It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda SecureEdge

SecureEdge Licensing

  • Last updated on

Barracuda SecureEdge supports various components and types of deployment. Licensing differs according to the component your SecureEdge is deployed on. For detailed specifications on SecureEdge components and types of deployment, see SecureEdge Specifications.

SecureEdge Components and Types of Deployment

Campus Diagram Template.svg

Following are the main components and types of deployment of SecureEdge:

The SecureEdge Manager

The Barracuda SecureEdge Manager, a cloud web UI, is the central management portal of Barracuda SecureEdge.

The benefits of using the SecureEdge Manager
  • Enables you to create, update, and delete components/infrastructure in your Barracuda account.

  • Enables central management of all Barracuda SecureEdge components in an organization’s network. For example, you can manage all your Edge Services, sites, and appliances, and perform various configuration and maintenance actions.

  • This cloud-based management user interface is activated with the first SecureEdge order and is free-of-charge.

For more information, see SecureEdge Manager.

SecureEdge Site Device

The SecureEdge Site device is an on-premises component of SecureEdge and can be run efficiently on hardware or virtual appliances. It provides purpose-built hardware and virtual appliances designed to protect and connect your network infrastructure. Barracuda SecureEdge appliances are available in multiple hardware models to meet networking requirements, ranging from small and home offices up to large data centers. A SecureEdge Site device offers the following advantages:

  • It can act as a stand-alone Firewall, SD-WAN device, Secure Web Gateway, ZTNA device, or Cloud-On ramp device to a SecureEdge Service - or a combination of any of these.

  • It can be easily configured to provide private Edge Services at no additional charge.

Note that, as for all Barracuda products, an active Energize Updates subscription is mandatory for every site device (hardware or virtual).

For more information on hardware models, see Hardware Models.

For an overview of virtual models, see Virtual Systems (VTx) Deployment.

SecureEdge Access Agent

SecureEdge Access lets you implement secure access to internal and external enterprise resources, whether they are on-premises or in the cloud, by using a Zero Trust endpoint solution known as the SecureEdge Access Agent. SecureEdge Access brings Zero Trust access service to your endpoint with a quick and easy configuration.

The benefits and features of using the SecureEdge Access Agent
  • It provides DNS-based URL filtering, Secure Internet Access (SIA), and secure Zero Trust Access (ZTNA) to any cloud - public or private - or SaaS application.

  • It is available for all desktop and mobile platforms.

  • Licensing is user based and is known as seats and covers up to 10 devices per user (also for simultaneous use). Available or unused seats can be transferred within an account.

  • The minimum initial order quantity for SecureEdge Access Agent seats is 25. SecureEdge Access Agent seats include the Edge Service provided by Barracuda Networks that allows for remote filtering and remote ZTNA-based application access with multiple browser tabs or virtual desktops.

  • Additional Edge Service bandwidth is available for purchase in 50 Mbit increments.

For SecureEdge Access, it is licensed per seat and these seats are transferable within an account.

For more information on getting started with SecureEdge Access, see Zero Trust Network Access Set Up Wizard and SecureEdge Access.

SecureEdge Services

The architecture of Barracuda SecureEdge Services follows a classic hub-and-spoke topology. The hub is referenced as an Edge Service in SecureEdge, and the spokes are referenced either as Site, IoT, or Connector. Edge Services act as the central hub in your network, both for SD-WAN and ZTNA.
To get the best solution designed to fit the requirements of your organization, the following types of Edge Services are available:

  • Edge Service – The Software-as-a-Service approach is deployed via a fully managed SaaS service, provisioned by Barracuda Networks and licensed in 50 Mbit increments up to 1 Gbit. For more information on how to configure the Edge Service, see Barracuda Edge Service.

  • Edge Service for Virtual WAN – In an Azure-integrated deployment, this component is deployed and billed through Azure Marketplace, with the workload running inside the organization's Microsoft Virtual WAN service. From a performance-based perspective, the license is available for a variety of scale units (from 2 to 80) with aggregated bandwidths between 1 and 40 Gbps. For more information, see Edge Service for Virtual WAN.

  • Private Edge Service – For a private or an on-premises deployment of the Edge Service, a SecureEdge Site device can be promoted to be a Private Edge Service. A Site device (either hardware or virtual) with a valid Energize Updates subscription is required for such a setup. For more information on how to set up a Private Edge Service, see Private Edge Service.

