Telemetry Data
To be able to continuously update and improve frequently used features based on real-world data, the Barracuda CloudGen Firewall sends performance and usage data to the Barracuda telemetry servers. Sending statistics is opt-out for new or freshly installed CloudGen Firewalls, and opt-in for updated firewalls. After collecting data, the CloudGen Firewall starts one attempt to update the telemetry data via an HTTPS connection. If the connection to the update servers fails, no further attempts are made until the next day. A copy of all parameters sent to the telemetry servers is logged every time an update is initiated.
The Barracuda Firewall Control Center sends data collected only on the box level. No data from the Control Center layer is collected. For firewalls in the public cloud (AWS, Google, or Azure), telemetry cannot be completely disabled; the minimal set of parameters is always transmitted.
As of firmware 9.0, it is mandatory to send telemetry data. Therefore, the option to disable sending telemetry data has been removed.
However, boxes where it was disabled previously, now show the '0' value in the user interface.
Telemetry Default Settings
Depending on the firmware version, the default setting for telemetry can be different.
If you are running a firewall with a fresh installation of firmware release 9.0.0, sending telemetry data is enabled per default.
If you are running a firewall deployed with an old firmware version that has been updated until version 8.3, sending telemetry data is disabled per default.
Also note that for managed firewalls, settings displayed in the UI on the Control Center and on the managed box can differ depending on the cluster and firmware version.
| Cluster < 9.0, Firewall >= 9.0 | Cluster >= 9.0, Firewall < 9.0 |
|---|---|---|
Control Center | On a CC: "Share Telemetry Data" displays "Disabled". | The CC displays that telemetry data is being sent. |
Firewall | On a firewall: "Share Telemetry Data" displays "Full System Diagnostics and Analytics" and the box is sending data. | The firewall is not sending data. |
Barracuda Telemetry Server
airlock.nap.aws.cudaops.com
Telemetry Parameter List
Name | Key | Value Type | Minimal Dataset | Full Dataset | Description |
|---|---|---|---|---|---|
General Information | |||||
Telemetry Amount | telemetry_amount | full/minimal | Yes | Yes | Whether the full or minimal amount of telemetry data is sent |
Serial Number | sn | Number | Yes | Yes | Serial number of the box |
MAC Address | mac | MAC address (hex format) | Yes | Yes | MAC address used for the license |
Model | appliance | Type | Yes | Yes | The appliance type, e.g., T100 for a SecureEdge T100 or VT1500 for a virtual appliance VT1500 |
Model | model | Type | Yes | Yes | The appliance type, e.g., T100 for a SecureEdge T100 or VT1500 for a virtual appliance VT1500 |
Virtual Type | virt_type | Type | Yes | Yes | Information about the hypervisor (VMware, Azure...) |
Virtual Subtype | virt_subtype | Type | Yes | Yes | Information about the hypervisor |
DevMap | devmap | Text | No | Yes | Device mapping |
Number of CPUs | numcpu | Number | Yes | Yes | Number of CPUs |
Memory Usage | memory | Percent | No | Yes | Percent of used memory |
Swap usage | swap | Percent | No | Yes | Percent of used swap memory |
Average CPU Load | cpu | Float | No | Yes | 15-Minute CPU average load at the moment of collecting the data |
Used Firmware Partition | diskfirmware | Percent | No | Yes | Allocation of partition "/" in percent |
Used Data Partition | diskdata | Percent | No | Yes | Allocation of partition "/phion0" in percent |
Firmware Version | firmware | Version String | Yes | Yes | Version of the CloudGen Firewall firmware software |
Firmware Timestamp | firmware_timestamp | Number | Yes >=9.0.6, 10.0.2, 10.5.0 | Yes >=9.0.6, 10.0.2, 10.5.0 | Timestamp of the last firmware change |
Uptime | uptime | Seconds | Yes | Yes | Box uptime in seconds |
Box Location | country | Location | Yes | Yes | Location of the box if configured |
Stand-Alone / Centrally Managed | mcmanaged | Yes / No | Yes | Yes | Is box managed by a control center |
EU Expiration Date | euexpiration | Date | Yes | Yes | Expiration Date of the Energize Updates |
EU Status | eustate | Status | Yes | Yes | Status of Energize Updates |
License Information | license_information | Json Object | Yes | Yes | A Json array that contains, for each license, the license type and |
License Status | licstatus | Status | Yes | Yes | Status of the license |
License Download Timestamp | licdownload_timestamp | Number | Yes >=9.0.6, 10.0.2, 10.5.0 | Yes >=9.0.6, 10.0.2, 10.5.0 | Timestamp of the last box-level license download |
Firewall Insights Configured | fwinsights_configured | Yes / No | No | Yes | Is Firewall Insights configured |
Firewall Insights Licensed | fwinsights_licensed | Yes / No | No | Yes | Is Firewall Insights licensed |
Virtual WAN for Azure Cloud | azurevwan_configured | Yes / No | No | Yes | Is vWAN for Azure Cloud enabled |
Web User Interface | ismanagedbywebui | Yes / No | No | Yes | Is Web UI enabled |
Kernel architecture | kernelarchitecture | Text | No | Yes | Is it a 32 or 64 bit system |
Metered Cloud Device | metered_ng | Yes / No | Yes only in versions < 10.0.0 | Yes only in versions < 10.0.0 | Is the appliance a metered cloud appliance (only in versions < 10.0) |
Time | server_timestamp | Time | No | Yes | Current time as Unix timestamp |
Telemetry configuration | telemetry_amount | String | Yes | Yes | Minimal or full telemetry |
Virtual Routing and Forwarding | vrf | Number | No | Yes | Number of VRF instances in use |
REST API Requests | rest_requests | Json object | No | Yes | Number of REST requests, grouped by role and category |
REST API over TLS | restd_ssl_configured | True / False | No | Yes | If TLS is configured for REST API queries |
Master Name | mastername | String | No | Yes | Master name of the Control Center by which the CloudGen Firewall is managed (only if it is a managed CloudGen Firewall) |
Tesseract ID | tesseract_id | String | No | Yes | Identifier of SecureEdge appliances |
Authentification Serial Number | auth_serial | String | No | Yes | Authentification serial number of SecureEdge appliances |
SecureEdge Managed Gateway | managedgateway | Yes/No | No | Yes | ‘Yes’ if appliance is a SecureEdge managed gateway |
Disk Encryption | isdiskencrypted | True / False | No | Yes | If disk is encrypted |
Reset Button for System Recovery | recovery_button | Enabled / Disabled | Yes | Yes | If the reset button is enabled for initiating system recovery by a long button press. |
Services | |||||
App Control | appcontrol | Status | No | Yes | Shows the status of Application Control (license and activation) |
TLS Inspection | sslice | Enabled / Disabled | No Yes: >= 9.0.6, 10.0.2, 10.5.0 | Yes | TLS Inspection for firewall service enabled |
TLS Inspection Timestamp | sslice_timestamp | Number | Yes | Yes | Timestamp of the last TLS inspection configuration change (enable/disable) |
Port Protocol Protection | protocolprotection | Enabled / Disabled | No | Yes | Is protocol protection in the firewall service enabled |
Google Safe Search | safesearch | Enabled / Disabled | No | Yes | Google Safe Search enabled |
YouTube for Schools | ytforschools | Enabled / Disabled | No | Yes | |