Popular Post AMLinington Posted February 24, 2017 Popular Post Posted February 24, 2017 (edited) I think you've been misled. I also find the reporting unbelievably unnecessarily complicated - you should have asked to see this in a demo rather than just taking for granted some salesman's flannel.... Could be why our current SW box complains about processor load all the time As a former SW minion (they made me redundant, so believe me, I'm not interested in doing anyone any favours out of the goodness of my heart), I have some perspective on both the cost AND reporting capability of the SW product. I have a lot of respect for the SW product, but it is not without its challenges. The trouble is, when it comes to web filtering - especially in schools, people want to have their cake, eat it, and for it still to be whole. When a product performs an action or fulfils a purpose, everything you ask it to do requires system resource to a greater or lesser extent. Web Filtering is MASSIVELY intensive - if you want it to be GOOD and FAST it has to call a lot of functions in the code. So you have to compromise on the things that aren't directly related. If you want epic levels of reporting, the product is going to have to process and store every nano-molecule of data going through it. If you want to pull complex reports, the reporting engine has to scan all that complicated data and cross reference it against your parameters, which again requires a SHEDLOAD of processing power and memory. Pick 2: It is unreasonable to expect a single box to be able to do everything concurrently. Someone pointed out that Fortinet offer a separate reporting module for additional cost, but that it nukes processing power - I imagine it does. Every product out there has to find their own balance and decide where they want to pitch their product - if they want to offer epic levels of reporting, then they need to trim back other processes so the quality of the filtering might be affected. If you want high quality filtering and epic reporting, the box is going to be slow and bogged down by running processes. If you want great filtering and a speedy box you'll need to compromise on all the other things you're asking it to do. You cannot directly compare each product, because they will all have compromised in certain areas. The key is for you, the customer, to identify your priorities and pick that product that is the closest match - if quality of reporting is super-high on your priority list and you aren't altogether worried about dynamic content filtering because your student demographic is basically given access to pretty much everything, then pick a box that has a less effective filter and a better reporting system. If you have a bunch of troublesome students and the governors breathing down your neck to lock out every possible tiny thing, then you'll need to compromise in other areas. There is nothing wrong with changing your product to meet your changing priorities, but understand that you won't get everything - you will have to compromise with every product. You cannot directly compare the reporting in one box with the reporting in another if their levels of filtering are vastly different. Which brings me around to cost. Even before they dumped me like a broken a chair, the costs of the SW product were increasing massively. I've been behind the scenes and peered around the curtain and can tell you that the 'old prices' were MASSIVELY undervaluing the product. I've sat with developers as they work on the SW product and know that in order to maintain development and continual improvement of a product, you can't manage on a small development team. If you want a product that relies on doing the same thing year in, year out, without ever changing or adapting to the changing environment, then it will obviously cost next to nothing, because the vendor isn't having to pay a big team to keep pace. I've been in support - some of you have probably even spoken to me on the phone. When I was there, I was PROUD to be a part of the support team because the business CARED about going above and beyond for the users. Yes, there will ALWAYS be unsatisfied customers that feel 'fobbed off' or feel like they don't get good value, but I can tell you that this is not the customer service ethos (or it wasn't when I was there - I can't comment on their business priorities these days). I miss being part of that team. I miss the guys there. We'd have 'technicians' phone us up having done ZERO troubleshooting themselves. I've lost count of the number of times a customer knee-jerk called support to complain about the product having failed to perform any reasonable tests of their own network and infrastructure. SO MANY TIMES I would run packet traces and discover that the customer had installed a product that was messing with routing, faffed with DHCP or DNS or has an internal networking SNAFU that has nothing to do with the product. Is it my job to support your internal network? Are you paying SW to support your network? Of course not. Would you phone Microsoft to complain that Windows was broken when your PC isn't even plugged in? But the SW engineers did it anyway because they are GOOD. SO GOOD. It might not seem like it, but SW customers get waaaaaay more for their money support-wise than some companies would give you. I won't say they're perfect because they aren't. But they aren't a faceless script-reading entity and that might not have a monetary value, but it certainly costs SW to maintain that ethos. A cost reflected in the price of the product. There