Deploying WAF-as-a-Service Security Module as a Container on Managed Kubernetes Cluster (AKS, EKS, GKE)
The traffic processing engine of WAF-as-a-Service can be deployed as a container on a Kubernetes cluster that is hosted and managed by the customer.
Prerequisites
You must have a WAF-as-a-Service account enabled for custom container deployment. This requires a signed NDA with Barracuda Networks. Contact your Barracuda sales representative for more information on signing an NDA.
You must have a running kubernetes cluster.
You must have permission to create the required resources in your Kubernetes cluster.
Kubernetes command line tool kubectl should be installed on the workstation that is used to manage your AKS cluster.
Allow access to the following domains from the Kubernetes cluster:
Hostname | Port | TCP/UDP | Direction | Purpose |
|---|---|---|---|---|
container-api.waas.barracudanetworks.com | 443 | TCP | Outbound | Update Configuration Settings |
waascontainerprod.blob.core.windows.net | 443 | TCP | Outbound | Storing Troubleshooting information |
wafaas-prod-eh.servicebus.windows.net | 443 | TCP | Outbound | Storing access and firewall logs |
waas-iot-hub-proxy-func-prod.azurewebsites.net | 8883 | AMQP | Inbound/Outbound | Exchange of configuration and other statistics |
Step 1. Create a Container Key
Navigate to https://waas.barracudanetworks.com/ and log in with your Barracuda account credentials.
If you do not already have a Barracuda account, click Free 30-Day Trial to sign up for a trial of WAF-as-a-Service.
On the Barracuda WAF-as-a-Service web interface, click Resources > WAF CONTAINERS > Container Keys.
On the Container Keys page, click New Key.
On the Create new key window:
Key Name - Enter a name for the key.
Select an option to create the key.
If you select I will generate my own key and provide the public portion:
Copy the UNIX command from the window and paste it into your UNIX-like system: ssh-keygen -f barracuda-wafaas-container-key
Copy the contents of the barracuda-wafaas-container-key.pub file and paste them into the Public key box.
Click Create.
If you select I would like WAF-as-a-Service to generate a key for me:
The Barracuda WAF-as-a-Service generates a key for the container.
Click Download and download the key file.
Click Create.
Step 2. Create a Container
On the WAF-as-a-Service web interface, click Resources > WAF Containers > Container Management.
On the Container Management page, click Add Container.
On the Add Container window:
Name - Enter a name for the container.
Encryption Key – Select the key that you created in Step 1. Create a Container Key.
Google reCAPTCHA is available for the applications in your container. An advanced risk analysis engine and adaptive CAPTCHAs are employed to challenge suspicious clients and protect against spam, BOTS and other threats. Clients failing the challenge will not be able to further use your application. To enable this protection you must provide your own reCAPTCHA keys. Refer to the Google documentation for creating reCAPTCHA keys.
If you leave these fields blank, or if reCAPTCHA is enabled, but the connection with Google is lost, WAF-as-a-Service's basic CAPTCHA will still challenge clients marked as suspicious.Click Add.
Step 3. Add an Application
On the WAF-as-a-Service web interface, click Applications.
On the Applications page, click Add Application.
On the Add Application window:
Websites:
Application Name – Enter a name for the application.
Domain Name – Enter the domain name of the application.
Click Continue.
Backend Server reachable from the public network (internet)
Backend Server Protocol - Select the protocol that needs to be used to access the server.
IP Address/Hostname - Verify the IP address/hostname of the backend server.
Port - Verify the port number on which the server is listening to.
Click Test Connection.
If the backend server is reachable, the following message is displayed:
Click Add.
If the backend server is not reachable from the public network, the following message is displayed:
Click Continue anyway and then click Add.
Click Close.
Contact Us
Barracuda Campus
Barracuda Support