Jump to content

Recommended Posts

Posted

The complexity, better than most but still not simple. Considering the amount of control you have these things can only get so simple.

 

It made sense to me at least.

 

Yes I know the layer 7 stuff is coming soon as well as the improved reporting, hence the close tie at the moment.

Posted
The complexity, better than most but still not simple. Considering the amount of control you have these things can only get so simple.

 

I've obviously not used one myself but a local school told me they hated the firewall because it was so complicated to get the simplest of setups working, which sounds contradictory to everything on these boards says...I'm starting to wonder if they just didn't know what they were doing....lol

Posted
Another major concern / requirement for me she ability to control bandwidth to websites and applications for certain groups and ip ranges. This is one of the areas that SonicWall out performed smoothwall.

 

We are also replacing our dated QoS module this year and will also offer bandwidth by category and group, and hopefully by application.

Posted
I suggest using a Juniper SSG 350M appliance for firewall, anti-virus, anti-spam and base web filtering (you can probably get this at no extra cost if you choose your ISP carefully as we did), TMG for back to back FW/DMZ and then a software only version of Smoothwall (no firewall) for the main on-site filtering. This way you have a fail safe on web filtering and firewall all at minimal cost.
Posted

@Marshall_IT , Lightspeed doesn't have to use a client. We generally don't install it.

 

It quite happily integrates with AD and open directory out of the box straight away.

 

Dave

 

 

 

Just an update after various visits, Web demos and research.

 

All thoughts are my personal opinions and are subjective to my needs.

 

I have had a good look at the following devices:

 

Smoothwall

SonicWall

Watchguard

Lightspeed

Fortigate

Bloxx

 

I have narrowed it down to either SonicWall or Smoothwall a these seem to offer the most complete devices.

 

The Bloxx offering, while good seemed to lack something of maybe just concentrate too much on anonymous proxies. (maybe that was just the sales guys).

 

Watchguard, while offering most of what I was looking for, misses out on some key things like YouTube controls. Also the policy creation tool, while a good idea was a little clunky and the ui overall I seemed a little dated.

 

Fortigate was very similar to Watchguard in respect of features and ui. But seemed a little less powerful.

 

Lightspeed I didn't like the idea of a client install.

 

So, on to Smoothwall and SonicWall...

 

One has a better filter, the other has a better firewall.

Both say they are improving the areas the are behind in.

 

Smoothwall have said we should see an update to their reporting and Firewall sections in the next few months.

SonicWall said they are looking closely at improving the more school centric bits that were missing from their filtering.

 

Although SonicWall are used, so I'm told, extensively throughout education in the UK, this seems to be more colleges and universities. These institutions have very different requirements when it comes to filtering.

 

There is one last factor in my situation, which could be a game changer in the case of which I choose. That I might be supporting a number of primaries with their line and filtering.

 

If their connection is routed through our high school, we'd only need one UTM, if they connect directly to the Internet but we created branch VPNs, they would need smaller boxes which I could manage remotely.

 

More to come I think.

Posted (edited)

Watchguard, while offering most of what I was looking for, misses out on some key things like YouTube controls. Also the policy creation tool, while a good idea was a little clunky and the ui overall I seemed a little dated.

 

Fortigate was very similar to Watchguard in respect of features and ui. But seemed a little less powerful.

 

 

I have smoothwall and lightspeed to demo at the moment, but need to do more with bandwidth QoS. I am now about to demo Watchguard and Fortigate to see if they are a better fit. I am really struggling to find something that will make the most of our limited bandwidth and filter ok. Do either watchguard or Fortigate allow bandwith limitations by group? I want to slow youtube down for students and leave it at normal speed for teachers.

 

Can I ask what youtube controls the watchguard misses out on? Budgetwise I don't think I can get a new firewall and web filter on different devices, so looks like I will have to compromise on either bandwidth control or the filtering. Tough decisions to be made.

Edited by boombah
Posted
I have smoothwall and lightspeed to demo at the moment, but need to do more with bandwidth QoS. I am now about to demo Watchguard and Fortigate to see if they are a better fit. I am really struggling to find something that will make the most of our limited bandwidth and filter ok. Do either watchguard or Fortigate allow bandwith limitations by group? I want to slow youtube down for students and leave it at normal speed for teachers.

 

Can I ask what youtube controls the watchguard misses out on? Budgetwise I don't think I can get a new firewall and web filter on different devices, so looks like I will have to compromise on either bandwidth control or the filtering. Tough decisions to be made.

 

If you got Lightspeed you'd need a firewall anyway so your firewall could do your bandwidth management.

 

We've been trialling / purchased a sonicwall box which is good for this :)

Posted

We have 2x Smoothwall UTM-1000 appliances. 1 as main firewall / filter the other as a child node handling the databases (but can be reconfigured if there is ever a hard/software issue with the other one).

Also have BYOD / Ruckus being handled by it (via VLANs).

 

LEA had Bloxx, but i have heard they are now also moving over to Smoothwall too!

