How to Configure the TS Agent in Barracuda SecureEdge

How to Configure the TS Agent in Barracuda SecureEdge

The Barracuda SecureEdge Manager allows administrators to configure the Barracuda Terminal Server Agent (TS Agent), to retrieve user information for users who are logged into a Microsoft Terminal Server. The TS Agent works in a similar way to the Barracuda DC Agent used for Windows domain controllers. It authenticates users by mapping their activity to the corresponding user and group information based on the configured context.

For Barracuda SecureEdge, the TS Agent setting is workspace scoped. The TS Agent maps user logins to IP addresses and can provide user identity information when traffic from a LAN address arrives at a SecureEdge site or private Edge Service. To enable this functionality, you need to install the Barracuda TS Agent on the AD server. All SecureEdge appliances must able to reach and connect to the TS Agent on the AD server and retrieve the User-IP mappings from it. 

Requirements and Limitations

  • For the Barracuda TS Agent to work, you must install TS Agent version 1.2.0 or higher.

  • To enable user- and group-based Web Filter policies, configure the TS Agent and sync your directory from Identity > Settings. You can add user/group context to policies in the SecureEdge Manager via Security > Web Filter > Policies.

Microsoft Active Directory must be reachable over an IP address in the prefixes advertised via BGP or a LAN connected to the same SecureEdge device as the client VM. 

Before You Begin

Before you configure the TS Agent authentication, you must install the Barracuda TS Agent on the Microsoft Active Directory server. For more information, see Barracuda TS Agent for User Authentication. For more information on how to sync your LDAP Active Directory in the Barracuda Cloud Control account, see LDAP Active Directory and Microsoft Entra ID

You need to install the latest version of the TS Agent, and it must be configured to send the username in the User Principal Name (UPN) format.

Configure the TS Agent on the SecureEdge Manager

Configure the TS Agent settings on Barracuda SecureEdge: 

  1. Go to https://se.barracudanetworks.com and log in with your existing Barracuda Cloud Control account.

  2. The chosen Tenant/Workspace is displayed in the top menu bar.

  3. From the drop-down menu, select the workspace you want to configure the TS Agent for your sites or private Edge Services.

  4. Go to Infrastructure > Settings.

  5. Expand the Settings menu on the left and select General.

  6. The General settings window opens.

  7. In the Site Specific TS Agent IP section, specify the following:

    • Global TS Agent IPs – Enter the valid global IP address of the Terminal Server Agent that you have configured and click Add. By default, the TS Agent setting is empty for new workspaces.

      ts-IPs.png



      • To set a specific TS Agent IP address for an individual Site or Private Edge Service (overriding the global value), do the following:

        • Click +.

          • The Add Site or Private Edge Service TS Agent IPs window opens. Specify the values for the following:

            • Site or Private Edge Service – Select the Site or Private Edge Service from the drop-down menu.

            • TS Agent IPs – Enter the valid IP address(es) for the TS Agent and click Ok.

              ts-agentIPs.png
  1. In the SITE OR PRIVATE EDGE SERVICE table, you can see the IP address has been added for your Site or Private Edge Service. You can also edit or remove the TS Agent IP entry for a Site or Private Edge Service entry by clicking the pencil or trash icon, respectively.

    ts-clent.png
  2. Repeat to add more TS Agent IPs for Sites or Private Edge Service.

  3. Click Save.

After the configuration is complete, you can verify that changes to the TS Agent setting in the Audit Log have been made and that notifications have been sent. In the selected workspace, all SecureEdge appliances should receive a TS agent entry with the provided IP.

Note that you can now set multiple IPs for a TS Agent. In addition, this feature allows you to override the IPs for a specific Site or Private Edge Service.

 


We value your feedback.
If you have questions, suggestions, or feedback on our documentation, contact the Campus Product Documentation team.
For general product inquiries or technical support, please contact the global Barracuda Support team.