Jump to content

Recommended Posts

Posted

Hey,

 

How do people deal with web filtering in small primaries? Everywhere I go to seems to be completely out of our price range (looking at your Smoothwall :'( ).

 

I'm looking at either a Hyper-V appliance or something we can install on our own hardware.

Posted
Hey,

 

How do people deal with web filtering in small primaries? Everywhere I go to seems to be completely out of our price range (looking at your Smoothwall :'( ).

 

I'm looking at either a Hyper-V appliance or something we can install on our own hardware.

 

What's your budget? What firewall are you currently using? Typical AD environment?

Posted (edited)

Not got a specific price range, but I'm willing to be a little generous with these things. At the moment we have Forefront TMG for staff and Squid/Dansguardian for the kids which upstreams to the TMG box. We've got a typical AD environment (2012R2, 7 and 8 clients) with about 75 devices.

 

TMG is finished as far as Microsoft is concerned, Squid+DG has too much overhead (and seems REALLY slow, but could be poor config) and ideally I'd like to condense the two solutions down to one for both user groups.

 

There just doesn't seem to be anything out there for smaller schools with decent IT provision :(

 

Admittedly our Smoothwall quote is from January 2012, maybe @tom_newton could get in touch for a more up to date one?

Edited by Blue_Cookeh
Posted

In that case, one of the smaller iBoss web filters would only put you back about $1,100 and subscription is based on number of concurrent users, and is very reasonable.

 

iboss Network Security Products

 

They also have the much less expensive iBoss Pro, which has nearly all of the features except for AD integration, although you can create internal users that can be used for authentication and group-based filtering.

 

iboss Pro Series Content Filter - Solution Overview

 

The iBoss is the best web filter out there, bar none. I've had vendors try to sell me their product, then I show them what our iBoss can do and ask if their product is better than that - and they quickly depart. Always.

Posted

If you are feeling brave, you can setup a pfSense environment with Squid3/Dansguardian.

 

You will have to source and setup your own blocklists, whitelists etc. and will take more setting up and management - However, it is a free solution to consider.

Posted
Hey,

 

How do people deal with web filtering in small primaries? Everywhere I go to seems to be completely out of our price range (looking at your Smoothwall :'( ).

 

I'm looking at either a Hyper-V appliance or something we can install on our own hardware.

 

You don't have to have Smoothwall hardware... although I don't know if not taking the hardware will drop it into your price range.

Posted
You don't have to have Smoothwall hardware... although I don't know if not taking the hardware will drop it into your price range.

 

It's the support contract that knocks it out of the park, the hardware cost only seemed to be about 1/10th of the quote.

Posted
Hey,

 

How do people deal with web filtering in small primaries? Everywhere I go to seems to be completely out of our price range (looking at your Smoothwall :'( ).

 

I'm looking at either a Hyper-V appliance or something we can install on our own hardware.

 

Thank you to the couple of posters namely box_l & fairm010 for mentioning Exa and our filtering SurfProtect. SurfProtect is included at no extra charge on our connectivity services, and our support services and updates are included at no extra charge, which as has been pointed out, the on-going support/service contracts can add huge costs to other services. If you are happy with your current provider for connectivity, our filtering is available as standalone, just PM me for the price (so it doesn't look like I am just sales pitching here, more than I already am), or give the team a call for a quote.

Where our filtering service differs from what other providers or grids offer, is that it is entirely our own code. We built it from the first line of code and continue to innovate and update it, at no extra cost or service charge; and we have thousands of schools using it, so if you would like a reference school near to where you are, again just PM me. Enough sales pitching now ;)

  • 3 weeks later...
Posted
We use Barracuda and for one of our sites we use the cloud service as there is no hardware needed. We also looked at sonicwall but we didn't need the firewall capability - happy to pass you the details of our account manager if you want.
Posted
most primary schools seem to use RM Safetynet Plus. It's offsite and looked after by SEGFL etc and is very cheap (something like £100) as all the schools club together.

 

RM Smartcache is relatively cheap but has been out of development for years and will be unsupported as of Sept 2015 iirc.

Posted

I'd recommend censornet. We're rolling it out to various primary schools that have moved away from SWGfL. That's fairly cheap too.

 

Meldrew

Posted
most primary schools seem to use RM Safetynet Plus. It's offsite and looked after by SEGFL etc and is very cheap (something like £100) as all the schools club together.

 

We had it... and I was so glad to escape. It really didn't do the job as far as we were concerned. Too much got through.

Posted

For primaries... Completely open source... Linux box (CentOS or Ubuntu) running squid and DansGuardian and set to download latest filter lists off the internet... I may even run Snort on a couple of boxes.

 

I have a couple of these boxes in primaries... been running strong for 3+ years, nice simple easy web interface to block or unblock anything.

 

One of them still in a Secondary School, Ubuntu server running Squid, DG and Webmin for management. It has 2 network cards one for internet and one for LAN to switch... been running about 3 years with no issues.

Posted
For primaries... Completely open source... Linux box (CentOS or Ubuntu) running squid and DansGuardian and set to download latest filter lists off the internet... .

 

Which lists would they be? I thought they were all closely guarded proprietry things.

Posted
This one:

 

URLBlacklist.com

 

That's *really* interesting. Cheap hardware (eg repurposed smartcache box!) + free sw + $70pa + some setup / admin time for filtering beats £££s for commercial offerings.

 

Does much bad stuff get through that list?

Posted
That's *really* interesting. Cheap hardware (eg repurposed smartcache box!) + free sw + $70pa + some setup / admin time for filtering beats £££s for commercial offerings.

 

Does much bad stuff get through that list?

 

I've never had a problem at all... sometimes it blocks too much but you just add exclusions for domains or whitelists.

 

It blocks 9/10 proxy sites too... logging is quite good. You can customize all the block pages etc to what ever you want too.

Posted
I've never had a problem at all... sometimes it blocks too much but you just add exclusions for domains or whitelists.

 

It blocks 9/10 proxy sites too... logging is quite good. You can customize all the block pages etc to what ever you want too.

 

Couple more q's if I may - do you authenticate against AD and filter accordingly? Also, what do you do about https? Ta.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...