Jump to content

Recommended Posts

Posted

I'm looking for some thoughts on the advantages and disadvantages of running our own firewall. We currently have an RM broadband connection and as part of that contract they provide remote firewall and filtering services. We don't use these services as we have a local solution(Smoothwall). However in these cash strapped times I'm wondering why we are paying twice for the same service and whether we wouldn't be better pushing at least the firewalling up the line.

 

Advantages

Cheaper

Run by experts

More resilient (failover)

 

Disadvantages

Slower changes

Less flexible ?

Less ability to monitor

 

On the whole we don't do much with our firewall, nor can I recall a situation when not having a change made right there and then would have been a major issue. I am also not entirely confident in our understanding of the technology which is always a worry.

 

So on the whole I'm leaning towards getting rid of our local device, but there seems to be a broad view high schools ought to control their own firewall and filtering locally. Maybe ten years ago I would have agreed but remote services are now much more mature and flexible than they were.

 

So what do people think ?

Posted
I reckon the ability to manage your own firewall rules is worth 1-2 thousand a year just in the convenience. Presumably the turnaround time for RM to modify inbound/outbound rules is not that quick.
Posted
I reckon the ability to manage your own firewall rules is worth 1-2 thousand a year just in the convenience. Presumably the turnaround time for RM to modify inbound/outbound rules is not that quick.

Our firewall changes via RM is normally within 24 hours, so turn around isn't that bad

Posted
I guess it comes down to price and convenience as well as experience. If you are comfortable managing your own firewall, Smoothwall is a perfectly capable tool for it, however the value add and experience RM brings to the table needs to be considered as well.
Posted
If you are comfortable managing your own firewall, Smoothwall is a perfectly capable tool for it.

 

If its just a Firewall you want I wouldn't buy Smoothwall. I would look at something like PFsense. It has more features and is cheaper (comparing the support from Netgate). If you're after a filter that's another matter.

Posted
I guess it comes down to price and convenience as well as experience. If you are comfortable managing your own firewall, Smoothwall is a perfectly capable tool for it, however the value add and experience RM brings to the table needs to be considered as well.

 

I think that's very much it. I've no problems with Smoothwall as a product, it's been solid and flexible for us and support has been good. When we bought it, it was absolutely the right choice, but times change and products and needs evolve so I'm reassessing our position.

Posted
I like the smoothwall firewall as it's basically only a little extra money compared to the normal web filter so you may as well take advantage and use that as the firewall. No point having a separate box running pfSense if you already have a smoothwall - just added unnecessary complication.
Posted
Just to jump in here (Product Manager at RM). We are currently developing self service firewall as well so changes can be made by the school instantly.

 

Useful, but in a way I'd be a little wary of using this, one of the reasons for handing the firewall management to RM would be to have any changes scrutinised by their experienced staff. Would there be safeguards to guard against unwise changes ?

Posted
Useful, but in a way I'd be a little wary of using this, one of the reasons for handing the firewall management to RM would be to have any changes scrutinised by their experienced staff. Would there be safeguards to guard against unwise changes ?

 

Surely that is the point of a network manager to decide what rules he wants configuring for his internet connection? Firewall rules at the basic in/out level are very simple.

Posted
Surely that is the point of a network manager to decide what rules he wants configuring for his internet connection? Firewall rules at the basic in/out level are very simple.

 

That is true but the pitfalls of firewalls can be dangerous and non-obvious. You could misconfigure the set up, opening you to a lot of issues without seeing any immediate detrimental effect. No harm in having a second, more experienced set of eyes look things over.

 

It comes down to risk and consequences. I simply don't deal with firewalling (and many other things) on a regular enough basis to feel 100% happy taking on all the risk myself.

Posted
Do you have a DMZ configured on your Smoothwall for internet facing servers? If so, and you moved to using RM's firewall, could RM provide you with a DMZ and the ability to set rules between the DMZ and internal network(s)?
Posted

You could take a service that includes the firewall, filtering on-premise, gives you admin access to make your own changes, but also includes unlimited access to help-desk to make changes on your behalf or advise as required. The consolidation of Firewall, router and filtering and inclusive support will often save money and certainly save time. It also has the advantages of being a single SLA, and bill. Best of both worlds - ultimate flexibility, low cost, expert support.

