Online Services

  • Last updated on

Access to hosts and domains in the Barracuda Cloud is required for the proper operation of a NextGen Firewall or Control Center. Ensure that the proper ACLs are in place to allow access to these services:

Update Servers - Port 80, 443

  • updates.cudasvc.com
  • - barracuda.com
  • - cntdtw02.sup.cudaops.com
  • *.upd.cudasvc.com
  • cnt01.upd.cudasvc.com - cnt15.upd.cudasvc.com

These update servers deliver pattern updates for the following services and features:

Download Portal - Port 443

  • dlportal.barracudanetworks.com
  • d.barracudanetworks.com

The download portal hosts all update packages, as well as hotfixes, and the associated tools and utilities used to run the firewall. The firewall queries the download portal for a list of available hotfixes and updates matching the firmware version.

For more information, see DASHBOARD General Page and Updating F-Series Firewalls and Control Centers.

License Activation Server - Port 443

  • bcc.barracudanetworks.com
  • api.bcc.barracudanetworks.com

Used to send license activation service, and to continuously poll for licenses available for the serial number associated with the firewall or Control Center.

For more information, see How to License a NextGen Firewall and Licensing F-Series Firewalls in the Control Center.

Zero Touch Deployment - Port 443


The Control Center queries the list of available Zero Touch-enabled firewalls from this service and pushes the minimal configurations to the cloud service, pending retrieval from Zero Touch-ordered firewalls.

For more information, see Zero Touch Deployment.

Authentication Servers

  • auth.useast1.aws.svc.fusion.cudasvc.com
  • auth.eucentral1.aws.svc.fusion.cudasvc.com
  • auth.uswest1.aws.svc.fusion.cudasvc.com
  • auth.euwest1.aws.svc.fusion.cudasvc.com
  • auth.svc.fusion.cudasvc.com

ATP Server

  • api-euwest1-aws.batd.cudasvc.com
  • api-uswest1-aws.batd.cudasvc.com
  • api-apsoutheast1-aws.batd.cudasvc.com
  • api-useast1-aws.batd.cudasvc.com
  • api-eucentral1-aws.batd.cudasvc.com
  • api-apsoutheast2-aws.batd.cudasvc.com
  • api-useast2-aws.batd.cudasvc.com
  • api-apnortheast1-aws.batd.cudasvc.com
  • *.batd.cudasvc.com

Barracuda ATP cloud services. If ATP is enabled, the firewall uploads files to be scanned via ATP to these services.

For more information, see Advanced Threat Protection (ATP).

URL Categorization Servers

  • api.useast1.aws.wcs.cudasvc.com
  • api.apsoutheast2.aws.wcs.cudasvc.com
  • api.euwest1.aws.wcs.cudasvc.com
  • api.uswest1.aws.wcs.cudasvc.com
  • api.eucentral1.aws.wcs.cudasvc.com
  • api.apnortheast1.aws.wcs.cudasvc.com
  • *.wcs.cudasvc.com

Barracuda online URL categorization services used by the Barracuda URL Filter in the firewall.

For more information, see URL Filtering in the Firewall.

DNS Blacklist


If the DNS Blacklisting is configured, the firewall checks the hostnames in the DNS queries against this online service.

For more information, see  Botnet and Spyware Protection in the Firewall.

Link Protection

  • linkprotect.useast1.aws.cudaops.com
  • linkprotect.eucentral1.aws.cudaops.com
  • linkprotect.uswest1.aws.cudaops.com
  • linkprotect.euwest1.aws.cudaops.com
  • linkprotect.cudasvc.com

If the Mail Security in the Firewall and Link Protection is configured, the firewall checks the hostnames in the DNS queries against this online service.

For more information, see How to Configure Link Protection for Mail Security in the Firewall.

AWS / Azure and Google Cloud APIs

Firewalls and Control Centers deployed to the public cloud use API calls for Cloud Integration features.

For more information, see Public Cloud.

Public Cloud Datacenter Network Objects

  • https://www.microsoft.com/en-us/download/confirmation.aspx?id=41653
  • https://ip-ranges.amazonaws.com/ip-ranges.json

To fill network objects with up-to-date IP ranges used by Azure and AWS data centers, the firewall queries these two services.

For more information, see How to Configure Network Objects for AWS and Azure Datacenter Networks.

Last updated on