We use cookies on our website to ensure we provide you with the best experience on our website. By using our website, you agree to the use of cookies for analytics and personalized content.This website uses cookies. More Information
It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda Web Security Service

Proxy and Caching

  • Last updated on

If you are not already in the Barracuda Web Security Service Manager interface, click Barracuda Web Security Service at the top of your Barracuda Cloud Control login screen. The Barracuda Web Security Service Manager interface appears. In the Barracuda Web Security Service Manager, click the CONFIGURATION tab.

Specify proxy and caching settings by selecting the desired Barracuda Web Security Service Connector on the CONFIGURATION > Gateway page and clicking the Proxy/Caching tab. This article describes the settings you can manage on this page.

Upstream Proxy

To configure the upstream proxy for a Barracuda Web Security Service Connector:

  1. In the Upstream Proxy area, enter or edit the fields in the table below.
  2. Click Save Changes.
  3. When prompted to sync the Barracuda Web Security Service Connector, click Sync.
FieldDescription
Send VIA HeaderSelect this option to expose the identity of the Barracuda Web Security Service Connector to web servers
Send Forwarded-For Header

Select this option to allow HTTP requests to:

  • expose the proxy that the Barracuda Web Security Service Connector is using, and
  • expose the client IP address for which the Barracuda Web Security Service Connector is forwarding.
Transparent Proxy PortSpecify the port to use to directly proxy through the Barracuda Web Security Service Connector. Default: 8080
X-Forwarded-For HeaderUsed for header extensions from any proxy for the client IP.This is useful when the Barracuda Web Security Service Connector is on the WAN side of another proxy. Used for logging and reporting only. Default: X-Forwarded-For
HTTP Methods

Specify allowed HTTP methods other than the standard GET, POST, and HEAD.

Example for Subversion: REPORT MERGE MKACTIVITY CHECKOUT

Default values:

  • OPTIONS
  • PUT
  • DELETE
  • TRACE
  • CONNECT
  • PROPFIND
  • PROPPATCH,MKCOL
  • COPY
  • MOVE
  • LOCK
  • UNLOCK
  • VERSION-CONTROL
  • REPORT
  • CHECKOUT
  • CHECKIN
  • UNCHECKOUT
  • MKWORKSPACE
  • UPDATE
  • LABEL
  • MERGE
  • BASELINE-CONTROL
  • MKACTIVITY
HTTP Ports

Allowed HTTP ports for forward proxied clients. Port range 1025-65535 is always allowed.

HTTPS PortsAllowed HTTPS ports for forward proxied clients.

Use Custom Proxy Authentication Settings

Enable this feature to specify the number of proxy authentication helper threads (below).

Number of Proxy Authentication helper threads

After you enable Use Custom Authentication Settings, set the number of helper threads here. Default value:12

Enable Authentication Caching

Enable this feature to allow the Barracuda Web Security Service Connector to cache successful NTLM authentication responses from the domain controller.

Authentication Cache TTL

Time-to-live (TTL), in seconds, for a successful NTLM authentication response. Default: 3600

Disable Proxy CacheSelect this option to disable proxy caching.
Peer Proxy IP

IP address of any pre-existing proxy in front of the Barracuda Web Security Service Connector.

Peer Proxy Port

Port for the IP address of any pre-existing proxy in front of the Barracuda Web Security Service Connector.

Peer Proxy Domains

To specify peer proxy domains for the Barracuda Web Security Service Connector:

  1. In the Peer Proxy Domains area: to edit a peer proxy domain, select the Domain name; to add a peer proxy domain, click Add New Peer Proxy Domain.
  2. In the Add/Update Domain to Peer Proxy screen, enter or edit entries for the fields in the table below.
  3. Click Submit.
  4. Click Save Changes.
  5. When prompted to sync the Barracuda Web Security Service Connector, click Sync.
FieldDescription
Domain

Domain names whose traffic you want sent to the specified peer proxy.

Example: .example.com

EnabledSelect this option to enable the peer proxy domain.

Regular Expression Proxy Authentication Exceptions

To specify regular expression proxy authentication exceptions for the Barracuda Web Security Service Connector:

  1. In the Regular Expression Proxy Authentication Exceptions area: to edit a regular expression proxy authentication exception, select the Regular Expression name; to add a regular expression proxy authentication exception, click Add New Regex Proxy Authentication Exception.
  2. In the Add/Update Regex Proxy Authentication Exception screen, enter or edit entries for the fields in the table below.
  3. Click Submit.
  4. Click Save Changes.
  5. When prompted to sync the Barracuda Web Security Service Connector, click Sync.
FieldDescription
Regular Expression

Enter the regular expression of a URL to exempt from proxy authentication.

