Ditto Posted March 23, 2018 Posted March 23, 2018 (edited) We're looking at the whole content/web-filtering/secure web gateway implementation - even the correct terminology is a challenge! I'm looking to fast-track to a shortlist based on the wisdom of edugeekers (users only - no sponsors please!) To narrow it down, any solution must cover Windows AD users, GSuite users/Chromebook use and mobile device and support multiple sites. For the solutions you are using that meet that requirement, could you score out of 5 (5 high, 1 low) on the following: Effectiveness Ease of use Value for money Support Reporting (i.e. to DSL/Heads etc.) Flexibility/configuration I'm especially interested in a cloud based solution, but open minded to more traditional hardware if it's significant better. Many thanks in advance. - - - Updated - - - Not sure how I got Cool icon in the title - any ideas how to remove? Edited March 23, 2018 by ZeroHour Removed icon, its below the post area fyi - ZeroHour
AlanD Posted March 24, 2018 Posted March 24, 2018 Well..don’t base your decision on what other schools say or do...but by all means take some of that into account. Only you know what is important...so you probably need to get some test kit in place to trial...and yes that’s a pain. Some wish to keep router, firewall and filter functions all separate. I think functionality overlaps these days...although I don’t think there is truly a product out there that manages this integration well...often a single box with separate menus inside....For example you might wish to allow Spotify. So you tick a box in the filter to allow streaming media services or whatever...and it doesn’t work. You then discover the filter doesn’t include rules for Spotify so you add a list of urls. It still doesn’t work...and you have to add some firewall exception rules in completley separate menu. And because it’s a mobile wireless device you later discover you need to add some https interception inspections. Finally it works...but you can’t see the usuage because you had to add the exceptions. All is well for a couple of months, and then it stops working. You discover you have to change and add urls to the filter, change inspection rules, etc, etc.Later you decide to remove access to Spotify...but you can no longer tell or remember which exceptions or URL’s belong to Spotify..because they are just part of a long list for various services you added. You would be thinking why doesn’t the filter privider provide this granularity and do it once for all their customers...but the reality is that once they have sold you their kit it’s only then you begin to see its limitations. I’d like to see the ability to create a filter set of rules for a particular app which includes urls, firewall, and exceptions in one place...and tick or untick it’s ability to work. Better still have that named rule set download and be updated from the filter supplier. Why every school has to separately google the firewall and filter rules and individually add them is rediculous. We wanted reverse proxy capability...because we host the odd thing from inside school...to allow access to home folders, etc. That started to limit our choice. And while we took a long look a cloud filters it always seemed somewhat convoluted to get our AD credentials visible...and often firewall functionality for cloud offerings were seemingly limited ..and in particular the firewalls were unaware of AD groups...and we like to say to the firewall let staff use this port or whatever...but not students. Some required cloud identification like RM unify. Then we wanted good prevent strategy reporting. So we needed to see google search details...not just this site was blocked. And we wanted to report different year groups to different year heads...not simply have one big report. Several global produced filters barely delivered on this front...and while all sorts of hand configurations and setups were possible...they would probably take half a lifetime to setup. We wanted full prevent strategy reporting out of the box. Then we wanted a box which would take 2x ISP connections with load balancing....and at least 300mb/s throughput...and at least the possibility of a fully redundant system with a second box with failover capability.. For us it eventually came down to Sophos or smoothwall....which are both pretty awful in many respects...and rediculously expensive...especially as neither are capable of stopping VPN clients drilling straight through them. And by the time you have finished adding exceptions for mobile apps you will wonder why you bothered with any filter, because there will be no prevent reporting on usage. Be prepared to drive a very hard bargain....and make it clear you are going for a different choice unless there is a significant discount. And don’t let let make you thing you are getting a fantastic deal because they offer you free set up or an additional year. Make them agree to several extra years ...and guarantee a future renewal price no more than current charge...and to come back 9 months after install for free to iron out problems. Most suppliers think schools are a soft target to sell into because unlike industries they often don’t have competence to make technical demands...and don’t have the balls to negotiate a bargain. We did quite like the way smoothwall has integrated DHCP, DNS and radius....as well as a captive portal...all of which makes it as easy as it ever can be for wireless devices..and we use it to route between our VLans because it is AD aware of IP addresses and so can allow staff but not students to access airserver to projectors for example. ...and that’s what we went for.....but you need to make your own decision based on your requirements and focus of importance. 1
karldenton Posted March 24, 2018 Posted March 24, 2018 Hi I have 2 setup on our network. I use a Sophos UTM SG230 for the firewall and filtering. It accepts several incoming connections, works happily with AD for filtering groups etc. The only downside to it is the reporting. Effectiveness. - 5 Ease of use - 3 Value for money - 4 Support - 5 Reporting (i.e. to DSL/Heads etc.) - 2 Flexibility/configuration - 5 I then use Netsupport DNA on top of that for the reporting / online safety side. Very easy to use, nice reports Effectiveness - 5 Ease of use - 5 Value for money - 5 Support - 5 Reporting (i.e. to DSL/Heads etc.) - 5 Flexibility/configuration - 5 1
ADMaster Posted March 24, 2018 Posted March 24, 2018 I can’t score on all fronts as some others. I have an Iboss, but it and firewall are paid for upstream as a larger package. Effective 3.5 – 4 SomeVPNs will drill right through, but that’s going to be almost all products. Ease of use 5 Value N/A Support 4 Reporting, difficult to score, I can make it send alerts to different people for different groups, however it lacks on some of the bandwidth reporting and drilling down to figure out where traffic is flowing. So a basic search terms report for a user is easy, for safeguarding. A tech view of things isn’t as comprehensive as I’d like. Flexibility / configuration 5. Very easy to configure and set different rules for different groups. I have the onsite version, they do have a cloud offering now too. We also use other tools to monitor for safe guarding. I’d also like to add a counter point to @AlanD need for the firewall to know the user / AD group. Yes it would be nice, but you can achieve similar results with Vlans. If you put staff and students in separate vlans, you can apply firewall rules based on subnet. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now