aren't many first and second line support desks that have a direct link to the developers of the product. Not many that can get a developer to help them tweak a piece of the SOFTWARE CODE ITSELF to solve your problem. I won't lie, I have literally zero respect for sales people - they are mostly non-technical and have very little idea of the work that goes in behind the scenes. Returning to the cake analogy, they give the 'bakers' (Developers and Support) 2 eggs, 4oz of Flour and 2oz Butter, then promise the customer a 4 tier chocolate masterpiece containing a tiny clockwork bird that flies out when the cake is cut. It doesn't work that way. I can't comment on the current state of the SW product because I've been out of the game for a while, but I do think that many users I see complaining on this and other tech forums about the performance and reporting of their respectively chosen filtering solution (whether it is Sophos, Bloxx, SW, Fortinet, etc) have really unrealistic expectations because they have little to no understanding of how the underlying code, data logging and databases within their products actually work. In part I blame sales people, because they promise the earth based on benchmarking done under controlled conditions and with the best spec hardware. We all know real life doesn't work that way. EVERY part of a product is the result of carefully calculated and debated cost compromises - you want a new reporting system built from scratch? Great! But it won't happen by the 3 month deadline. So a company will develop and improve the existing platform, but that can result in complex and convoluted UI processes. It's a toss up - difficult to use but THERE, or 'Simple to use' but will take 10 years to develop from scratch? Anyone familiar with ServiceNow? Great, versatile product but OH SWEET MERCY it's complicated. You can actually TELL where the code and development for one feature finishes and another one starts because it's SO BLIMMIN COMPLICATED and one part of the product works in a totally inverse way to another part. The SW product is the same (and I hazard a guess a bunch of the others are too, but I have no experience with them). So my advice would be to assess each product based on your own unique priorities, and understand that each product will have strengths and weaknesses in different areas. So pick the one that is the best fit for your organisation - the one that 'ticks the most boxes'. This might change over time or you might need to accept that the 'nice to haves' will have to make way for the 'ESSENTIAL's. Edited February 24, 2017 by AMLinington 11
kearton Posted February 24, 2017 Posted February 24, 2017 What don't you like about the inbuilt reporting in the SG UTMs? I've been pretty happy with it - it emails me a list of all "extremism" hits and who did it etc... each week, for example. It's not granular enough for my needs. A Daily/Weekly/Monthly report of one of the 5 inbuilt reports (of which "extremism" isn't one for me... unless you mean as included in the "Policy Violators" report(?) which is far too generic for my needs... finding stuff is like finding a needle in the haystack... and the PDFs aren't text searchable for me either) doesn't cut the mustard here. FastVue gives us realtime alerts, and the reports you can run or schedule are very granular.
localzuk Posted February 24, 2017 Posted February 24, 2017 It's not granular enough for my needs. A Daily/Weekly/Monthly report of one of the 5 inbuilt reports (of which "extremism" isn't one for me... unless you mean as included in the "Policy Violators" report(?) which is far too generic for my needs... finding stuff is like finding a needle in the haystack... and the PDFs aren't text searchable for me either) doesn't cut the mustard here. FastVue gives us realtime alerts, and the reports you can run or schedule are very granular. You can make your own reports - which is what I have done. Took a few minutes to set up how I wanted.
Simcfc73 Posted February 24, 2017 Author Posted February 24, 2017 @AMLinington A very passionate response of SW. I've been a user for 15 years (ish) so I obviously like it but reporting has been promised a overhaul for longer than I remember... and the safeguarding logs are nowhere near what was shown to me in leeds 12 months ago. If they came out and said our reporting wouldnt improve due to the brilliant filtering. fine... I'll be doing a pro/con evaluation of all the products I look at.. as well as my time learning a new product if I move.
kearton Posted February 24, 2017 Posted February 24, 2017 You can make your own reports - which is what I have done. Took a few minutes to set up how I wanted. There is that. But I find it advantageous to know that little Johnny has googled "how to commit suicide" in realtime rather than in a summary email at 12:46am... :/ I'll have to take a closer look at the custom ones tho. (I do use the Daily Top10 already). Thanks.
AMLinington Posted February 24, 2017 Posted February 24, 2017 @AMLinington A very passionate response of SW. It is probably worth reiterating that I do not work for Smoothwall anymore. I was made redundant and discarded. So my comments are based on my own opinions of the product and not out of loyalty or because they are my employer. As I said, I have a lot of respect for the Smoothwall Product and for the Support and Development teams, but objectively, having been 'behind the scenes' I am aware of the challenges and can provide some relevant insight. But my comments should not be construed as representing Smoothwall in any way.
