Jump to content

Recommended Posts

Posted

Currently have a Smoothwall with an S8 appliance. I prefer keeping firewall + filtering together in a UTM device ideally, and our contract ends in April next year so I'm looking at testing some alternative solutions between now and then...

 

At the moment i've spoken to Sophos and Sonicwall and I'm considering staying with Smoothwall as another option. Has anyone got any other recommendations that fit well within a secondary school (1200 pupils, 600-700 domain devices, BYOD, 300 potentially 500mb wan)

 

Any suggestions i could take a look at please? Any comparisons you can make against your suggestions with Smoothwall (how it's been better or worse) would also be helpful.

Posted
My current MAT has Smoothwall. TBH, I wish it had SonicWALLs instead. The Smoothwall filter is better but SonicWALL is a much better firewall. From what I understand, the reporting product that SonicWALL are bundling with the product is better than what Smoothwall provides as well but, well, that wouldn't be hard.
  • Thanks 1
Posted

I can't speak highly enough of Fortigate UTM devices. They're not in Gartners top quadrant by accident.

 

They are also not licenced on a per user basis, but on a per device basis with different options which included sandboxing, Internet of compromise etc etc See https://www.fortinet.com/fortios for a full feature set.

 

If you want a quote on one or you wanted to use our highly resilient cloud hosted virtualised appliances we can simply "sit on top of" your Internet connection then we'd be happy to do that too. We've won awards at the Internet Service Provider award ceremony the last two years running for our hosted Fortigate and Fortianalyzer service. It really is very good.

 

 

Happy to answer any specific questions you may have.

 

Dave

Posted
We're loving our new Sophos XG, does pretty much everything we need. Reporting still not quite there but it's more than enough to cover all the bases. *way* beyond Smoothwall, which is a name I now dread hearing :(
  • Thanks 2
Posted

I like Sophos security bundle and if I had that little extra money at the time I might have gone that way. Instead we have smoothwall s8 and s4’s across our sites and recently changed our broadband to wave9. We get great throughout and we are now doing training as a team to make sure we get the most out of the product.

Fortinet are military grade, and again if I could afford it I would - I had demo and thought the educational safeguarding reporting was more important and it didn’t have that feature , so went with smoothwall.

We have HP switches and the fortinet security appliance can do SDN stuff like turn off Aruba switch port 14 in the science lab if malware is detected etc there is a YouTube video of the setup and I was impressed!

Don’t know much about sonicwall but I think it’s considered highly in industry.

Pfsense I think is an option if you have no money - I believe there is a firewall and filtering version which is open source and you could implement it via a virtual appliance etc. On LinkedIn training (now Microsoft) there is a video series on how to setup the firewall and filter. If I had a primary school etc with no money you could do this and maybe look at opendns cloud dns safety filtering ?

 

I do like my Smoothwall’s but still learning what they can do, so I guess it’s budget and safeguarding features for me.

 

Wave9 have been great with getting my sites gig bearer broadband and I can highly recommend them.

 

Thanks

John

  • Thanks 1
Posted
Add fastvue, http://www.fastvue.co,

to get really good reporting. So much better that the built in stuff.

 

That's very interesting, not seen that before. Might give that a look if i can down the route of one of their supported products.

Posted
Just requested a quote on that, interesting indeed. The big problem for the majority of UTMs these days appears to be having to siphon through all the cdns, social media links in pages flagging up obscuring the actual results we need.
Posted
As both Sonicwall and Sophos offer endpoint solutions i was also thinking of taking up their endpoint protection solutions, anyone have an experience of those or would you stick with SCCM doing AV?
Posted
As both Sonicwall and Sophos offer endpoint solutions i was also thinking of taking up their endpoint protection solutions, anyone have an experience of those or would you stick with SCCM doing AV?

We have a Sophos UTM and did look at using the endpoint software, however it was sooooo expensive relative to continue using SCCM + SCEP so stuck with that.

Posted
We have a Sophos UTM and did look at using the endpoint software, however it was sooooo expensive relative to continue using SCCM + SCEP so stuck with that.

 

Thanks, must admit i've not seen any prices for that yet. I remember the good old days where we paid pittance for sophos AV due to an LEA agreement, but that offer died off i think.

Posted
Thanks, must admit i've not seen any prices for that yet. I remember the good old days where we paid pittance for sophos AV due to an LEA agreement, but that offer died off i think.

If you have an MS agreement with the SCEP cals included then you are already good to go, we needed to add them on to our agreement but the price was crazy low.

Posted

Hi Mrbios,

 

I'd be happy to look at a quote for your Sophos and provide any advice/demo if required. We also offer some great pricing on endpoint.

 

Kind regards

Posted
What are peoples thoughts of moving there firewalls or part of into the "cloud", I was more thinking about attack mitigation ie. DDOS attacks etc, the UTM will start blocking this but your local connection will probably be saturated by then so of little use. (Have seen this happen at a local school so it does happen.
Posted

You are 100% right. If you get a DDoS and you have a direct internet connection with onsite firewall then this will get easily saturated until your ISP attempts to put a block to it. Putting big firewalls in the cloud does help to reduce DDoS impacts as they soak up the DDoS in our data centres first.

 

Ours do this already. We get DDoS'd at least once a week and customers normally don't notice.

 

Thanks

 

Dave

Posted
You are 100% right. If you get a DDoS and you have a direct internet connection with onsite firewall then this will get easily saturated until your ISP attempts to put a block to it. Putting big firewalls in the cloud does help to reduce DDoS impacts as they soak up the DDoS in our data centres first.

 

Ours do this already. We get DDoS'd at least once a week and customers normally don't notice.