Posted
have you looked at Palo Alto,Network Security we are using this at our boarding school and must say that we have used Sonicwall, Websence and smoothwall in the past, but this device out performs them all. Especially with application management. Allow the application regardless of the web site=perfect. We have only a small list of blocked web sites on the device.
Posted
have you looked at Palo Alto,Network Security we are using this at our boarding school and must say that we have used Sonicwall, Websence and smoothwall in the past, but this device out performs them all. Especially with application management. Allow the application regardless of the web site=perfect. We have only a small list of blocked web sites on the device.

 

A few people on the forums have mentioned Palo Alto and said how good they are but then said the price is extremely high. Never seen it myself so can't comment other than that :)

Posted
we are also looking into setting up our own filtering system and leaving the local LEA. As you are from Leeds it would appear we are in the same boat. Looking at smoothwall too and I have heard good things but it's always good to give others an opportunity to show us their products. Just got to get these things in place as soon as possible so we can at least get to grips with it.
Posted
Those of you in Leeds (and indeed further afield), you're always welcome to pop in and see us - we're on Gelderd Rd, just opposite the mercedes/smart garage before you hit the ringroad. Drop in for a coffee and biscuit any time, we'd be happy to chat filtering :)
Posted
pfSense for both firewalling and filtering, you can even run it virtual so that means it's free!

 

Free as in kittens ... nice to have when given to a loving and caring home, but still needs feeding, taking to the vets, time spent playing with them, etc ...

 

*NOTHING* is free!

Posted

I would be content with a free solution if it was a secondary system, or if I were a lot more proficient at security.

The companies that make these products have a lot more staff working on them than I could dedicate to it.

 

Invest in what is important, and what is more important than security?

Posted
pfSense for both firewalling and filtering, you can even run it virtual so that means it's free!

 

We are running PFSense. It was initially put in when our firewall died. We put it on an old machine to get things back up and running. That was weeks ago. I have been trying to get quotes for Fortinet, Sonicwall, Watchguard and Palo Alto in that time, I still don't have a single quote yet. Guess living in Thailand, it comes with the territory. I still think I need something at layer 7 to sort our bandwidth issues out, but PFSense has been very very good and hasn't missed a beat.

 

As for the filtering, I have used it in the past, but as mentioned, it took a fair bit of work and it wasn't that great. I have ordered a lightspeed appliance to cover that, so we will see how that goes.

Posted

Another Leeds school here moving away from the LEA. We are currently looking at Smoothwall and Fortinet options, in fact my colleague is out looking at a Smoothwall setup right now. I'd be intrigues to know how easy it is to configure and how straight-forward it would be to setup transparent proxy for BYOD?

 

We are also looking at switching to Office 365 for email features (because the A2 plan is free :)) so it's going to be a big summer for us! New ISP, new firewall, new filtering, new email etc. ARRRGGGHHH!!!

Posted

Ive just moved from websense to smoothwall, took me a while to get going but getting there with it, ive had to change my thinking about blocking and allowing sites but i must admit, its a better solution than websense (@john).

 

Ive done a guide on here under BYOD Ruckus and smoothwall on how to get the BYOD working (well ive documented my setup) which may help some people http://www.edugeek.net/forums/how-do-you-do/109684-byod-smoothwall-ruckus.html

  • Thanks 2
Posted
Another Leeds school here moving away from the LEA. We are currently looking at Smoothwall and Fortinet options, in fact my colleague is out looking at a Smoothwall setup right now. I'd be intrigues to know how easy it is to configure and how straight-forward it would be to setup transparent proxy for BYOD?

 

We are also looking at switching to Office 365 for email features (because the A2 plan is free :)) so it's going to be a big summer for us! New ISP, new firewall, new filtering, new email etc. ARRRGGGHHH!!!

 

Fortinet & Lightspeed are brilliant bits of kit.

 

 

FYI we are going to be holding a seminar at Weetwood Hall in Leeds on Wednesday 27th March from 11am.

 

We'll be show casing our Fortinet security, Lightspeed fitlering / MDM and also going over different WAN network designs. I'll put up an official post on this later. Lunch will be provided and we'd love to see as many techie people there as possible :)

 

Both Fortinet & Lightspeed will be sending people to demonstrate the products and it will be an extremely technical session :)

 

If any of you want to come do let me know!

 

Thanks

 

Dave

  • Thanks 1
Posted
As i've said I think previously on this thread, 2 weeks and we get a Lightspeed / SonicWall combination installed. See how we go with it, hopefully should be good :)
  • 1 month later...
Posted
We switched from SmoothWall to a Fortinet 100D with Talk-Straight - What a mistake to make - nothingg but trouble for 7 months now and still no sign of improvements. The support is nothing short of shocking, no systems properly in place to support that massive amount of new customers and quite frankly we feel ripped off. No SLA's in place to speak of and if they are they keep very quiet about it using words like "shortly". We will be looking to return to SmoothWall asap.
  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...