AlanD Posted February 25, 2017 Posted February 25, 2017 Well - I certainly agree with the conclusion. Assess the products out there and evaluate their strengths and weaknesses. It would seem to me that too many schools take a look at what others around are using - and use that as an argument for implementing it. I thought SW did better than most to address the prevent strategy....and provided a hardware firewall with the ability to provide relatively seamless BYOD use as it acts as a radius and DHCP server. And we were keen on a solution which could do reverse proxy. Yes it has limitations,....and I am currently struggling to get lots of APPS to work for mobile devices without either making them "invisible" by bypassing https inspection for them, or blocking them - or risking holes that allow users to bypass authentication. Its good to prevent users from being able to download potentially infected word macro files, but simply blocking all word files is not so useful. And it would have been nice if files from "official" sites like exam boards and government were not blocked by default. Perhaps they should take a look at the "exceptions" that lots of schools end up adding and after inspecting them (and making any appropriate changes) have a "school configuration" that is likely to meet the needs of schools without lots of school based customisations.
Wave9_Lee Posted February 28, 2017 Posted February 28, 2017 Hi Simcfc, I'd be happy to provide a quote and some options for you. If you'd like a demo, or a chat with one of our technical team, no problem. DM me your details if you'd like a quote. kind regards Lee
bicky Posted February 28, 2017 Posted February 28, 2017 +1 for iBoss We were using Smoothwall appliance for last three years, now moved to iBoss which is much better. We used to use proxy when using SW, now with the iBoss no need to push the proxy settings. Few application had issue connecting via proxy.
AlanD Posted February 28, 2017 Posted February 28, 2017 I am a relatively new user to smoothwall - and so still getting the hang of it. I thought the reporting looked fine - no worse than Websense (now forcepoint) that I was used to. And I liked the Safeguarding provision a lot. But...the safeguarding reports don't have the customisation that the main reports have (didn't realise that earlier ).....so I would quite like to email reports to appropriate Heads of year which ONLY have the reports for the users in that year group. Don't understand why safegiarding section doesn't have the customisation tools available elsewhere. ...and I'd like to be able to clear up some of the "clutter" to make the reports more understandable/readable without the multiple line quoted content. And currently I'm forever having to "unblcok" or allow sites - such as downloads from exam boards - which are clearly going to be safe for schools.... ...oh...and APPS on mobile devices are a bit of a nightmare - I seem to have to practically allow a list of URLS for each APP to bypass https inspection or authentication to allow them to work. But I'm not saying the competition is any better....because I looked at several of those. And I liked the fact that BYOD works nicely with it using it as a Radius server and DHCP server....and I like the reverse proxy....and the load balancing....
mikkydoos Posted March 1, 2017 Posted March 1, 2017 Moving from SW to Sophos in a couple of weeks. Was impressed by the demo we had (UI much better than SW) and the price was sensible (SW quote was just silly). I sought out some honest feedback from Sophos users and all were very positive. Had a demo of Sophos recently. Looked great. Stuck with Smooth' after hammering them down on the price and to avaoid the hassle. Will change next time around though.
