Jump to content

Recommended Posts

Posted

Hi,

 

We are currently trying to replace our existing firewall with a nice new shiny Dell SonicWall NSA box at my Upper School. We are struggling to get to grips with the best approach to adopt at the moment. I am wondering if there is anyone who uses a SonicWall and would be willing for us to visit for a chat/look at the setup? We are based in Bedfordshire, but can travel to Bedfordshire/Hertfordshire/Cambridgeshire/Buckinghamshire.

 

Many thanks,

 

Ash.

Posted
We use a cluster of NSA 5600s. I'm honestly not sure I can recommend the sonicwall solution at the moment, due to what appears to be a massive flaw in how it handles authentication of users to the box, which is (arguably) required in order to monitor connections for safeguarding, and also for filtering different groups of users.
  • Thanks 1
Posted

@Roberto - Can you enlighten on that some more? We are talking to Dell at the moment and they have told us that their AD integration is based on agents running on workstations around the campus in each vlan that handle the authentication requests - I am not trying to prejudge, but it seems an unusual way of doing things. Is this what you are referring to and if so - what is the real life experience of using it?

Cheers

Wally

Posted

What size school do you have it needs clustered 5600s?

Sonicwall Agents are used on servers to run LDAP queries against DCs and use WMI to extract users and groups from windows devices.

You import AD groups and assign groups to Filters.

 

It can be quite effective but is only as good as your AD skills

 

Truth is the Sonicwalls are extremely good firewalls but school content filtering solutions they are not.

 

If you need more granular control on your web filtering using windows groups then your better of looking at alternative methods.

Posted

Truth is the Sonicwalls are extremely good firewalls but school content filtering solutions they are not.

 

If you need more granular control on your web filtering using windows groups then your better of looking at alternative methods.

 

Had awful difficulty with our SonicWall and filtering at last place, gave up in the end and went for a separate solution. I have used Bloxx and Sophos which both seem do a very good job but there are probably other alternatives.

 

The one thing that also put me off with SonicWall was the need for Agents on Servers both are not needed in Sophos, Bloxx or other solutions.

Posted

Will hopefully do a POC with Sonicwall in a few weeks to test their authentication model. One of the things they did mention that was different was how they handled users multiple AD groups. Our current Bluecoat proxy works on standard firewall top down first match scenarios. Eg a student in two groups - All Students and All Sixth Form Students - if we put the rule for all Sixth Form Students - allow Facebook - higher in the list than the All Students block Facebook - then Sixth form kids will be allowed Facebook. Sonicwall guys said this was not how they worked and that groups had no priority - only individual users in a policy override group membership. So to allow sixth formers to access facebook we would have to list them individually in the allow rule rather than by group. Would be interested if anyone can confirm this or otherwise?

 

As an aside...We had Sophos in and were quite impressed until they cautioned us of scenarios with shared computer access...eg libraries - in that their AD authentication model was to cache the credentials of the user against the IP for 15 minutes in their tables.

When pushed on this they admitted that this would mean when one student logged off and the next logged on - the database and reports would show the previous students ID. Pushed further it was not just reporting but actual access rights...so that if a teacher logged off and then a student logged on - they would get the teachers access. Obviously in a work environment with 1 to 1 computer access this probably not an issue...but for us it was an instant deal breaker.

So at present we are "talking" to Sonicwall / iBoss / Websense.

 

 

Cheers

Wally

Posted
@Roberto - Can you enlighten on that some more? We are talking to Dell at the moment and they have told us that their AD integration is based on agents running on workstations around the campus in each vlan that handle the authentication requests - I am not trying to prejudge, but it seems an unusual way of doing things. Is this what you are referring to and if so - what is the real life experience of using it?

Cheers

Wally

 

Whoever told you that? They're either flat-out wrong or talking about an option that was not offered to us, doesn't appear to be mentioned in the documentation, and isn't available on my.sonicwall.com.

 

Sonicwall Auth works by talking to authentication servers, either/and LDAP or RADIUS. If you use LDAP then you need to install agents on the servers you are using.

 

The issues we have appear to be a specific bug with the implementation of authentication requests when using LDAPS on our current combination of firewall and firmware version. We've been talking to their top-level support people, the ones who have access to the developers, and we're currently trialling a fix but it has taken several months to get to this point, which is why I have pause in recommending this as a solution to education right now (To be fair, I still consider it to be overall a pretty good solution and I'd have no issues suggesting it for a business whose requirements placed less of a strain on this part of their system).

 

What size school do you have it needs clustered 5600s?

 

We're a college, not a school. We've trialled some of the other solutions mentioned in this thread in the past, but our traffic throughput and filtering needs tended to leave even their higher capacity systems crying to themselves in a darkened corner of the server room. The Sonicwalls keep up with our traffic throughput very well and have considerable headroom for growth... though you'd damn well hope so with clustered 5600s right?

 

Having said that, I agree with your comments about the filtering not being ideal, I'd prefer to use the sonicwalls alongside something like websense for filtering, but budgets must and all that.

  • Thanks 1
Posted

Hi all,

 

Thank you for your replies. We have had a PM inviting us to have a look at their SonicWall solution, but your replies are not looking too promising for our SW :( . Having said that, we've looked at demos of Smoothwall and the interface and options seems to be very similar. We are using our SW very successfully for SSLVPN on Staff laptops, so just need to get the rest sorted filtering/fw rules etc. We have installed the authentication client on two of our DC's for LDAP, and also have the option of using our RADIUS server too. Group settings for content filtering does seem to be a bit of a pain to set up!

Any other thoughts/suggestions still welcome here!!! We don't really want to have to ditch it and get another solution.

 

Ash.

Posted
We currently have a SonicWall at two schools - both work well (somewhat) but the issue we face relates to HTTPS traffic, particularly YouTube and Google (although we have currently solves the Google issue at a DNS level - without the SonicWall). This is also the case when using DPI-SSL, have you found a work around for this issue?
Posted

Depending on the auth methods you choose, I have seen a number of the types off issue reported here - agents on ADs are particularly unreliable.

For transparent proxying there's often a "timeout" issue with in-line authentication as someone mentioned with sophos. For such non-domain devices I would recommend 802.1x and integration with your wireless controller it is extremely accurate and reliable. For domain machines, something like a kerberized proxy logon is most reliable and effective in my experience.

  • 2 weeks later...
Posted (edited)

We've currently got a NSA 3600 running on our own leased line (100 down/up) - got the DPI-SSL configs etc perfect as been in for 18 months now.

 

The issue is DPI-SSL (https inspection) only utilises CPU core 1 (the control plane) and so gets hammered; EDIT: Also only supports inspecting 250 SSL connections and we currently quadrupedal that in pupils alone.

 

cpu1.jpg

 

Authentication is working fine with the SSO agent on 3 domain controllers - unknown users are challenged with a login prompt.

 

The major flaw with SonicWALL (other than DPI-SSL that will be multi-core in the current months) is the Content Filter lists. We've had a number of dodgy sites (too many) through and the AppControl does not detect proxies like Glype even though they are listed.

 

We've had a SmoothWall on trial and it did OK but it's not perfect and not user friendly at all in terms of administration. There is also a small but noticeable delay on internet access that was never there with the SonicWALL.

 

Got a iBoss coming in for trial so the search continues!!

Edited by DSP
  • Thanks 1
  • 3 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...