Jump to content

Recommended Posts

Posted

We are likely to set up our own WAN soon, and we'll need a filtering/firewall product to go with it.

 

I have got/am getting prices for:

 

Meraki

Lightspeed/Fortinet

Sophos UTM

Smoothwall

 

My question is - which do people think is better.

 

The Meraki MX appliances are nice bits of kit, but from what I can tell the filtering side seems a little limited (especially from a reporting POV). That said, they're also very competitively priced.

 

Lightspeed/Fortinet seems like a great pairing, good reporting etc...

 

Sophos looks pretty capable, especially if you add in the iView and Firewall Manager products for managing multiple devices and getting advanced reports.

 

Smoothwall, which has always been the favourite of Edugeek, and appears a great system also. That said, from prior quotes, its pretty expensive.

 

So, which would you go for?

Posted
Why go with a lightspeed and fortinet combo? Why not just the fortinet by itself?

 

That's the solution offered by an ISP. Lightspeed for filtering, Fortinet for firewall.

Posted

This is just my personal opinion but...

 

- Meraki ended up being a big fat no since hardware becomes a brick once you stop licensing them (urgh cloud managed stuff sucks)

 

- Smoothwall were way too pricey for us

 

- Sophos UTM is what we were using and I loved it. Our SG115 was a brilliant bit of kit and the software was fantastic. Filtering was top notch and staff never complained.

 

- We moved to the Lightspeed/Fortinet combo courtesy of our ISP, it's been relatively good, filtering is great, ability to filter mobile devices off network is really useful, but the UI isn't as polished.

 

Overall for me, it's always a toss up between Sophos UTM and Lightspeed at this point.

  • Thanks 1
Posted

Are you looking for onsite or cloud filtering/firewall ? when we were looking my preference was for an internet line on its own and then go with onsite filtering/firewall that I could manage but our new ISP managed to convince me otherwise with cloud based light speed and fortinet as they had all the high availability / redundancy so nothing would go down which we couldn't afford to replicate - but that hasn't turned out very well, if we had gone with onsite filtering/firewall I don't think we would have had any downtime.

 

But from what I have seen fortinet and lightspeed are good products, some schools I know just use fortinet for filtering with fortianalyzer for reporting.

Posted
Doesn't your ISP rate the fortinet filtering that well? From what I have seen it looks good.

 

I don't know, but Lightspeed/Fortinet is what they're offering us for the solution if we buy from them.

Posted

The Fortinet filtering is pretty good but in our experience too difficult for the average primary school teacher to use hence why we offer the Fortigate & Light speed combo.

 

The default reporting on Light speed is also very good and easier to use than Fortianalyzer.

 

That said we can offer hosted Fortigate & Fortianalyzer if you prefer as we offer this to our business customers and won best use of business cloud at a recent Internet Service Provider Awards ceremony.

 

Fortigate is a brilliant UTM / NGFW which is extremely powerful.

 

Dave

Posted
Have you looked at WatchGuard we find it very good and quick but the email spam interface is pants [emoji6] but why not take advantage of O365 email filtering and then collect you email from them without spam, plus you only need SMTP open to the Microsoft servers not the whole internet works like and SMTP relay.
Posted

We have SWall UTM-1000 which was sold to us (under BSF implementation) as suitable for our up-to 800 clients. The box isn't upgradeable, and they would now say that it isn't powerful enough for 800 users. Our license was paid to 2019!!!

 

They will let you transfer the license to your own server (one school locally has theirs on a virtual server) - and we do find it does what we need... You'll see some adverse comment when they moved to the Framlinghm release, but to be fair they ARE addressing the safeguarding agenda and improving setp by step.

 

We have a Cisco ASA firewall at our edge (managed by our ISP), and we do also use some additional control within the SWall appliance.

Posted

I recommend a good hard look at SOPHOS. Ref Meraki, we love the APs and Switches, but not overly keen on the firewall - easy to manage but we've found you need to significantly over-spec to get a bxo that will cope with all the features turned on.

 

We provide SOPHOS as a managed service, so although the cloud managed dashboard is pretty user-friendly, we're there to support and assist as and when needed. Fully supports PREVENT initiative too.

Posted

Smoothwall came in cheaper than competitors for us, interesting in light of the comments above. Filtering wise it's got some nice features but also does some silly things that our previous Bloxx unit handled better.

 

When looking at options it always seemed to be that the firewall-first vendors didn't have quite as flexible or education-focused filtering as the more specialist vendors. Watchguard I believe have Websense providing their database so slightly more intelligence there if you can only get the one device. Otherwise a combo of something like Fortinet or Palo Alto (if you have £££) along with a Lightspeed \ Smoothwall would be best of both worlds.

 

Also filtering in-line at the edge is preferable to using bridged proxy appliance but again the in-line high-spec firewalls tend not to have the more advanced filtering & Safeguarding features.

  • 6 months later...
Posted

Sorry to jump on an old post, but just wanted to add to the info above if anyone was using this as a knowledge-base to make a decision!

 

Following discussions with Meraki - their MX security appliances do not (yet) support DPI-SSL or HTTPS filtering (please also see https://documentation.meraki.com/MX-Z/Content_Filtering_and_Threat_Protection/Blocking_Websites_with_Content_Filtering_and_Layer_7_Firewall_Rules).

 

Personally for anyone considering the Meraki appliances for an install immediately, I'd consider this as a potential issue. Particularly with the likes of Google using HTTPS etc.

 

However, the AutoVPN makes it a doddle to configure VPNs between schools - perfect if setting up for a MAT/ partner schools. (Although other products are available out there that aren't particularly complex).

Posted

Experience with BLOXX and Sophos

 

Sophos is prob better for support, rolled out 4 proxy's at last place with management for load balancing. Had absolute minimum problems in the 4 years I was there :-).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...