 

But I'm biased : )

 

Seriously though, for a large, complex environment, I would always recommend an on-premise security platform. It will facilitate BYOD, multiple changing application scenarios, resilient WAN options (including 4G) amongst other benefits such as VPNs, VLAN routing, DHCP, Radius Authentication, 2FA, fully combined reporting (firewall.filtering) for better visibility, inline anti-virus etc. In addition, some say that best practice is to route internal traffic through your next gen firewall as this will help protect against infected/rogue devices inside the LAN.

 

As cyber threats increase in diversity and frequency, I think that the best way of keeping your users and information secure is to have on-premise security, combined with end-point protection, supported by a skilled partner.

 

My 2P

Posted

We have a similar setup to you, but we've just moved to RM Broadband so have a year left on our Smoothwall licence.

 

The advantages I've found, rightly or wrongly, are:

  • we still have the greater level of control over what we inspect and decrypt with Smoothwall than we do with Safetynet
  • we can have a smaller number of external IP's for our services, routing most through the reverse proxy (but could be achieved through other methods)
  • can seperate to an extent, so our Smoothwall is on a smaller "external" range on the RM network from our main network, however when we set this up the main range was also added to the RM router so should we ever remove Smoothwall we can just swap a few gateway settings around

 

I manage another school where I do just have the RM filtering and leave RM to manage the firewall, I've had no issues.

Posted

I don't think I could be happy not having something at my perimeter. I know the feed is coming straight from RM and they have the firewall on your feed, but at least if you have a device at the only Internet entry to your network then at least you know (barring config issues) that you are locked down. Which I know is irrational as the firewall is just at the other end of the single entry, but I guess it comes down to that handing over control.

Same reason I guess I have concerns about filtering in the cloud, as much as it gives greater flexibility and it is fine if you have total control over every device that connects and you can guarantee that, but one rogue device gets filter free access.

Posted

My view is that it doesn't matter where the firewall is so long as you have the same function set as you would an on premise box.

 

As many of your know we virtualise our Fortigate firewalls in the cloud so you get all the function of those firewalls with exactly the same interface as you would onsite.

 

The short list of benefits are

 

Same feature set

Resilient firewalls rather than single onsite

No capex costs

Lower on-going opex costs

No need to purchase annual software licensing or alter this, that's all taken care of by our team

The ability to create a WAN instantly and have a single pane of glass for ALL of your sites which means not having to update umpteen number of firewall and filter configurations

The ability to scale much better than having onsite boxes as your Internet connectivity increases (which it will do). We can just "turn on the taps" for more protected UTM instantly.

All software upgrades handled by another party

We have certified Fortinet engineers running the platform. You can make changes yourself or we can do it for you.

 

My view is that any onsite platform (firewall, file storage, server) etc is moving or has moved to the cloud and firewalling and filtering is just another extension of the same principle.

 

If you want to take a look at our hosted Fortigate security and Netsweeper education specific filtering then do drop me a line as we've now 1,500 schools using it :)

 

Thanks

 

Dave

Posted
Advantages

Cheaper

Run by experts

More resilient (failover)

 

Disadvantages

Slower changes

Less flexible ?

Less ability to monitor

Some things to think about:

