Jump to content

Recommended Posts

Posted

Hi all

 

Anyone here has experiences with Schools Broadband hosted Firewall? I'm used to having an on premise one and wondered how flexible a cloud based one is, my other option is to get a Fortigate 300E and make changes and look after it in house.

 

Thanks a always

  • Thanks 1
Posted
Yes we use it at a lot of schools.

 

I find it very good, very flexible.

 

Do you have specific questions?

 

Thank you, its whether it's good with adfs and WAP... we have DMZ set for various things and was trying to picture how that can be set up with Cloud firewall

 

So you are allowed login to tweak settings on it? Do you use Netsweeper on it as well vs Fortigate's own filtering service?

Posted
Thank you, its whether it's good with adfs and WAP... we have DMZ set for various things and was trying to picture how that can be set up with Cloud firewall

 

So you are allowed login to tweak settings on it? Do you use Netsweeper on it as well vs Fortigate's own filtering service?

 

Evening @MrWu,

 

with our cloud based virtualised Fortigate firewalls you have EXACTLY the same access and feature set as you would do with an onsite firewall. Some of the advantages of using it in the cloud is

 

You have a resilient service (multiple physical devices rather than a single onsite) giving more resiliency for less cost

The devices we use are very large and allow you to scale up the amount of bandwidth and processing power, so no need to put a firewall in the bin when you upgrade your Internet connectivity.

We do all of the software updates for you and manage the underlying OS of the device but give you full flexibility to change anything on your virtual firewall.

We have multiple Fortinet Certified engineers. When it comes to firewalls we really do know what we're doing.

 

One things the Fortigates aren't too great at doing is education specific content filtering. In particular from a reporting perspective. To get the most from them from a reporting point of view you need the additional Fortianalyzer service (we also offer this as a hosted service if required). They are though in our opinion the best UTM and NGFW appliances available on the market. We use cloud based high availability load balanced Netsweeper content filtering services. They are also better at doing HTTPS decryption on scale than Fortigate boxes.

 

You can use the web filtering functionality on the Fortigate box but we recommend using Netsweeper instead.

 

We've quite a few clients who use the virtualised Fortigate firewall as a wireless controller in conjunction with FortiAP's. Please check with our pre-sales team on compatibility with FortiAPs if you have some existing ones you want to use. We're not on the very latest FortiOS version but we will be upgrading in the next few months.

 

If you've any questions feel free to get in touch.

 

Thanks

 

Dave

  • Thanks 1
Posted

Thank you all

 

Another question, if the Firewall is cloud based, how would zones and DMZ presented to the Fortigate ? Would the router have mutilple ports so there some flexibility in separating WAN or wireless zones? Thanks !

Posted

Yes that's exactly how it can be done.

 

Ports on the router can be assigned do different Fortigate virtual interfaces. In your case one or many for dmz and one or many for lan.

 

Best do a small diagram as to how youd like it to work and send to our technical build team who will make it happen.

 

Thanks

 

Dave

Posted (edited)
Yes that's exactly how it can be done.

 

Ports on the router can be assigned do different Fortigate virtual interfaces. In your case one or many for dmz and one or many for lan.

 

Best do a small diagram as to how youd like it to work and send to our technical build team who will make it happen.

 

Thanks

 

Dave

 

Thanks Dave, that’s good to know .. will get a diagram over

 

That’s a good sign since first step is to get a temporary filtering on the BYOD side to your proxy .. we had a weird setup whereby wireless was assigned to one of the physical ports on our current Sonicwall.(this will be rectified when we redo our core switch etc)

 

Our Filter with Sonicwall has expired and I need a temporary solution on BYOD side (lan side is ok with GPO assigning proxy)

 

So was thinking for a few months before we fully transition to Netsweeper transparent proxy is to do this as a workaround

 

BYOD -> Schools broadband router -> Backup FTTC line by Schools broadband -> virtual port on fortigate to Netsweeper

Edited by MrWu

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...