SecureEdge Connector Software

SecureEdge Connectors help to keep your devices secure by redirecting traffic through a secure VPN connection. The SecureEdge Connector is a small software agent, managed by the SecureEdge Manager for Linux or Windows servers, that is deployed with one or multiple target applications.

The benefits of using a SecureEdge Connector
  • Use ZTNA to access any application in any public cloud or site.

  • Connect to numerous applications on Windows and Linux servers and in the cloud via one-click Connector deployments.

  • Establish a secure VPN connection between the service and a resource you are connecting to.

SecureEdge Connector comes in two variations
  • Inbound traffic – This variant does not require a license but requires a valid Edge Service subscription or validly licensed Site appliance.

  • Routed traffic – Requires a valid license.

For more information on the SecureEdge Connector, see SecureEdge Connector.

For more information on the SecureEdge Connector on a Linux client, see SecureEdge Connector on Linux Client.

Secure Connector IoT Device

The Barracuda Secure Connector is a hardware device that allows you to connect remote appliances and micro-networks to the corporate data center via the VPN.

  • To integrate a Secure Connector device for IoT environments in your Barracuda SecureEdge deployment, you must create a site configuration with the basic settings for each SecureEdge appliance.

  • Barracuda Networks provides purpose-built connectivity appliances with a minimal footprint and DIN-rail compatibility.

  • For harsh environment, rugged hardware models are available.

  • Usage of Secure Connector devices requires a valid service subscription for the numbers of devices in use.

For more information, see Secure Connector IoT device.

Subscriptions

The following table provides an overview of the subscriptions available for your SecureEdge product.

Desktop Hardware

1U Rack Mount Hardware

DIN Rail Compatible Hardware

Virtual

Connector (software)

T100

T200

T400

T600

T900

T93

T193

Secure Connector 2

Secure Connector 3

VT100 - VT5000

Inbound

Routed

Available Software/Feature or Service Subscriptions

Energize Updates (EU)

Mandatory

Mandatory

Mandatory

* EU is included with Connector SKU

* EU is included with Connector SKU

Mandatory

not required

included with Connector SaaS SKU

Additional Subscriptions

Instant Replacement (IR)

optional

optional

optional

optional

optional

n/a

n/a

n/a

Energize Updates (EU)

Barracuda Energize Updates helps you secure your investment in the ever-changing IT world. With an Energize Updates subscription you will receive security updates to patch or repair any security vulnerabilities, keep your Barracuda product up-to-date and fully functional at all times, and get access to our award-winning support.

Note that an active EU subscription is mandatory for all SecureEdge hardware and virtual models. The subscription is available on a monthly basis or as SaaS. For more information, see standard benefits of Energize Updates.

  • In addition, the EU subscription also covers the SecureEdge site devices Txx and VTxx:

    • SD-WAN

    • Firewall and Application Control

    • Web Filter

    • IPS

    • Deep TLS/SSL Inspection

    • Malware Protection with Advanced Threat Protection

Important Information Related to License Expiration Behavior

If the mandatory subscription Energize Updates expires, the following functional restrictions will apply:
  • Stand-alone units
    Units remain accessible via the SecureEdge Manager but no configuration changes will be accepted. Traffic will keep flowing through the device. Basic firewall functionality will keep working. Locally stored security functions like IPS with IPS signatures stored locally will keep working but will no longer receive updates and will therefore quickly become outdated. Security functions relying on active cloud services provided by Barracuda Networks, like Advanced Threat Protection and URL filtering, will no longer work.

  • Units connected to a SecureEdge Service via SD-WAN or units configured as a Private Service Edge
    In addition to the above, the SD-WAN tunnels will terminate, and all ZTNA connections, point-to-site tunnels, and Connector tunnels will terminate.

Instant Replacement (IR)

One-hundred percent uptime is important in corporate environments, but sometimes equipment can fail. In the rare case that a Barracuda product fails, Barracuda ships a replacement unit on the same or next business day. And with the Hardware Refresh Program, we ensure that customers benefit from the latest hardware improvements and firmware capabilities:

  • Enhanced support via phone and email support 24/7.

  • Free hardware refresh after four years of continuous IR coverage.

Must be purchased within 60 days of hardware purchase and is a continuous subscription from the date of activation.

Note that the Instant Replacement service applies to customers worldwide, except Brazil, China, and Japan.

For more information, see Barracuda Instant Replacement.