Jump to content

Which webfilter/firewall would you choose?  

50 members have voted

  1. 1. Which webfilter/firewall would you choose?



Recommended Posts

Posted

Hi all,

 

I'm currently a Bloxx customer and for obvious reasons looking for an alternative (and soon).

 

I've had web demos of a number of products but would like to get peoples opinions on what you use now, what you have used in the past and what would you would buy if you had to renew right now.

 

I use Bloxx for NTLM authenticated web filtering on the domain and transparent filtering on various BYOD networks plus I use the firewall features.

 

So far I've looked at:

 

Lightspeed (which currently does not have firewall features until May at the earliest)

Smoothwall (which I currently have an evaluation unit for)

Fortinet (web demo scheduled for next week)

iBoss (the interface for which I wasn't very keen on)

Barracuda (which supplies separate firewall and filtering appliances so is the most expensive yet possibly the most flexible)

 

I'd really appreciate peoples thoughts and opinions as I an not sure which direction to head in!

 

Thank you!!

Posted (edited)

Personally not a fan of UTM.

 

web traffic filtering and firewall security are two entities i like to keep separate. You'll often find one company does one aspect great, and the other aspect pretty poorly, so in many situations you're compromising on one to benefit the other. My philosophy on it is to have the best of both worlds.

 

Smoothwall is a brilliant filter, but i wouldn't recommend it as a firewall, and i'd say the complete opposite for the fortinet. No experience of iboss or barracude, but another one to add to your list would be Sophos.

 

Of course, i've not used/seen every product, so there may be one that does both great, but if there was I'm sure it'd be more popular. For example there's a reason Smoothwall is such a popular filter, and you hear about it and it's well known because of that fact.

 

EDIT:

Just to add: doing the same thing at the moment myself. I've opted for a Smoothwall for my filtering after previously being somewhat disappointed with lightspeed, very very happy with it. Still considering firewalls though, so will keep an eye on opinions in this thread :) would love a palo alto but probably a fair way out of my price range.

Edited by mrbios
Posted

Everyone is raving on about Sophos, personally I'm not impressed but I think its because our box was so low spec.

 

Personally firewall and filter should be kept separate I think but that's just my view on things.

 

Watchguard kit is reliable, I've used hundreds of the things but when we looked at the UTM side of it back 5 or so years ago it wasn't at a level to provide good filtering, the basics were ok but anything else it didn't stand out at me. Smoothwall seems to be the best I've seen but a nice price tag I believe.

 

Have you had a look at pfsense and use Dansguardian which is part of it, the likes of Smoothwall use the same if I am not mistaken.

Posted
Everyone is raving on about Sophos, personally I'm not impressed but I think its because our box was so low spec.

What model did/do you have?

Posted

I'm running Sophos UTM on an Intel NUC i3, VM image 8gb ram and two cores allocated.

 

It's been brilliant at home, but we also use smoothwall at work, another great product for 1000+ users.

Posted

I would say Smoothwall especially with their new updates which are coming in Framlingham regarding the PREVENT stuff.

 

As a Smoothwall user, im not sure where i would be without it.

Posted
I'd go for a SonicWALL personally, it can pretty much do everything from Layer 3 routing to Deep Packet Inspection. Line Bonding and fail-over, LDAP Authentication so you can filter per-user. It's like LightSpeed Rocket, Smoothwall and UTM rolled into one in my books... I might be biased slightly because they look nice and Dell. :p
Posted
I'd go for a SonicWALL personally, it can pretty much do everything from Layer 3 routing to Deep Packet Inspection. Line Bonding and fail-over, LDAP Authentication so you can filter per-user. It's like LightSpeed Rocket, Smoothwall and UTM rolled into one in my books... I might be biased slightly because they look nice and Dell. :p

 

Pretty sure smoothwall can do all that and coming in the next update is google cloud user integration, and I dare say office365/azure user integration in the near future.

Posted

Have recently put in a couple of PaloAlto's where I curently work ( 2 site college ) and I wouldn't say the filtering was as good as the Sophos. We did have Sophos doing web filtering (which was quite good IMO) and Cisco ASA for firewall.

 

Setup and managed a SonicWall at my last place which didn't seem too bad apart from the filtering side.

Posted

As a UTM and NGFW the Fortinet kicks ass on all of those listed.

 

In an education environment though Smoothwall and Lightspeed are much easier to use with regards to content filtering. It's why we use Fortinet as the firewall and Lightspeed as the filter as together we believe it's the best solution on the market.

 

Dave

Posted

Thank you everyone for your input on this, it's much appreciated. There's certainly a lot to think about. I'm surprised there hasn't been any mention of Barracuda as I thought they might have been a strong contender. And Sophos was not on my list of contenders originally!