CSmith Posted March 1, 2017 Posted March 1, 2017 And it would have been nice if files from "official" sites like exam boards and government were not blocked by default. Perhaps they should take a look at the "exceptions" that lots of schools end up adding and after inspecting them (and making any appropriate changes) have a "school configuration" that is likely to meet the needs of schools without lots of school based customisations. Hi @AlanD - Usually when you first set up your Smoothwall you're presented with the option to chose your default web filter policies - selecting Education from this list will create three allow policies, for 'Education and Reference', 'Academic Institutions', and 'Government' - these should cover the "official" sites you're referring to. If you didn't/haven't seen that page then I'd recomend allowing those three categories which should reduce any overblocking issues. We usually (almost always) categorise exam related sites (such as exam boards) as 'Education and Reference' but it's possible we've missed some - if you (or anyone else) is experiancing any issues with exam related sites then please PM me so we can work to resolve these issues Chris
Jehanzeb Posted March 1, 2017 Posted March 1, 2017 Smoothwall has been fine for us too but yes reporting awful. I ran a custom report on an IP address 10.x.x.x between 01/02/17 to 24/02/17 and it crashed twice before it produced the report which I converted in PDF, 61Mb in size. Not a presentable report to higher management. I also struggle to setup reports be send to email directly. I am counting on Inverness to fix some of the major issues including reporting. At the end of the day higher management and parents (if they ask for it) need simple to understand reports and quick, not in 5hrs or more. Kindest regards J. 1
kennysarmy Posted March 2, 2017 Posted March 2, 2017 Smoothwall has been fine for us too but yes reporting awful. I ran a custom report on an IP address 10.x.x.x between 01/02/17 to 24/02/17 and it crashed twice before it produced the report which I converted in PDF, 61Mb in size. Not a presentable report to higher management. I also struggle to setup reports be send to email directly. I am counting on Inverness to fix some of the major issues including reporting. At the end of the day higher management and parents (if they ask for it) need simple to understand reports and quick, not in 5hrs or more. Kindest regards J. Better reporting is coming
wickit Posted March 2, 2017 Posted March 2, 2017 Better reporting is coming Smoothwall is taking notes from Valve 2
wickit Posted March 2, 2017 Posted March 2, 2017 Better reporting is coming Smoothwall is taking notes from Valve 2
mikkydoos Posted March 2, 2017 Posted March 2, 2017 (edited) Doesn't mention reporting Edited March 2, 2017 by mikkydoos
nicholab Posted March 7, 2017 Posted March 7, 2017 (edited) I still worrying about a Sophos UTM being as bad as hosted light speed was for not stopping the wrong stuff and having to unblock other stuff. Also does it do a good enough job for prevent alerting? Edited March 7, 2017 by nicholab
Simcfc73 Posted March 7, 2017 Author Posted March 7, 2017 I had a long conversation with a Sophos guy (sales so take it with a pinch of salt) but according to him the next release of Sophos due Easter will have useful safeguarding reporting that you can actually use and hand out. Also mentioned keyword filtering
kennysarmy Posted March 8, 2017 Posted March 8, 2017 I had a long conversation with a Sophos guy (sales so take it with a pinch of salt) but according to him the next release of Sophos due Easter will have useful safeguarding reporting that you can actually use and hand out. Also mentioned keyword filtering If you could PM me his email address that would be most useful. Cheers
Simcfc73 Posted March 8, 2017 Author Posted March 8, 2017 it was setup through Softcat so they organisedit all.. Just waiting for a price now but very tempted.
MYK-IT Posted March 10, 2017 Posted March 10, 2017 (edited) @Simcfc73 We had Sophos in yesterday, demonstrating and explaining all about their Sophos XG Solution; and how it can expand and support Sophos Cloud, (We are currently using Sophos Enterprise Console). The GUI was definitely a breath of fresh air (compared to our existing Smoothwall) but of course, it's the features that are most important, and that it is able to meet the demands and requirement technically, from a security, detection and preventative point of view as well as our DSL's requirements, in respect of KCSIE / PREVENT. The 'heartbeat' function was very good, for protecting (remote) devices not connected directly to the School's Network; but would still be protected and filtered as per School-based filtering; and how device(s) can be blocked, or limited if security / AV level is not current etc. Additionally, we have been researching SonicWALL and Fortinet as well as continued discussions with Smoothwall on how their product (and reporting) is going to be updated and improved over the next few releases etc. Despite the many meetings and time spent researching, it is proving to be a very worthwhile exercise in respect of being brought up to date with the latest (and future) developments and features of the various potential products etc. Edited March 10, 2017 by MYK-IT
buzzard Posted March 10, 2017 Posted March 10, 2017 If I was looking at buying any solution, I'd almost certainly arrange a trial and that the purchase is dependent on the success of the trial. Did that with SW and it was all sorted, configured and working before we spent a penny.
Simcfc73 Posted March 10, 2017 Author Posted March 10, 2017 I have the ISO to make a virtual machine so will have a play with that. Shame it hasnt got the safeguarding and keyword stuff on that he mentioned. The deal they sent me was very very tempting though.. but I have to buy it by the end of this month.
Arcolite Posted March 15, 2017 Posted March 15, 2017 (edited) We've recently removed our web filtering from a dedicated appliance to being handled purely by our Palo Alto Firewall. Best decision we've made - our internet speeds have increased dramatically. Our previous products (Bloxx and CensorNet, both Squid proxies) seemed to be a bottle neck. We did look at Smoothwall, but the quote was more than we had budgeted, especially when we're already paying for a URL subscription from Palo Alto. Edited March 15, 2017 by Arcolite
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now