MrWu Posted February 22, 2019 Posted February 22, 2019 Hi all Anyone here has experiences with Schools Broadband hosted Firewall? I'm used to having an on premise one and wondered how flexible a cloud based one is, my other option is to get a Fortigate 300E and make changes and look after it in house. Thanks a always 1
snagrat Posted February 22, 2019 Posted February 22, 2019 Yes we use it at a lot of schools. I find it very good, very flexible. Do you have specific questions? 2
IrritableTech Posted February 22, 2019 Posted February 22, 2019 Due to the virtualization of the fortinets it may as well be a dedicated in house box. There's not been anything I've wanted to do which I couldn't. 2
MrWu Posted February 22, 2019 Author Posted February 22, 2019 Yes we use it at a lot of schools. I find it very good, very flexible. Do you have specific questions? Thank you, its whether it's good with adfs and WAP... we have DMZ set for various things and was trying to picture how that can be set up with Cloud firewall So you are allowed login to tweak settings on it? Do you use Netsweeper on it as well vs Fortigate's own filtering service?
SchoolsBroadband Posted February 22, 2019 Posted February 22, 2019 Thank you, its whether it's good with adfs and WAP... we have DMZ set for various things and was trying to picture how that can be set up with Cloud firewall So you are allowed login to tweak settings on it? Do you use Netsweeper on it as well vs Fortigate's own filtering service? Evening @MrWu, with our cloud based virtualised Fortigate firewalls you have EXACTLY the same access and feature set as you would do with an onsite firewall. Some of the advantages of using it in the cloud is You have a resilient service (multiple physical devices rather than a single onsite) giving more resiliency for less cost The devices we use are very large and allow you to scale up the amount of bandwidth and processing power, so no need to put a firewall in the bin when you upgrade your Internet connectivity. We do all of the software updates for you and manage the underlying OS of the device but give you full flexibility to change anything on your virtual firewall. We have multiple Fortinet Certified engineers. When it comes to firewalls we really do know what we're doing. One things the Fortigates aren't too great at doing is education specific content filtering. In particular from a reporting perspective. To get the most from them from a reporting point of view you need the additional Fortianalyzer service (we also offer this as a hosted service if required). They are though in our opinion the best UTM and NGFW appliances available on the market. We use cloud based high availability load balanced Netsweeper content filtering services. They are also better at doing HTTPS decryption on scale than Fortigate boxes. You can use the web filtering functionality on the Fortigate box but we recommend using Netsweeper instead. We've quite a few clients who use the virtualised Fortigate firewall as a wireless controller in conjunction with FortiAP's. Please check with our pre-sales team on compatibility with FortiAPs if you have some existing ones you want to use. We're not on the very latest FortiOS version but we will be upgrading in the next few months. If you've any questions feel free to get in touch. Thanks Dave 1
MrWu Posted February 24, 2019 Author Posted February 24, 2019 Thank you all Another question, if the Firewall is cloud based, how would zones and DMZ presented to the Fortigate ? Would the router have mutilple ports so there some flexibility in separating WAN or wireless zones? Thanks !
SchoolsBroadband Posted February 24, 2019 Posted February 24, 2019 Yes that's exactly how it can be done. Ports on the router can be assigned do different Fortigate virtual interfaces. In your case one or many for dmz and one or many for lan. Best do a small diagram as to how youd like it to work and send to our technical build team who will make it happen. Thanks Dave
MrWu Posted February 24, 2019 Author Posted February 24, 2019 (edited) Yes that's exactly how it can be done. Ports on the router can be assigned do different Fortigate virtual interfaces. In your case one or many for dmz and one or many for lan. Best do a small diagram as to how youd like it to work and send to our technical build team who will make it happen. Thanks Dave Thanks Dave, that’s good to know .. will get a diagram over That’s a good sign since first step is to get a temporary filtering on the BYOD side to your proxy .. we had a weird setup whereby wireless was assigned to one of the physical ports on our current Sonicwall.(this will be rectified when we redo our core switch etc) Our Filter with Sonicwall has expired and I need a temporary solution on BYOD side (lan side is ok with GPO assigning proxy) So was thinking for a few months before we fully transition to Netsweeper transparent proxy is to do this as a workaround BYOD -> Schools broadband router -> Backup FTTC line by Schools broadband -> virtual port on fortigate to Netsweeper Edited February 24, 2019 by MrWu
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now