  • You can get on-site firewalls that are "run by experts" (i.e. come with management contracts), and you can get self-managed cloud based systems, so I don't think your "run by experts" point is necessarilly related to whether you are using an on-prem or cloud based firewall. Obviously *anything* (cloud or on-prem) that comes with a management contract is going to cost more than something self-managed, so you have to make your choices on whether you want to spend more money to reduce your workload.
  • School ICT staff have to be generalists (managing a wide array of systems) and can't be expected to be specialists in network protocols and network security. So even if you go for a self-managed option, you still need to make sure you have adequate support from your firewall vendor. You should be able to work with them to set it up to do what you want in a secure way rather than being completely on your own.
  • Resiliency can be done with on-prem kit, but obviously this costs more than having a non-resilient system. At the same time, I wouldn't want to guarantee that all cloud based systems are resilient - check with the vendor where their single points of failure are rather than just assuming it is resilient!
  • There's no reason why a cloud based system needs to be slower than an on-prem system when it comes to making changes. Again, check with the vendor to see how changes are managed.
  • There's no reason why a cloud based system needs to have poorer logging than an on-prem system.
  • Do you need access controls between your internal networks (such as separating BYOD from the school's business network?) If so, an on-prem firewall is probably the way to go.
  • Do you need different firewalling for different users? This probably doesn't affect your choice between cloud and on-prem, but might affect your choice of product since some can set firewalling based on user group and some know nothing about individual users and just set up rules based on IP addresses.
  • What kind of integration do you want between your web filter and your firewall? Again, that might not affect your choice between on-prem / cloud, but might affect your choice of product.

Posted

These so-called benefits of it being "in the cloud" are a little bit woolly though. For example I am a little wary of the claim that it is both cheaper outright, and on an on-going basis, yet updates, resilliency, expert support etc are all being provided. These things clearly aren't being done for free and I imagine the discounts on licensing are not that great so I am not sure what magic is occurring in the cloud such that it is cheaper and yet all these things are also being taken care of too.

 

This is no different to things like RM CC3 and CC4 which supposedly save schools tens of thousands of pounds a year yet as we all know is not always the case.

 

I am skeptical.

Posted
These so-called benefits of it being "in the cloud" are a little bit woolly though. For example I am a little wary of the claim that it is both cheaper outright, and on an on-going basis, yet updates, resilliency, expert support etc are all being provided. These things clearly aren't being done for free and I imagine the discounts on licensing are not that great so I am not sure what magic is occurring in the cloud such that it is cheaper and yet all these things are also being taken care of too.

 

Yes, you should definitely run the numbers rather than just trusting that its cheaper.

 

Where it is cheaper, its usually just down to economies of scale - the cost of providing hardware to 10 primary schools, each with an on-prem web filter / firewall is always going to work out more than the cost of buying a single piece of more powerful hardware that can run all of them at the same time. Obviously on top of that there are hosting/bandwidth costs and the supplier is going to sell both the "on prem" and "cloud" solutions at their respective market rates - the supplier's margin is not going to be the same on both and you can't necessarily assume that something that costs the supplier less is going to end up costing the school less!

 

Also you have to consider the cost / risk balance associated with keeping hardware around for a long time. For example, when we sell cloud based systems the school pays an annual fee that includes the hardware/hosting that is being used and when we sell on-prem solutions the school pays for the hardware and we specify a 3 year warranty. But some schools choose to run the hardware for a _lot_ longer than 3 years, which is of course fine - the school has made a (hopefully informed) choice to save some money by accepting an increased risk of hardware failure.

 

That makes a simple comparison between cloud/on-prem costs quite difficult: taking the 3 year cost of an on-prem solution, dividing it by 3 and comparing it to the annual cost of a cloud solution is a nonsense if you might have stuck with the on-prem hardware for 6 years instead of replacing it as soon as the 3 year warranty ran out. On the other hand, the on-prem hardware *might* fail at 4 years, which makes assuming that it'll run for 6 a bit nonsensical too.

 

The only thing you can really say is that you know exactly how much the cloud system will cost you, and you know the _maximum_ the on-prem system will cost you, but that maybe you hope the on-prem system might cost you less than that maximum in the long run. Different schools are going to evaluate this calculation in a different way, which is why I think we're going to be having arguments about which is the "better" option for a long time to come. :)

Posted
Some things to think about:

