Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Web Application Firewall Streamline On-Premises Central Management
News & Analysis

Web Application Firewall Streamline On-Premises Central Management

ISBuzz TeamBy ISBuzz TeamJune 30, 2015Updated:June 30, 20155 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Microsoft Admits PaperCut Servers Used By LockBit and Cl0p Ransomware
City Of Toronto Admits Data Theft, Clop Takes Blame
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Web Application FirewallLatest Version Includes Support for SAML and JSON Payload Inspection

  • With the latest version of Barracuda Web Application Firewall, version 8.0, Barracuda released support for the latest enhancements to Barracuda Control Server, its on-premises platform for central management, to further streamline the management of product updates, shared policies, and services across multiple clusters and data center locations.
  • Building on its support for Microsoft Azure AD, Barracuda Web Application Firewall now offers enhanced support for Security Assertion Markup Language (SAML) to enable it to work with a broader range of systems utiliisng SAML, including Microsoft ADFS, Swiss ID, and more.
  • The latest version of Barracuda Web Application Firewall also enhances support for JavaScript Object Notation (JSON) payload inspection, as JSON payloads are increasingly used for Representational State Transfer (REST) application program interface (API) calls and other web technologies to deliver cloud, software-as-a-service (SaaS), and mobile applications.

“As virtualisation continues to foster dispersion of applications and data, we have seen our customers distribute security enforcement points across different parts of the network and across data centers,” noted Stephen Pao, GM Security, Barracuda. “While security enforcement points disperse, IT operations managers continue to express their desire to manage those dispersed enforcement points from a single pane of glass. The enhancements made to Barracuda Web Application Firewall and Barracuda Control Server came from direct customer feedback around many of these use cases.”

Streamlined Centralised Management Across Clusters and Data Centers

The latest version of Barracuda Web Application is designed to work with the latest enhancements to the Barracuda Control Server, available for on-premises deployments as a virtual appliance. The Barracuda Control Server provides a scalable, centralised console for unified management, control, and visibility across multiple Barracuda appliances and virtual appliances.

Highlights of the latest Barracuda Control Server release include:

  • Service-Level Configuration Templates– Service-Level configuration templates are typically used when promoting individual services across various phases of a deployment lifecycle. For example, as an individual web application is moved through alpha, beta, stage, and production environments, configuration templates can be used to migrate settings associated with that individual application. Previously, the Barracuda Control Server supported migration of configurations at an appliance-level, not at an individual service level.
  • Shared Policy Templates – Shared policy templates are used to ensure consistent security policy across multiple services within a single physical or virtual appliance configuration, as well as across appliances.
  • Centralised Firmware Revision Management– Barracuda Control Server now includes an interface that can be used to centrally manage similar and disparate product revisions across a deployment. Previously, Barracuda Control Server only supported product update management at an appliance or configuration group level.

Enhanced Support for SAMLv2 Access Control

In addition to application security, the Barracuda Web Application Firewall provides a front end for access control to web applications, including single-sign on and multi-factor authentication. Last October, Barracuda announced the ability for the Barracuda Web Application to federate identity with Microsoft Azure AD, a SAML-based identity provider.

To further increase compatibility with additional SAML use cases, the latest version of Barracuda Web Application Firewall adds additional capabilities.  Highlights include:

  • SAML-based Conditional Access Rules – Several applications require conditional access based on certain attributes associated with the user. These attributes could be organisational – like role, group membership, or personal – like device type, age, postal code, etc. Administrators can now create such conditional access rules based on the attributes in SAML assertions from the Identity Provider (IdP). Conditional access rules can be granularly created across different security domains within the web application.
  • Support for Multiple IdP – Users can now log into protected web applications through multiple trusted SAML providers. The Barracuda Web Application Firewall provides the users with IdP selection dialogs to specify their preferred IdP for authentication and assertion requests.

These new capabilities allow the Barracuda Web Application Firewall to extend beyond the simpler SAML use cases for Azure AD to support other SAML identity providers including Microsoft ADFS and Swiss ID.

Enhanced JSON Payload Inspection

Changes in web programming techniques used in cloud, SaaS, and mobile applications continue to challenge traditional service-oriented architecture (SOA) gateways and intrusion detection systems (IDS).  In particular, increased use of JSON and REST based technology has changed both the usage and interaction over customarily used Hyper Text Transfer Protocol (HTTP) transactions. The latest version of Barracuda Web Application Firewall enhances its ability to secure JSON payloads, to provide comprehensive security for REST APIs and dynamic web applications.

Barracuda Total Threat Protection

Barracuda Web Application Firewall and Barracuda Control Server are part of the Barracuda Total Threat Protection initiative, which is aimed at providing powerful, integrated security protection across multiple threat vectors at an affordable cost. Barracuda Total Threat Protection is designed to protect multiple threat vectors – including email, web applications, remote access, web browsing by network users, mobile Internet access, and network perimeters – that span private and public cloud deployments. It includes the combination of award-winning security solutions, a common management interface, a single point of support, and affordability.

About Barracuda Networks, Inc. (NYSE: CUDA)

Barracuda (NYSE: CUDA) provides cloud-connected security and storage solutions that simplify IT. These powerful, easy-to-use and affordable solutions are trusted by more than 150,000 organisations worldwide and are delivered in appliance, virtual appliance, cloud and hybrid deployments. Barracuda’s customer-centric business model focuses on delivering high-value, subscription-based IT solutions that provide end-to-end network and data security.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Managing App Access on Frontline Devices in an Always-On World

March 9, 20264 Mins Read

OWASP Top 10 2025: New Enemies, Old Foes, and an Approach to Vulnerability Remediation That Must Evolve

January 22, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 404

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}