 

Thanks

 

Dave

 

I did get a comparison quote from yourselves, I am considering. Would there be a way of leveraging the cloud firewall protection on our mobile clients when using not using our local connection?

Posted
What are peoples thoughts of moving there firewalls or part of into the "cloud", I was more thinking about attack mitigation ie. DDOS attacks etc, the UTM will start blocking this but your local connection will probably be saturated by then so of little use. (Have seen this happen at a local school so it does happen.

 

Depends on exactly what you're firewalling - if its just internet traffic then putting the firewall at the ISP might be fair enough. If you need to firewall your internal networks (e.g. controlling traffic between lesser-trusted networks and trusted stuff) then you really want it on-site. You don't want traffic between your local networks having to go up to your ISP and back down again.

 

If its just DDoS protection you want, you don't need a full firewall at the ISP, just ask your ISP about their DDoS protection products in addition to running your own on-site firewall. Your mileage may vary though - I've seen a school DDoSed once (by a disgruntled ex-student!) and Virgin Media were pretty unhelpful when it happened, because they school weren't paying them enough.

 

I'm a big believer in UTM products - as applications are increasingly mixing different types of traffic, keeping your firewall and web filter separate seems a bit of a nonsense to me. So then you're talking about whether you want to put the web filtering on the ISP's end of the connection too (which is exactly what folks like @SchoolsBroadband do, of course).

Posted
I'm a big believer in UTM products - as applications are increasingly mixing different types of traffic, keeping your firewall and web filter separate seems a bit of a nonsense to me.

 

At the risk of going a bit off topic, the benefit that I can see is that if you have a separate firewall and filter, you have the potential to end up with a better experience overall. For example, Smoothwall is a very good filter but its firewall is comparatively weak (in my opinion). SonicWall has the opposite problem, a relatively weak filter but an excellent firewall. The trouble of bundling a load of functionality into one product (and this goes for almost anything, not just UTMs) is that there is always going to be one area of functionality which is stronger than the other.

 

Now, you may feel that the firewall in UTM X or the filter in UTM Y is good enough in either instance but there is sometimes clear reasoning to use two separate products.

Posted
Depends on exactly what you're firewalling - if its just internet traffic then putting the firewall at the ISP might be fair enough. If you need to firewall your internal networks (e.g. controlling traffic between lesser-trusted networks and trusted stuff) then you really want it on-site. You don't want traffic between your local networks having to go up to your ISP and back down again.

 

If its just DDoS protection you want, you don't need a full firewall at the ISP, just ask your ISP about their DDoS protection products in addition to running your own on-site firewall. Your mileage may vary though - I've seen a school DDoSed once (by a disgruntled ex-student!) and Virgin Media were pretty unhelpful when it happened, because they school weren't paying them enough.

 

I'm a big believer in UTM products - as applications are increasingly mixing different types of traffic, keeping your firewall and web filter separate seems a bit of a nonsense to me. So then you're talking about whether you want to put the web filtering on the ISP's end of the connection too (which is exactly what folks like @SchoolsBroadband do, of course).

 

I agree UTM's are the way to go and we have that on-site already, it was interesting when speaking to Virgin Media directly, they didn't quote for DDOS protection as according to the account manager its a £100k+ product, I kid you not.

Posted
I did get a comparison quote from yourselves, I am considering. Would there be a way of leveraging the cloud firewall protection on our mobile clients when using not using our local connection?

 

hi Rob,

 

I'm presuming you mean ipads at home etc on 3G / 4G? If so they yes. We're about to launch a 4G sim which we can terminate in exactly the same was as a leased line or FTTC / DSL based connection.

 

So that device will get exactly the same kind of security and filtering as if you were onsite.

 

There is also Forticlient (Fortinets Endpoint protection) too which pushes out the same security settings onto remote devices. I'd love to sell lots of this but most schools find it too expensive compared to say Sophos or ESET.

 

Ping me a PM if you've got some specific questions or give me a call. More than happy to talk things through.

 

Dave

Posted
they didn't quote for DDOS protection as according to the account manager its a £100k+ product, I kid you not.

 

Yep, that's what I found. We had a school being DDoSed, phoned up Virgin to ask if they could help and they basically said "a school wouldn't be able to afford our DDoS protection", and that was that.

Posted

Individual School getting DDoSed is a relatively rare event (it tends to be more common on aggregated services, like legacy LA networks) and there are some protections available with on-site UTM, Multiple IP addressing and backup links. In fact I suspect that internal rogue users are responsible for more attacks on single schools (which a good UTM on-premise UTM would help)

@Norphy we think that a firewall and web-filtering on Sophos XG is a very good compromise, where both features are excellent. I think when you add in additional security features (AV, antimalware, application control) as well as the link to their endpoint product, it's a pretty good 'package'. One management platform too, which helps..

Posted
I should make it clear that we use a UTM as well (Smoothwall). I’m just trying to say that the use case for a UTM isn’t always as clear cut as implied.
Posted
hi Rob,

 

I'm presuming you mean ipads at home etc on 3G / 4G? If so they yes. We're about to launch a 4G sim which we can terminate in exactly the same was as a leased line or FTTC / DSL based connection.

 

So that device will get exactly the same kind of security and filtering as if you were onsite.

 

There is also Forticlient (Fortinets Endpoint protection) too which pushes out the same security settings onto remote devices. I'd love to sell lots of this but most schools find it too expensive compared to say Sophos or ESET.

 

Ping me a PM if you've got some specific questions or give me a call. More than happy to talk things through.

 

Dave

 

Sent you a PM

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...