Jump to content

Recommended Posts

Posted

Hi All,

 

Hope this is the right place to put this. We are currently looking at our options, our Broadband subscription is coming to an end, and the LA provided service is a bit clunky and expensive.

 

Has anyone here moved away from the LA service and are using: WatchGuard or Sophus, etc?

 

Just looking for some advice about possible pitfalls, advice on possible replacement filtering and firewalls, etc.

 

Any help much appreciated!

Posted

Well my approach was to keep the LA broadband for a transition period and evaluate the new services while keeping the LA as a fallback. You can then see get a real feel for how the two compare.

 

A bit more expensive but with proper planning the additional cost shouldn't be too significant.

 

Much depends on whether you are going to go for a managed package including data connection and filtering or buy in raw bandwidth and deploy an appliance of your choice separately. I prefer the latter as its generally cheaper and you will get more flexibility in contract terms. Many managed packages now seem to want a 3 year commitment up front which I think is excessive.

  • Thanks 1
Posted

@meadowgirl are you a primary or secondary school?

 

We're a secondary with 6th form and we left the LA about 18 months ago, it's been a big success. We have a connection that is literally 10 times faster for the same price.

 

We sourced our Internet connection (gigabit fibre) and our UTM separately (Smoothwall for the UTM) and the difference is huge - the old LA broadband was so unreliable.

 

We also sourced an additional business FTTC 80Mb backup line because we're heavily reliant on Internet access not just for work but for SIP too - it's barely been used but for the minor additional cost it's worth it.

  • Thanks 1
Posted

@Primus We are a large Special School (4-16, 250+ Students 150+ Staff).

 

We have heard good things about Watchguard, which is why we asked about them. We will check out Smoothwall too - thanks for the info!

Posted

We use a Sophos XG box. Price is extremely competitive and can integrate with endpoint and cloud security services (such as Office 365 email/ Azure protection). We've used a number of other products in the past including SonicWALL and the Sophos is cheaper, offers better reporting built in and offers more features.

 

The cost of hardware and license costs (for the Sophos XG) over 3 years is still cheaper than we were quoted just for the tin for a new SonicWall.

 

In terms of our broadband, we pay for Virgin education lines and a cheap BT backup line (in the event that the Virgin goes down). The new BT service even offers extra fail over via 4G (so you'd have 3 layers of failover!).

  • Thanks 1
Posted
We did this and have saved a fortune over the last 6 years. Currently have 100meg direct with Virgin Fiber, now renewing with 300MB Virgin Line with adsl backup through a reseller cheaper than virgin giving us 3 months of cross over just in case. We replaced our old Cisco ASA's with a Fortinet 500D and fortinet analyser (which keeps logs and runs reports) It has a piece of software that runs on each DC and logs log on events so your guaranteed that the correct filtering is being applied to student or teacher no mater which device they are logging on to or it falls back to a basic web filtering if say a teacher hasn't logged off their pc in months. So nice getting a quote to change over to their wifi solution to integrate al these for easy BYOD
  • Thanks 1
Posted

You just need to be clear about what additional services your LA might provide - particularly if you are locked into some kind of SIMs deal with a VPN back to the LA. And/or they might be providing safeguarding or other services.

 

We use an Asymmetric (and therefore cheap) 300Mb/s (15MB/s upload) Virgin cable connection (£80 a month) and an FTTC 80Mb/s (20Mb/s upload) £50 a month into a smoothwall which acts a load balancer (as well as doing usual filtering and safeguarding....and firewall...and radius/BYOD). Smoothwall is not without its problems - "reporting" is surprisingly poor despite looking good on the surface. Safeguarding is better...although the whole thing is clunky and not as well integrated as it might be. But for us, is seemed the least worse of the offerings out there. Sophos might have been better - we would have quite liked its SSO capability for reverse proxy, but smoothwall had realtime content analysis which we thought might be good....not sure it has ever been that useful though. Looking at FTTP (330Mb/s) despite its high upfront cost to replace FTTC as it would be cheaper over 5 years and give more bandwidth. For us - our bandwidth pattern doesn't require the symmetric capability of a leased line - despite using Google drive and Office 365.