To exempt HTTP traffic to example.com and all of its subdomains, enter: ^http://([^:/]*\.)?example\.com/.*$

To exempt HTTPS traffic to mydomain.com and all of its subdomains, enter: ^(.*\.)?mydomain\.com:443

EnabledSelect to enable this option.

Request Header Proxy Authentication Exceptions

To specify Request Header Proxy Authentication Exceptions for the Barracuda Web Security Service Connector:

  1. In the Request Header Proxy Authentication Exceptions area: to edit a request header proxy authentication exception, select the request header name; to add a request header proxy authentication exception, click Add New Request Header Proxy Authentication Exception.
  2. In the Add/Update Request Header Proxy Authentication Exception screen, enter or edit entries for the fields in the table below.
  3. Click Submit.
  4. Click Save Changes.
  5. When prompted to sync the Barracuda Web Security Service Connector, click Sync.
FieldDescription
HeaderExempt clients' browsers/programs which send specific HTTP request headers listed here. Example:: Header:User-Agent Pattern Regex:Java.*
Pattern RegexEnter the pattern regex in the text box.
EnabledSelect to enable this option.

Source IP Proxy Authentication Exceptions

To specify Source IP Proxy Authentication Exceptions for the Barracuda Web Security Service Connector:

  1. In the Source IP Proxy Authentication Exceptions area: to edit an exception, select the exception name; to add an exception, click Add New Source IP Proxy Authentication Exception.
  2. In the Add/Update Source IP Proxy Authentication Exception screen, enter or edit entries for the fields in the table below.
  3. Click Submit.
  4. Click Save Changes.
  5. When prompted to sync the Barracuda Web Security Service Connector, click Sync.
FieldDescription
IP Address
IP Address of the Source to be exempted.
NetmaskNetmask for the Source IP Address.
EnabledSelect to enable this option.

Destination IP Proxy Authentication Exceptions

To specify Destination IP Proxy Authentication Exceptions for the Barracuda Web Security Service Connector:

  1. In the Destination IP Proxy Authentication Exceptions area: to edit an exception, select the exception name; to add an exception, click Add New Destination IP Proxy Authentication Exception.
  2. In the Add/Update Destination IP Proxy Authentication Exception screen, enter or edit entries for the fields in the table below.
  3. Click Submit.
  4. Click Save Changes.
  5. When prompted to sync the Barracuda Web Security Service Connector, click Sync.
FieldDescription
IP Address
IP Address of the Destination to be exempted.
NetmaskNetmask for the Destination IP Address.
EnabledSelect to enable this option.

Domains Not Cached

To specify Domains excepted from caching for the Barracuda Web Security Service Connector

  1. In the Domains Not Cached area: to edit a Domain, select the Domain name; to add a Domain, click Add New No Cache Domain.
  2. In the Add/Update No Cache Domain screen, enter or edit entries for the fields in the table below.
  3. Click Submit.
  4. Click Save Changes.
  5. When prompted to sync the Barracuda Web Security Service Connector, click Sync.
FieldDescription
Domain Name
Name of Domain exempted from caching.
EnabledSelect to enable this option.

Exempt Domains

To specify Domains to exempt from sending to the Barracuda Web Security Service (applies in Service Enforcement mode only):

  1. In the Exempt Domains area: to edit a Domain, select the Domain name; to add a Domain, click Add New Exempt Domain.
  2. In the Add/Update Exempt Domain screen, enter or edit entries for the fields in the table below.
  3. Click Submit.
  4. Click Save Changes.
  5. When prompted to sync the Barracuda Web Security Service Connector, click Sync.
FieldDescription
Domain Name
Name of Domain whose traffic is not sent to the Barracuda Web Security Service.
EnabledSelect to enable this option.

Exempt Networks

To specify Networks to exempt from sending to the Barracuda Web Security Service (applies in Service Enforcement mode only):

  1. In the Exempt Networks area: to edit a Network, select the Network name; to add a Network, click Add New Exempt Network.
  2. In the Add/Update Exempt Network screen, enter or edit entries for the fields in the table below.
  3. Click Submit.
  4. Click Save Changes.
  5. When prompted to sync the Barracuda Web Security Service Connector, click Sync.
FieldDescription
Network
Name of Network whose traffic is not sent to the Barracuda Web Security Service.
EnabledSelect to enable this option.
Last updated on