Barracuda Web Application Firewall

How do I link / cluster Barracuda Web Application Firewalls in Bridge-Path Mode?

  • Date changed: 2 years ago

All Barracuda Web Application Firewalls.


Two Barracuda Web Application Firewalls can be linked to create a high availability environment. If the primary unit goes down for any reason the backup unit assumes the role of the primary. This provides continuous network availability.


Primary Unit

  1. Go to the Basic > IP Configuration tab, and fill-in the WAN IP Configuration section. With Bridge-Path mode, the WAN and LAN interfaces must be on physically separate networks and the LAN interface must be on the same logical switch as the servers.
  2. Set the Bypass on Failure parameter to No.
  3. Set the Monitor Link parameter for the WAN configuration to Yes, and then click Save Changes.
  4. Go to the Advanced > High Availability tab and add a password in the Cluster Shared Secret field, and then click Save Changes. Both units in the cluster must have the same shared secret to communicate.
  5. In the Clustered Systems section, check the status of the Clustered System and verify that its status is Green (communicating).


Backup Unit


Ensure you can reach the WAN and LAN port of the primary unit from the backup unit before you add the backup unit to the cluster. Do this from the Ping Device option under the Advanced > Troubleshooting tab.

  1. Same as Step 1 above. 
  2. Same as Step 2 above. 
  3. Same as Step 3 above.
  4. Same as Step 4 above. The shared secret should be the same as the Primary unit.
  5. In the Clustered Systems section, enter the WAN IP address of the backup unit and click Join Cluster.
  6. Same as Step 5 above.


Clustering in Bridge Mode:

  • When you want to cluster two machines in Bridge mode for High Availability, first put the desired secondary or backup unit in proxy mode. Once you join the two using the above steps, the secondary machine will synchronize configuration from the primary and switch to Bridge mode.
  • Ensure both devices are configured with correct and same time and time zone.