  • You can get on-site firewalls that are "run by experts" (i.e. come with management contracts), and you can get self-managed cloud based systems, so I don't think your "run by experts" point is necessarilly related to whether you are using an on-prem or cloud based firewall. Obviously *anything* (cloud or on-prem) that comes with a management contract is going to cost more than something self-managed, so you have to make your choices on whether you want to spend more money to reduce your workload.
  • School ICT staff have to be generalists (managing a wide array of systems) and can't be expected to be specialists in network protocols and network security. So even if you go for a self-managed option, you still need to make sure you have adequate support from your firewall vendor. You should be able to work with them to set it up to do what you want in a secure way rather than being completely on your own.
  • Resiliency can be done with on-prem kit, but obviously this costs more than having a non-resilient system. At the same time, I wouldn't want to guarantee that all cloud based systems are resilient - check with the vendor where their single points of failure are rather than just assuming it is resilient!
  • There's no reason why a cloud based system needs to be slower than an on-prem system when it comes to making changes. Again, check with the vendor to see how changes are managed.
  • There's no reason why a cloud based system needs to have poorer logging than an on-prem system.
  • Do you need access controls between your internal networks (such as separating BYOD from the school's business network?) If so, an on-prem firewall is probably the way to go.
  • Do you need different firewalling for different users? This probably doesn't affect your choice between cloud and on-prem, but might affect your choice of product since some can set firewalling based on user group and some know nothing about individual users and just set up rules based on IP addresses.
  • What kind of integration do you want between your web filter and your firewall? Again, that might not affect your choice between on-prem / cloud, but might affect your choice of product.

Some fair points here. Having deployed and worked in aggregated networks, both LA and corporate networks for years, I can safely say that even when the architects, engineers, telcos and data centre tell you that there are no single points of failure, one almost always turns up. And the fact of not knowing it was there, makes it a much more exciting experience trying to fix it.

 

I find it's safer to trust what you can see/prove : )

  • Thanks 1
Posted
Some fair points here. Having deployed and worked in aggregated networks, both LA and corporate networks for years, I can safely say that even when the architects, engineers, telcos and data centre tell you that there are no single points of failure, one almost always turns up. And the fact of not knowing it was there, makes it a much more exciting experience trying to fix it.

 

I find it's safer to trust what you can see/prove : )

Yes, I think I can agree with that one :)

 

I've recently been involved in a "hot spare internet connection" configuration that involved convincing BT to install some fibres on quite extensive exciting new routes to avoid the primary and secondary links passing through the same geographic location. Took quite a while before everyone involved was sure that it was possible. :)

Posted

A quick note on the "changes are slower for cloud systems" point: I presume this was on the assumption that for a managed system you would have to jump through the support team rather than just making the changes yourself as you would on a self-managed system. As I mentioned, I don't think you need to consider the differences between cloud and on-prem for this point, but rather who manages it. Different vendors are going to offer different options on this, but certainly all the managed contracts that I deal with certainly don't stop the customer from directly making their own changes if they need to, its just that the "management" bit of the contract means that they can (but don't have to) ask for something in plain English and let someone else figure out the technical detail for them.

 

With that kind of set up it's up to the administrator to decide whether they are comfortable making the changes themselves, but they can always make an urgent change themselves to get something working immediately and then ask someone to check that they did it right. That said, most urgent things that I can think of tend to be web filtering, rather than firewalling.

Posted

Thanks everyone for your input. Lots of good stuff there.

 

From our point of view the decision appears fairly clear cut. We already get inclusive cloud filtering and firewalling as part of our broadband contract and we are also paying for the same onsite. So bottom line is we are effectively paying twice for the same service. The onsite firewall is due for replacement, do we replace it or just switch to the cloud ? If there's no compelling advantage to a local solution (and looking at this thread I don't think there is) then we may as well drop it and save the money. The fact we're saving money is a big weight when it comes to balancing the options.

 

Now I've just got to convince our change adverse IT Steering Group ;)

Posted
So bottom line is we are effectively paying twice for the same service. The onsite firewall is due for replacement, do we replace it or just switch to the cloud ? If there's no compelling advantage to a local solution (and looking at this thread I don't think there is) then we may as well drop it and save the money.

 

I think you need to compare the products and their features, rather than concentrating on whether they are cloud / on-premises.

 

If what your ISP offers does what you need then dropping the on-prem box to save money sounds sensible. But if the ISP's offering is missing some features that you think you need then you might want to stick with the on-prem solution.

 

You said you're paying twice at the moment - does your ISP not let you opt out of paying for their filtering/firewalling if you've opted to buy in a third party system?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...