Scope:
This solution applies to the Barracuda Web Application Firewall, all firmware versions.
Answer:
The main differences between the Proxy Mode and the Bridge Mode are as follows:
Proxy Mode
- Supports the creation of HTTP/HTTPS, Instant SSL, redirect, custom SSL/FTP/SSL services.
- You can configure Network ACL, Source NAT and Destination NAT.
- Instant SSL, Real server Load Balancing, TCP Pooling, Content Routing, Caching, and Compression can be achieved (some of these features are not included in 360 model).
- During configuration, more network changes are required.
- Features like Hardware bypass and bypass on failure are not available.
- Requests coming to a non-VIP configured on Web Application Firewall are dropped.
- In proxy mode, services not configured as VIP are not allowed to pass through the box.
Bridge Mode
- You can create HTTP and HTTPS services only.
- You cannot configure Network ACL, Source NAT or Destination NAT in this mode.
- Instant SSL, etc., are not available in this mode.
- Fewer network changes are required, since the existing IP Address infrastructure is reused.
- Features like Hardware bypass and bypass on failure are only available in this mode.
- In bridge mode, services not configured as VIP are allowed to pass through the box by default.
Link to This Page:
https://campus.barracuda.com/solution/50160000000IenHAAS