Skip to content
Notifications
Clear all

Anyone using Barracuda CloudGen with multi-cloud (AWS + GCP)?

1 Posts
1 Users
0 Reactions
0 Views
(@annam)
Estimable Member
Joined: 1 week ago
Posts: 71
Topic starter   [#17100]

I've been evaluating Barracuda CloudGen Firewall for a multi-cloud network security architecture spanning AWS and Google Cloud Platform. Our organization is in the later stages of a phased migration, where some legacy applications remain in AWS us-east-1 while new analytics workloads are being deployed in GCP's europe-west1 region. The primary goal is to establish a secure, unified network layer with consistent policy enforcement and centralized logging across both providers.

From my analysis, I've identified several key considerations and potential pitfalls specific to a multi-cloud deployment:

**Deployment Architecture & Connectivity:**
* The necessity of deploying at least two CloudGen Virtual Appliances (one per cloud provider) and establishing a mesh VPN between them via the CloudGen Firewall Control Center. This introduces latency for east-west traffic between clouds, which must be factored into application design.
* The complexity of managing routing tables in both AWS Route Tables and GCP VPC Networks to ensure traffic is correctly directed through the respective CloudGen instances. Asymmetric routing is a significant risk here.
* The choice between using the cloud providers' native VPN or Peering services versus relying solely on Barracuda's IPsec tunnels for the backbone. Native peering (AWS Direct Connect/GCP Cloud Interconnect) may offer better performance but adds cost and management overhead.

**Policy Management & Operational Challenges:**
* While the Control Center provides a single pane of glass, policy application must carefully account for differing cloud provider security group constructs and network ACL behaviors underneath the virtual firewall layer.
* Log aggregation becomes more complex. Ensuring VPC Flow Logs (AWS) and Firewall Rules Logging (GCP) are correlated with the CloudGen-specific event logs requires a dedicated SIEM integration plan.
* Cost forecasting is non-trivial. Beyond the licensing model, one must model data transfer costs for traffic inspection between availability zones and regions within a cloud, and more critically, the substantial egress costs for traffic flowing from one cloud provider to the other via the firewall mesh.

My specific questions for the community are:
1. Have you implemented a multi-cloud transit VPC/VPC architecture using CloudGen, and if so, what were the lessons learned regarding the initial setup and ongoing routing management?
2. How do you handle high availability and failover scenarios? Does a failure in the AWS-side appliance impact GCP-bound traffic, or is failover isolated per cloud?
3. Are you using any automation tools (Terraform, Ansible) to manage the configuration of multiple CloudGen instances in a synchronized way, or is the Control Center sufficient for day-to-day policy pushes?
4. Has anyone performed a quantitative analysis on the latency and cost impact of routing all inter-cloud traffic through the firewall mesh versus using a cloud-native interconnects for the data plane with firewall inspection in each cloud?

I am particularly interested in any migration playbooks or risk assessments you may have developed for this scenario. The documentation is comprehensive for single-cloud deployments but becomes notably sparse when discussing heterogeneous cloud environments.

—Anna


Migrate slow, validate fast.


   
Quote