Jump to content

Recommended Posts

Posted

Hi All

 

So, we are only looking at the moment and instead of contacting companies so they can say what we need - I'm asking here.

 

What does Internet Filtering/Firewall cost other Secondary Schools with the below - I will include as much as possible depending if it's cost per device/user:

 

We have around 1500 Students

200 Staff

 

600 Windows PCs/Servers/Laptops

 

We allow BYOD so this covers-

500 Students with an actual device to use provided by the School

Allow Mobile phones and other years to use their own devices, potentially another 500 devices at least.

 

What we are after is an estimated price for Web Filtering which of course allows us to block/allow groups, catergories and sign on option for NON Domain devices. Currently we have LIGHTSPEED provided by our LEA.

 

As for Firewall, this is actually one of few things I've little to no experience with - again all managed by the LEA.

 

Would we need our own box to setup, install and to maintain or would this be provided by a company that can do our Internet Filtering or another company as a annual service? - I'm open to suggestions.

 

Just wondering what other Schools our size do, rough costs mainly to see if it could save us money looking else where.

 

thank you

Posted

What are you not happy with about your current setup?

 

Lightspeed seem pretty good...

 

I had a Palo Alto 3000 series at my last place I was happy with - it's not a cheap option, but we were nearly 3000 users and a gig connection, so we needed more oomph than most. For that we had a device, support and updates and it was about 5k for the first year and then 1500 a year for the last 4 because by then we had paid off the equipment.

 

Rather than getting 2 devices I would strongly suggest looking into single device soultions like the Palo or a Sophos UTM.

Posted

We seem to have a similar staff/pc/byod setup as you. We have always had our own box for our firewall though.

We are moving away from Smoothwall (before that we were using TMG and when I started we were using RM as a filter and ISA as a firewall.

 

The best UTM I have found was probably the Sophos one although the barracuda one had a lot going for it (if you liked isa/tmg then the firewall part seems a total copy of that)- it's a bit more complicated to use than the Sophos and you seem like you'd want a more gradual welcoming into running your own edge security.

 

We thought the iBoss filter (definitely arrange a trial) was so good though we've spent the last 2 months trying to find a firewall to pair with it. Transparent inline filtering with a program that gets installed on the DCs to pick up users for filtering when they authenticate using radius. You can get some very good pricing for those - I really can't overstate how much I like their filter.

We've currently got a fortigate on trial although without its analyser partner I'm not sure I'd want it. I like the analyser much more than the firewall.

I've got an Allied Telesys firewall lined up for a trial over Christmas as well which is looking promising.

The palos I dream of one day having but my manager thinks the 3000 series is too expensive.

Watchguard as a UTM seemed ideal on paper but I was told they were too expensive to even bother organising a web meeting on so I have no hands on with those.

I didn't like Sonicwall as a UTM.

 

I like to have my things onsite and managed by myself (our head also prefers than we control as much as we can ourselves)

Firewall maintenance is fairly low impact - how often does one really need to publish a service/website or alter the allowed port list for a new piece of software and it's rarely, if ever, so urgent it can't be done out of hours.

Filter maintenance can be a couple of things a day but once it's set up if you need to spend more than 40 minutes a week on it you probably want to rethink how you are doing it.

It's difficult to get excited about firewalls (even for me)

 

I did see a demo on what seemed quite a reasonable web based filter called iSheriff but presumably you'd still need a firewall onsite. That was dismissed by us as our manager is fed up with pac files and proxy settings.

Posted

@mthomas08 we have a virtualised Fortigate UTM / Firewall with Lightspeed filtering as standard. No capex costs just ongoing which at RRP is £3,900pa with unlimited user licences on a 100Mbit line.

 

That includes all UTM renewals, support contracts, management AND you get a resilient pair rather than a single box. If you bought all the kit together and then paid for all the licences you'd have to spend about £15k up front about £8kpa just for licences, support and UTM renewals.

 

Lightpseed is an awesome education specific filter. Fortinet provide the fastest UTM / firewalls in the world. It's a great combo. I hear IBoss is also good as is Smoothwall but we stuck with Fortigate / Ligthspeed combo for some very good reasons.

