localzuk Posted May 6, 2016 Posted May 6, 2016 We are likely to set up our own WAN soon, and we'll need a filtering/firewall product to go with it. I have got/am getting prices for: Meraki Lightspeed/Fortinet Sophos UTM Smoothwall My question is - which do people think is better. The Meraki MX appliances are nice bits of kit, but from what I can tell the filtering side seems a little limited (especially from a reporting POV). That said, they're also very competitively priced. Lightspeed/Fortinet seems like a great pairing, good reporting etc... Sophos looks pretty capable, especially if you add in the iView and Firewall Manager products for managing multiple devices and getting advanced reports. Smoothwall, which has always been the favourite of Edugeek, and appears a great system also. That said, from prior quotes, its pretty expensive. So, which would you go for?
Dragon Posted May 6, 2016 Posted May 6, 2016 Why go with a lightspeed and fortinet combo? Why not just the fortinet by itself?
localzuk Posted May 6, 2016 Author Posted May 6, 2016 Why go with a lightspeed and fortinet combo? Why not just the fortinet by itself? That's the solution offered by an ISP. Lightspeed for filtering, Fortinet for firewall.
Blue_Cookeh Posted May 6, 2016 Posted May 6, 2016 This is just my personal opinion but... - Meraki ended up being a big fat no since hardware becomes a brick once you stop licensing them (urgh cloud managed stuff sucks) - Smoothwall were way too pricey for us - Sophos UTM is what we were using and I loved it. Our SG115 was a brilliant bit of kit and the software was fantastic. Filtering was top notch and staff never complained. - We moved to the Lightspeed/Fortinet combo courtesy of our ISP, it's been relatively good, filtering is great, ability to filter mobile devices off network is really useful, but the UI isn't as polished. Overall for me, it's always a toss up between Sophos UTM and Lightspeed at this point. 1
whs1000 Posted May 6, 2016 Posted May 6, 2016 Are you looking for onsite or cloud filtering/firewall ? when we were looking my preference was for an internet line on its own and then go with onsite filtering/firewall that I could manage but our new ISP managed to convince me otherwise with cloud based light speed and fortinet as they had all the high availability / redundancy so nothing would go down which we couldn't afford to replicate - but that hasn't turned out very well, if we had gone with onsite filtering/firewall I don't think we would have had any downtime. But from what I have seen fortinet and lightspeed are good products, some schools I know just use fortinet for filtering with fortianalyzer for reporting.
Dragon Posted May 6, 2016 Posted May 6, 2016 Doesn't your ISP rate the fortinet filtering that well? From what I have seen it looks good.
localzuk Posted May 6, 2016 Author Posted May 6, 2016 Doesn't your ISP rate the fortinet filtering that well? From what I have seen it looks good. I don't know, but Lightspeed/Fortinet is what they're offering us for the solution if we buy from them.
SchoolsBroadband Posted May 7, 2016 Posted May 7, 2016 The Fortinet filtering is pretty good but in our experience too difficult for the average primary school teacher to use hence why we offer the Fortigate & Light speed combo. The default reporting on Light speed is also very good and easier to use than Fortianalyzer. That said we can offer hosted Fortigate & Fortianalyzer if you prefer as we offer this to our business customers and won best use of business cloud at a recent Internet Service Provider Awards ceremony. Fortigate is a brilliant UTM / NGFW which is extremely powerful. Dave
LytchettNM Posted May 7, 2016 Posted May 7, 2016 Have you looked at WatchGuard we find it very good and quick but the email spam interface is pants [emoji6] but why not take advantage of O365 email filtering and then collect you email from them without spam, plus you only need SMTP open to the Microsoft servers not the whole internet works like and SMTP relay.
bodminman Posted May 8, 2016 Posted May 8, 2016 we too will be starting to look for a Filter/Firewall solution as out Lightspeed Rocket subscription runs out in Sept.
Mistert89 Posted May 8, 2016 Posted May 8, 2016 We have SWall UTM-1000 which was sold to us (under BSF implementation) as suitable for our up-to 800 clients. The box isn't upgradeable, and they would now say that it isn't powerful enough for 800 users. Our license was paid to 2019!!! They will let you transfer the license to your own server (one school locally has theirs on a virtual server) - and we do find it does what we need... You'll see some adverse comment when they moved to the Framlinghm release, but to be fair they ARE addressing the safeguarding agenda and improving setp by step. We have a Cisco ASA firewall at our edge (managed by our ISP), and we do also use some additional control within the SWall appliance.
Wave9_Lee Posted May 10, 2016 Posted May 10, 2016 I recommend a good hard look at SOPHOS. Ref Meraki, we love the APs and Switches, but not overly keen on the firewall - easy to manage but we've found you need to significantly over-spec to get a bxo that will cope with all the features turned on. We provide SOPHOS as a managed service, so although the cloud managed dashboard is pretty user-friendly, we're there to support and assist as and when needed. Fully supports PREVENT initiative too.
gshaw Posted May 10, 2016 Posted May 10, 2016 Smoothwall came in cheaper than competitors for us, interesting in light of the comments above. Filtering wise it's got some nice features but also does some silly things that our previous Bloxx unit handled better. When looking at options it always seemed to be that the firewall-first vendors didn't have quite as flexible or education-focused filtering as the more specialist vendors. Watchguard I believe have Websense providing their database so slightly more intelligence there if you can only get the one device. Otherwise a combo of something like Fortinet or Palo Alto (if you have £££) along with a Lightspeed \ Smoothwall would be best of both worlds. Also filtering in-line at the edge is preferable to using bridged proxy appliance but again the in-line high-spec firewalls tend not to have the more advanced filtering & Safeguarding features.
Techie2000 Posted December 6, 2016 Posted December 6, 2016 Sorry to jump on an old post, but just wanted to add to the info above if anyone was using this as a knowledge-base to make a decision! Following discussions with Meraki - their MX security appliances do not (yet) support DPI-SSL or HTTPS filtering (please also see https://documentation.meraki.com/MX-Z/Content_Filtering_and_Threat_Protection/Blocking_Websites_with_Content_Filtering_and_Layer_7_Firewall_Rules). Personally for anyone considering the Meraki appliances for an install immediately, I'd consider this as a potential issue. Particularly with the likes of Google using HTTPS etc. However, the AutoVPN makes it a doddle to configure VPNs between schools - perfect if setting up for a MAT/ partner schools. (Although other products are available out there that aren't particularly complex).
Davit2005 Posted December 6, 2016 Posted December 6, 2016 Experience with BLOXX and Sophos Sophos is prob better for support, rolled out 4 proxy's at last place with management for load balancing. Had absolute minimum problems in the 4 years I was there :-).
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now