 

Are there any other Bloxx users here that have already moved away to a different solution? If so, what did you go for?

 

Also, for those of you that use Smoothwall, do you use it as a captive portal for BYOD traffic? I currently have a Ruckus wireless system that I was going to use as a captive portal, however, the Ruckus system (at least the system I have on the software version I have) is not able to push iOS devices from one SSID to another so as far as creating a provisioning/on-boarding portal goes, this failed miserably. I'm not sure if this is a Ruckus failing or a general iOS failing? I instead have separate BYOD networks that users connect to themselves, they then authenticate via RADIUS/NPS using their AD credentials... The Bloxx then filters based on policies assigned to the different subnets these wireless networks are on. I then have applications running on my DHCP and NPS servers to match MAC/IP addresses to NPS/AD credentials for reporting. Its a little cumbersome but does work... The only downside to the way I have it set up currently is that they are never prompted to install my CA certificate and so many complain they can't access certain sites/applications because SSL interception fails...

Posted
If you're already using 802.1x for byod wifi auth, my advice would be to pass that straight on to a filter that can handle it (eg. my vote - the Smoothwall... I may have gone, but not forgotten!)
  • Thanks 1
Posted

We use the on boarding portal for staff devices only, to register their device against the AD username to put them on to the correct wifi network. They are filtered against limited categories.

 

Our pupils connect to the pupil wifi network, then it loads a smoothwall login page where they enter their AD credentials so it identifies them to filter accordingly. They have to login every two hours if they don't do any internet related activity. We have a limited number of concurrent connections allowed

Posted

It all depends on what your specific requirements are. Back when I was looking for a TMG replacement, I compiled a list (please note: I don't claim this to be 100% correct... It's based on what I was told by vendors) of what features some different alternatives had. I had a list of requirements of what i *had* to have in a UTM, and this meant that some products were instantly disregarded as a possibility.

TMG Replacement Options.JPG

  • Thanks 2
Posted

Just a note regarding the Sophos UTM. They acquired a company called Cyberoam in recent times and have changed their OS considerably. From what I've seen a lot of current Sophos customers are not overly impressed with the new appliance OS. I would imagine the positive comments re: Sophos UTMs are not based on the new appliance OS.

 

We currently use Cyberoam/Sophos firewall/filters. We have recently upgraded the OS to the new release from Sophos, which is very similar to the Cyberoam OS. I can't say that i would recommend it though against many of others mentioned so far, based on my experience of it at the moment. However, it does do what we need it to, but the interface and the way certain things are done leaves a lot to be desired.

Posted

Just r.e. Sophos UTM...

 

they still fully support the old UTM OS, they know the new product is a bit sub-par and will give you free downgrade rights on any Sophos hardware, so you can still upgrade later on whenever you're ready.

Posted

Thank you everyone once again for your input. I am certainly leaning towards the Smoothwall at the moment...

 

It all depends on what your specific requirements are. Back when I was looking for a TMG replacement, I compiled a list (please note: I don't claim this to be 100% correct... It's based on what I was told by vendors) of what features some different alternatives had. I had a list of requirements of what i *had* to have in a UTM, and this meant that some products were instantly disregarded as a possibility.

[ATTACH=CONFIG]35404[/ATTACH]

 

How up to date is this attachment?

 

Thanks!

Posted

Ive just had a look at that table and there should be quite a few ticks under the Fortinet which are not there at the moment.

 

it's quite interesting hearing about the UTM side of firewalls. Yes all firewalls should do UTM but just how good are they at doing it and how do you monitor how effective it is?

 

i've used a lot of firewalls in my time having spent 15 years doing nothing but and although a lot brag about doing certain features some are far far better. The key to using the best firewalls is understanding how they fully work and also the concepts of attacks and what someone managing your firewall should be doing. I'd highly recommend becoming certified with whichever vendor you decide to use otherwise you'll simply skim the surface of what your devices can do and how they work. It will normally cost to do this but quite often you can do self study (e.g. Fortinet FCNSA) and just pay to do the exam which is a couple of hundred pounds.

 

Dave

Posted
Remember with UTM devices if you use the device as your internet gateway watch those Interface speeds on the WAN, the speed will slow the more services that are enabled.

 

Absolutely I couldn't agree more with that.

 

I remember seeing one particular company at BETT last year (one of the list above) who guaranteed they could do a full Gbit throughput with all UTM functionality turned on scanning all user traffic for a secondary school for one of their standard devices. The conversation didn't go much further as they were talking rubbish....

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...