 

Thanks

 

Dave

Posted
Fortigate 200D would handle that a breeze. You would be looking around £5000/£6000 for that UTM, and then around £1800 a year for the filtering updates and support. I would not give up my Fortigate for anything. FortiGuard.com | Home is their threat centre which is worth a look. You can see all the standard category filters you can choose too.
Posted

Rather than getting 2 devices I would strongly suggest looking into single device soultions like the Palo or a Sophos UTM.

 

Any particular reason you say that?

 

I've always found most solutions have a good or great filter, and a poor firewall. Or a good or great firewall, but a poor filter. Seems very rare to find one company doing both jobs well in my - very limited - experience. (Though i haven't seen the sophos device, certainly from what i've heard palo alto is among the best firewalls out there, but i've not heard stellar things about their filtering capabilities?)

Posted

We have 200 staff, 1200 students, 1100 pc's 50 BYOD devices, We're in the process of moving to Censornet and it cost us around £6300 pounds including mail filtering this was for 1 year just to trial. Web filter is based on concurrent connections and we went for 700.

 

Web filtering is local VM (installed from ISO) and allows blocking, whitelisting sites etc. As for the mail, mx records are pointed to cloud service which filters the mail then forwards to local exchange server.

 

Again there is a URL to visit to edit email rules and you get end user notifications of emails blocked which can be released etc....

Posted
Any particular reason you say that?

 

I've always found most solutions have a good or great filter, and a poor firewall. Or a good or great firewall, but a poor filter. Seems very rare to find one company doing both jobs well in my - very limited - experience. (Though i haven't seen the sophos device, certainly from what i've heard palo alto is among the best firewalls out there, but i've not heard stellar things about their filtering capabilities?)

 

PfSense does both - exceptionally well.

Posted

My two pence, I'll stick with SmoothWall whilst the product still maintains good updates, and a forward looking development plan. I've looked at the others and then don't offer me as much flexibility, however I do run a separate firewall and use the SmoothWall for filtering/BYOD/RADIUS/SSL inspection, with AD and location based authentication.

 

We have quite a few VLAN's and being able to configure different methods of authentication on different ports/lans is key, I'm not sure if all the others platforms will allow this type of config simply.

 

I think when looking at changing solutions you need to look at where you are going as well as support your current infrastructure.

Then seeing if the product meets your needs, so if your looking at google apps etc look at a platform that will support it, I suppose we all have our differing tastes as each one has it's positives and negatives

Posted (edited)

I really ought to become a Sophos salesperson...

 

Loving our Sophos UTM here. Very competitive on pricing. Does everything in one box. Top notch support.

 

Just not keen on the way their new XG firewall is going, but I believe they're slowly fixing that one :o

 

You can download the Home version which will run everything as if it were licensed to play with, just limited to 50 IPs. You can run it on Sophos hardware, your own server, or within a VM.

Edited by Blue_Cookeh
Posted
Filtering £280 per year for 1000 users, put on top of a 330 meg BT fiber line for £1800 per year, using pfsense for firewall. Job done. Better than the £15000 cost per year for SWGFL for a 35 meg line.
Posted

We were looking at this some time ago.

 

But recently our county signed deal with Smoothwall. As we get internet through LEA they provide firewalls as well, but we will be configuring smoothwall as both filtering and FW. At the moment we have quite basic FW from Juniper, but it doesn't do much.

When we were looking at filtering we had 2 similar quotes after some negotiations. Both Lightspeed and Smoothwall came around £9k for 3 year deal, smoothwall includes firewall. We have around 1200 pupils and 200 staff. 100MB connection.

For me biggest worry is future renewal, both will try to hook you on but 3 years later when deals expires I'm not sure if they will want to give nice discounts, like they do for new customers.

Posted
If I remember correctly the Juniper Firewalls dont run JunOS... I think its ScreenOS or something... Junos is far far better, but typically is only used in their Routing and Switching platforms.

 

ScreenOS is used in the NetScreen platform and the SRX's use JunOS, bar the Netscreens I boxed up here and sent back to ATOS (who Love them so hope they are patching like crazy) I've not seen NetScreens in the wild for years as most folks seemed to use the JunOS based kit so suspect yes its not good but actually risk to schools probably low as most probably used an SRX not a NetScreen

Posted
i am looking into new firewalls and web filtering systems at the moment. One thing I will say is, stay away from smoothwall. They have introduced this credit system and if you run out, they will not support you unless you pay. A lot of NM talking about this atm.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...