Jump to content

Recommended Posts

Posted

Hi,

 

Just out of interest, how are other sophos users using reports.

 

I have some scheduled reports setup for the usual but as I was getting no results I reported it as a fault but its by design.

 

The report only reports items that are allowed through. So by their logic we have to allow all terrorist sites through to get any data relating to prevent.

 

There is a report which shows all blocked attempts but it dumps everything into a massive report.

 

I may be mistaken but it seems they are light years behind smoothwall.

Posted
Hi,

 

Just out of interest, how are other sophos users using reports.

 

I have some scheduled reports setup for the usual but as I was getting no results I reported it as a fault but its by design.

 

The report only reports items that are allowed through. So by their logic we have to allow all terrorist sites through to get any data relating to prevent.

 

There is a report which shows all blocked attempts but it dumps everything into a massive report.

 

I may be mistaken but it seems they are light years behind smoothwall.

 

Which Sophos product are you using?

Posted
The product is lightyears ahead of smoothwall in just about every way except reporting IMO, but there's changes to come. Could be worth speaking to Sophos directly to see if they can offer any specifics on timing or improvements, their support has typically been very good.
  • Thanks 1
Posted
The product is lightyears ahead of smoothwall in just about every way except reporting IMO

 

And PREVENT compliance? Surely if you can't see who is trying to access the naughties you can't be compliant? Or is this purely an issue with trying to generate a report to export? You can see the PREVENT transgressions on screen?

Posted
Just wondering if anyone can expand on Sophos Filtering and PREVENT/Reporting? I'm going to be starting a tender for a new firewall soon and Sophos was high on the list, but if in reality it can't show us even what Smoothwall can show us now there doesn't seem much point.
Posted

@TechMonkey

 

Netsweeper (filter only), Fortinet (filter and UTM / firewall) and Lightspeed (filter only) are all very good at reporting (although Fortinet also needs FortiAnalzyer or Forticloud to enhance it to be Prevent compliant).

 

We've now over 1,000 schools using our Fortinet firewall and Netsweeper filter solution so they have the best of both worlds. No capex costs as it's all in the cloud. We also put proactive Prevent compliant reports on as standard which includes full SSL decrypt. If its of interest do send me a PM, we'd be happy to give you a tender response.

 

Good luck.

 

Dave

Posted
Just wondering if anyone can expand on Sophos Filtering and PREVENT/Reporting? I'm going to be starting a tender for a new firewall soon and Sophos was high on the list, but if in reality it can't show us even what Smoothwall can show us now there doesn't seem much point.

 

Hi Techmonkey,

 

Happy to arrange a demo for you anytime. The reporting is very comprehensive and compliant, but is not the most user-friendly as I would say it gives more insight than most systems, but is almost too much info, so there is a process of setting up custom reports to do to fine tune for your specific needs. Users are identified in the 'blocked attempts' log. In addition the Threat Quotient report is very useful as this highlights users who have the most 'risky' behaviour, which isn't just down to inappropriate web-requests, but also other activity such as application, VPN, etc. In addition for those that want a less detailed, more visually helpful dashboard, we offer Fastvue alongside the service too.

 

cheers

Posted

@SchoolsBroadband

 

Many thanks I'll take a look and consider. I'm still not quite sold on a cloud filter though, something doesn't sit right with me not having a beefy bit of iron at our perimeter.

 

Hi Techmonkey,

 

Happy to arrange a demo for you anytime. The reporting is very comprehensive and compliant, but is not the most user-friendly as I would say it gives more insight than most systems, but is almost too much info, so there is a process of setting up custom reports to do to fine tune for your specific needs. Users are identified in the 'blocked attempts' log. In addition the Threat Quotient report is very useful as this highlights users who have the most 'risky' behaviour, which isn't just down to inappropriate web-requests, but also other activity such as application, VPN, etc. In addition for those that want a less detailed, more visually helpful dashboard, we offer Fastvue alongside the service too.

 

cheers

 

Thank you for the response. I'm confused though, Simcfc73 says that the Sophos box only reports on items that have gone through the filter. So how will I give my DSL a report showing what pupils have tried to access or at risk pupils if it only shows what they have been able to see? If the system is set up correctly you will never be able to report as everything dodgy will be blocked and you can't report on it.

 

Or have I got the wrong end of the stick?

Posted

@TechMonkey

 

no problem.

 

Just so you know though we actually extend the perimeter of your network effectively into our cloud based and virutalised Fortigates. Very useful if you want to bring any other sites in as part of a WAN as then you only need one cloud based firewall and we then link them together over our network. There's no extra cost for this.

 

We've about 1,500 schools using it at the moment so its quite well tested :)

 

Thanks

 

Dave

Posted
@SchoolsBroadband

 

Many thanks I'll take a look and consider. I'm still not quite sold on a cloud filter though, something doesn't sit right with me not having a beefy bit of iron at our perimeter.

 

 

 

Thank you for the response. I'm confused though, Simcfc73 says that the Sophos box only reports on items that have gone through the filter. So how will I give my DSL a report showing what pupils have tried to access or at risk pupils if it only shows what they have been able to see? If the system is set up correctly you will never be able to report as everything dodgy will be blocked and you can't report on it.

 

Or have I got the wrong end of the stick?

Hi Techmonkey, there is a blocked request report. A report on failed/blocked attempts. As I said, the information is all there, it just needs some investment in time to create customer reports to be presented better. Sophos are working on these and other improvements all the time.

 

cheers

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...