Jump to content

Recommended Posts

Posted

It's coming up to filter / utm renewal time - currently with Smoothwall.

 

I'm looking at alternatives but they all involve a costly network upgrade as our network is only layer 2 with no core switch. We use VLANS for wifi which are routed (zone bridging) on the smoothwall box for bonjour etc.

 

So which UTM options offer similiar functions to Smoothwall in that respect (and cost) ? Ideally I'd like to upgrade the network but I'm not sure that is feasible at this point - most solutions I've seen are inline between a layer 3 switch and the internet.

 

Or am I just going to have to wait till the network is sorted ?

Posted

Sophos utm is worth a look. We was a smoothwall customer for 3yrs and changed to sophos utm. Sophos utm can do everything smoothwall can do and much more.

Went through a company called pcs-systems.com

Posted
Not sure I have the budget for a layer 3 this year, plus I want to go HP and I'm not sure if they with marry up with our ageing netgears

 

Switches are switches, and communicate via standards - you can mix and match to your heart's content. Sticking with a single manufacturer just makes life easier with admin of them.

 

The HP Comware switches are better value for money; to be honest, if you're not that big you can probably get away with something like an A5120, which is <£1500 for a 48 port. 24 port is half that. Depends on your network, though!

Posted (edited)
I'm looking at alternatives but they all involve a costly network upgrade as our network is only layer 2 with no core switch. We use VLANS for wifi which are routed (zone bridging) on the smoothwall box for bonjour etc.

 

Why do Smoothwall alternatives require a Layer 3 switch? A lot of schools are switching to a routed infrastructure with a core layer 3 switch these days, and there are certainly a few good reasons to do this, but we certainly don't require it.

 

So which UTM options offer similiar functions to Smoothwall in that respect (and cost) ? Ideally I'd like to upgrade the network but I'm not sure that is feasible at this point - most solutions I've seen are inline between a layer 3 switch and the internet.

 

Usually the setup we'd recommend is either:

1. A flat wired network, separate VLANs for wifi (network backbone is made up of layer 2 VLAN-capable switches):

- Put each Wifi network on its own VLAN.

- Put the whole wired network on a single VLAN.

- Connect the filtering server to a VLAN trunk, with an IP address for each VLAN.

- All of the devices on the networks use the filtering server as their default gateway and it routes between the VLANs.

Machines on the wired network can obviously talk to each other since they're on the same VLAN, use the filtering server's firewall to control access between VLANs (e.g. restrict access between the wifi networks and the wired network.

 

Alternatively:

2. A routed wired network, separate VLANs for wifi (layer 3 switch required):

- Put each Wifi network on its own VLAN.

- Split the school into multiple networks, a core layer 3 switch to route between the wired networks.

- Connect the filtering server to a VLAN trunk, with an IP address for each VLAN.

- All of the devices on the wired network use the layer 3 switch as their default gateway.

- All of the devices on the wifi networks use the filtering server as their default gateway.

Machines on the wired network can talk to each other by being routed through the layer 3 switch, use the filtering server's firewall to control access between Wifi and wired.

 

The reason for using a layer 3 switch for option 2 is simply that wired traffic is often high bandwidth and doesn't need much access control, so a fast layer 3 switch is best for this whereas wifi traffic is lower bandwidth and does tend to need better access controls.

 

It sounds like the first option would be best for you, and closely matches what you already do. It certainly doesn't preclude upgrading to a routed network at a later date either.

 

If you do decide to upgrade to a routed infrastructure, we've found that HP switches are by far the best - you can certainly save up-front costs by getting a cheaper brand, but the pain and downtime associated with managing badly behaved switches isn't worth it.

Edited by plexer
sarky comment removed
Posted

@SteveHill, you are correct 1. is what we currently use, as far as I know most filtering solutions don't work with this - smoothwall does.

 

I fancy a change from Smoothwall not just because of the Support issue, but mainly as it just doesn't appear to be serving our current needs very well.

Posted
but mainly as it just doesn't appear to be serving our current needs very well.

@caffrey any chance of elaborating on this? We're considering Smoothwall at the moment over the likes of Sophos for more education-spec filtering performance but interested to hear what's not working so well...

Posted

Been a customer for a while, when it's filtering the domain it's a great product - solid and reliable. The problem lies with our BYOD and mobile devices, layer 7 filtering is an extra module (cost) that when I tested it wasn't very effective, the firewall is just terrible and difficult to do anything with. The reporting system isn't particularly good and has been promised an overhaul for ages. The documentation is poor (even more so on new features) which can lead to usage of a support ticket. The interface isn't structured very well (Counter intuitive - even after all the years I've been using it through many redesigns I still fumble around the menus). Then again I've not really had much chance to use any other products so I've no idea really how they compare but from what I've seen with demo's they are a lot slicker. Smoothwall also doesn't have an accompanying MDM solution either (Two of the other competing products have and are integrated well into their products)

 

Sure I could ask support how to manage our BYOD but again this would cost me a support ticket...

 

Sorry if I'm rambling it's early :)

Posted

Smoothwall has always strived to be a best of breed *content* filter, and I strongly believe that is the case. With the increasing complexity of School networks (not to mention the other sectors that we play in), we have added variants and options to address most customer needs. Where a third party technology is used (NAVL - Layer 7, Vipre - AntiMalware, Mailshell - AntiSpam), then we pass on costs.

 

Support credits – a controversial issue indeed. The initial idea behind support credits was for them to be a benefit to the customer. The idea being that people don't like paying for consultancy/training throughout the life of a contract, and that with Support credits they could be used for non-support related activities. This is often in the form of a health check or help configuring a new feature. For a small number of customers on older support contracts, the number of credits is lower than average – this can be/should have been redressed in account management but I understand there are a few gaps. Call us! We are nice people...

 

Last point - We are a UK based, firewall and filtering vendor. We are a private company and don't rely on third parties for funding or investment. We listen to our main customer base and have a rolling update/feature release cycle. You'll always have the latest version of Smoothwall and we won't have major versions to upgrade to. We're updating the firewall early next year and need people who know what they want to feed into our requirements – please talk to us, tell us your issues.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...