Tall_Paul Posted February 10, 2014 Posted February 10, 2014 Hi all I'd be grateful to see what others think of this: We currently use TMG and Websense and have done for years. The clients that connect out through this are W7-based devices connected to my network and authenticated by AD. What we are increasingly finding is devices like IPads, Surface RTs, etc don't work very well behind an authenticated proxy so we've been looking at getting another device to sit alongside the TMG box. Also, our ISP is SWGFL. This has lead to a meeting I've just had with my principal where has questioned the need for the firewall and web filtering and asked why we cannot just ditch both and rely on the SWGFL filtering service and firewall (as a way of saving money). I know we originally set up Websense as there were (many years ago) problems with the SWGFL service. We originally set up a firewall to 'protect' us from other schools who use SWGFL and share our IP range assigned through them. Now I can see the benefit of getting shot of Websense, but getting rid of our firewall makes me feel very uneasy (even though it would make my life much easier in relation to unauthenticated proxy). So, I'm just seeing what my fellow Edugeekers who have a set up similar to the above do (and would you argue for keeping the firewall or not?) Thanks all Paul
Michael Posted February 10, 2014 Posted February 10, 2014 Are you sure SWGFL don't separate schools using VLANs? It'd be very surprised if they didn't, as it could mean viruses/malware (in a worse case scenario) hopping from one network to the next. So long as there's a firewall in place somewhere then you should be OK, but it is nice to be able to manage your own firewall.
MicrodigitUK Posted February 10, 2014 Posted February 10, 2014 We are on the SWGfL and have Smoothwall on top of that. Smoothwall WITH 802.1X authentication works perfectly and transparently for BYOD. Then traditional NTLM and Kerberos can be done on the Smoothwall for the traditional networked PC's and Apple Macs. SWGfL do have a transparent proxy but you will loose the per user audit trail, as SWGfL don't log per user. 1
Tall_Paul Posted February 10, 2014 Author Posted February 10, 2014 I think my principal's idea is to get rid of everything and just rely on SWGFL. I'm not sure why we were set up this way originally (old NM long gone with zero documentation) but I suspect (and hope) SWGFL's offerings have improved since then. I don't know about SWGFL VLANs either. If they are set up then it would allay my fears a bit and I think my principal would be happy with losing per-user logging due to the large monetary saving.
Boredguy Posted February 10, 2014 Posted February 10, 2014 Our SWGfL connection used to allow access to other schools IP ranges (made supporting our local primary very handy) but disappeared about 3 years go. We are purely using the upstream Safetynet for our filtering provision with the transparent option enabled as we also have Impero to log the website access on the workstations. At present only our staff BYoD devices have the transparent proxy as their primary connection type as we still force all other connections via the normal SWGfL proxy address. Must admit I fail to see how sending traffic via normal or transparent proxy will stop SWGfL from generating logs for users since it will still have IP address assigned regardless... then again from feedback from another site they have never managed to get any log files from SWGfL to resolve an issue.
Oaktech Posted February 10, 2014 Posted February 10, 2014 I'd be terrified of using just SWGFL, having now been independent of them for 6 months. The SWGFL filtering is, at best, not logical, and the firewall admin is slow and patchy. We've previously had to wait for six weeks to have a bi-di port opened, and then they got it wrong the first 2 times they tried.
Boredguy Posted February 10, 2014 Posted February 10, 2014 Firewall modifications have always been reasonable quick when you consider it's RMI doing some of the modifications, although I did have a few backwards and forwards attempts when getting IMAP opened up purely for the Microsoft Datacentres last summer but that only took a week in total. Their filtering solution might not be the most advanced out there, but it does what it claims to do. No web filtering solution is every 100% perfect, but it just depends on how much you want to invest in it.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now