WCC Deployment Quick Start Guide

WCC Deployment Quick Start Guide

Complete the steps in this guide to configure, launch, and license your Barracuda WAF Control Center instance.

Before You Begin

  • The Barracuda WAF Control Center Vx is deployed with one Network Interface Card (NIC) by default

  • The management interface cannot be added without adding the LAN interface

  • For deployments in AWS or Azure, the license type is “Bring your own license” (BYOL)

In this article:

  • Private Cloud indicates systems like VMWare ESXi, Hyper-V, Oracle Virtual Box, etc.

  • Public Cloud indicates Amazon Web Services and Microsoft Azure.

Deployment Steps

Perform the following steps:

Step 1. Open Network Address Ranges 

Ensure that you have network connectivity to "updates.cudasvc.com".

For private cloud deployments, ensure that the network ranges/ports are allowed on the upstream network firewall. For public cloud deployments, create the security group/network security groups.

For more information on the usage of ports for the WCC, check the following table:

Hostname

Port

Direction

TCP/UDP

Purpose

Hostname

Port

Direction

TCP/UDP

Purpose

term.cuda-support.com

22

Outbound

TCP

Technical Support connections

 

25

Inbound/Outbound

TCP

Email alerts

 

53

Outbound

Both

Domain Name Service (DNS)

cnt12.upd.cudasvc.com

80/8000

Inbound/Outbound

TCP

  • Virus/attack/security definition and firmware updates

  • VM provisioning

cnt13.upd.cudasvc.com

cnt14.upd.cudasvc.com

cnt15.upd.cudasvc.com

ntp.barracudacentral.com

123

Outbound

UDP

Network Time Protocol (NTP)

updates.cudasvc.com

443

Outbound

TCP

Initial VM provisioning *

* The initial provisioning port can be disabled after the initial provisioning process is complete.

Connectivity between WAF Instances and the WCC:

Bi-directional traffic for the following ports should be allowed between the WAF WAN IP address and the WCC WAN IP address.

Port

Direction

TCP/UDP

Purpose

Port

Direction

TCP/UDP

Purpose

48320/48321

Inbound/Outbound

TCP

Secure tunnel between the WCC and WAFs

2200

Inbound/Outbound

TCP

File transfer

Step 2. Start the Virtual Appliance, Configure Networking, and Enter the License

You should receive your license token/serial # of Barracuda Vx via email or from the website after you download the Barracuda WAF Control Center Vx package. If not, you can request an evaluation on the Barracuda website at https://www.barracuda.com/purchase/evaluation or purchase one from https://www.barracuda.com/purchase/index. The license token looks similar to the following: 01234-56789-ACEFG.

Virtual Machine Deployment for Private Clouds

Ensure that you make a note of the Barracuda Vx serial number displayed here. The same serial number should be provided as password when you log into the Barracuda Web Application Firewall Vx web interface.

  1. In your hypervisor client, start the virtual appliance and allow it to boot up.

    1. For instructions on deploying the images on specific private cloud platforms, see How to Deploy the Barracuda WAF Control Center Vx image.

    2. For instructions on allocating system resources like CPU, RAM, and storage, see Allocating Cores, RAM, and Hard Disk Space for Your Barracuda WAF Control Center Vx.

  2. After the deployment is complete, access the serial console of the VM, and from the console, log in with the following: username is "admin", and the password is the serial number.

  3. In the System Configuration window, use the down arrow key and select TCP/IP Configuration. Configure the following:

    1. WAN IP Address

    2. WAN Netmask

    3. Gateway Address

    4. Primary DNS Server

    5. Secondary DNS Server

  4. If the Internet can be accessed only through an explicit proxy, configure the proxy server using Proxy Server Configuration (Optional), so that it reaches the Internet for provisioning.

  5. Under Licensing enter your Barracuda License Token and Default Domain to complete provisioning. The appliance will reboot as a part of the provisioning process.