  • Thanks 1
Posted
You just need to be clear about what additional services your LA might provide - particularly if you are locked into some kind of SIMs deal with a VPN back to the LA. And/or they might be providing safeguarding or other services.

 

We use an Asymmetric (and therefore cheap) 300Mb/s (15MB/s upload) Virgin cable connection (£80 a month) and an FTTC 80Mb/s (20Mb/s upload) £50 a month into a smoothwall which acts a load balancer (as well as doing usual filtering and safeguarding....and firewall...and radius/BYOD). Smoothwall is not without its problems - "reporting" is surprisingly poor despite looking good on the surface. Safeguarding is better...although the whole thing is clunky and not as well integrated as it might be. But for us, is seemed the least worse of the offerings out there. Sophos might have been better - we would have quite liked its SSO capability for reverse proxy, but smoothwall had realtime content analysis which we thought might be good....not sure it has ever been that useful though. Looking at FTTP (330Mb/s) despite its high upfront cost to replace FTTC as it would be cheaper over 5 years and give more bandwidth. For us - our bandwidth pattern doesn't require the symmetric capability of a leased line - despite using Google drive and Office 365.

 

Alan I know you've made this point before and you're right you would need to be clear about your requirements but as a school we couldn't manage with such low upload speed. Even when I take out our offsite backup that runs our upload requirement is far higher than what you've got there and we've got 160 staff and 1250 kids.

 

Our backup FTTC connection has a 20Mb upload speed and we *really* feel it if we do ever failover as this has a huge impact as once it gets maxed out you get the usual huge performance degradation - particularly evident on SIP phone calls but also even with just general web browsing.

  • Thanks 1
Posted
We use a Sophos UTM here, which we've found to be really good over the last few years Sophos are currently pushing their XG firewall but the feature set is still not completely up to where the UTM is which is why we've held off migrating until now, although the gap is narrowing. Having said that, it does offer some features that UTM does not, such as security heartbeat which integrates with the endpoint product. Just compare the two if you do look at Sophos. We've found that as an integrated product, it helps protect our published services, web filtering, on-premise email etc, all under one pane of glass.
  • Thanks 1
Posted
If you will be running an on-site filtering system rather than going for an all-in-one internet connection, my advice is to get the new filtering system set up on your old connection before switching the connection itself over. Nothing worse than changing too much all at once, in my experience!
  • Thanks 1
Posted
Many managed packages now seem to want a 3 year commitment up front which I think is excessive.

 

We've always left the contract duration up to the school, and certainly different schools want to do things in different ways so I think flexibility is important. Multi-year contracts often come with some advantages such as spreading the cost of any hardware rather than paying for it all up-front. But at the same time, it's a big commitment, so some schools prefer to stump up for hardware up-front in exchange for a shorter commitment. One size definitely doesn't fit all. :)

  • Thanks 1
Posted
If you will be running an on-site filtering system rather than going for an all-in-one internet connection, my advice is to get the new filtering system set up on your old connection before switching the connection itself over. Nothing worse than changing too much all at once, in my experience!

Hi Steve,

 

would have to argue with you here - guess it depends on the service provider. In my view, it's better to move broadband and UTM at the same time, and with the same provider. Install charges (if any) should reduced as it;s one visit/project. There can be efficiencies in terms of engineering and configuration. Importantly, the SLA will encompass both elements, so that you have one number for support of both elements (which are often co-dependent, and separate suppliers can often play the 'it's not us - must be them' card)

 

Lastly, when moving from an LA, it's often impossible to do it piecemeal, legacy apps as well as inflexible WAN and routing design can preclude 3rd party firewall/UTM on an LA layer 2 aggregated WAN.

 

My twopenneth!

  • Thanks 1
Posted

We cut and ran from the LEA about 9 years ago - brought SIMS in house and bought our own fibre internet and Smoothwall UTM. Apart from updates etc we're still running the same kind of setup and its worked well.

 

As already mentioned there are sometimes things the LEA provide that you might need to consider, financial systems, BMS/heating controls, alarms, phones etc when switching to another supplier

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...