Joko Posted December 4, 2020 Posted December 4, 2020 Morning, Our renewal is due with Smoothwall next year and i have been asked to propose some alternatives from higher up, and i wouldn't mind looking myself as we have had some issues with support delays. Smoothwall was put in before my employment and it seems that it's used for pretty much everything but the safeguarding alerting side as we use Impero for that. Has anyone moved away from Smoothwall recently or are planning to move away? We would need full Firewall/Filtering solution to replace like for like. I have done some searches on here and seen some threads about Securly, Sophos XG. However, i believe Securly is just web filtering? Also, i know Cisco Umbrella is being used by the DfE. Any recommendations? Thanks.
TechMonkey Posted December 4, 2020 Posted December 4, 2020 I've not moved from Smoothwall so can't make any recommendations, but the popular choices seem to be Sophos XG, Securly, Fortinet, Opendium and a smattering of Barracuda. We looked at all but Securly. My rough reviews from demos, probing and speaking to others are: Sophos XG Pretty. Just as bad at reporting, if not worse, than Smoothwall such that everyone buys a third party reporting engine to bolt on. Still a maturing product so some features seem flaky or under development. Filter is not content aware. Just had a big Injection bug found that had been exploited. Fortinet A firewall with some filtering options. Does what it needs to, more of a help than an actual product for filtering. Filter is not content aware. Not very extensive filters provided Opendium Ugly as sin but a very impressive product. Some really fancy features but just packaged up as if it were still the 90s. Content aware filter Barracuda Expensive. Nice package, very easy to use. Expensive! Filter is not content aware. What it comes down to ultimately is what you are after. The big thing seems to be a lot of these devices are Firewalls that have some filtering and also how geared towards Education they are. This directly leads to how much work you are going to have do. My big concern was the lack of content scanning, URL scanning is a very reactive method especially as people don't label the naughty sites as clearly as they used to I fear I may have to lose this ability eventually with HTTPS tightening further and further. Eventually what I may do is get a second box for Firewall capabilities and stick with Smoothwall for filtering, as that is what they do exceptionally well. 1
Simcfc73 Posted December 4, 2020 Posted December 4, 2020 I echo the reporting bit on XG, its a nice product... much easier to use than Smoothwall IMHO and the price was cheaper than the SW renewal even with a new appliance. 1
synaesthesia Posted December 4, 2020 Posted December 4, 2020 We do very much like XG - it's a lot more mature feeling now than when we first had it - reliable, easy to use (miles ahead of Smoothwall there) - reporting isn't fantastic but the price difference is easily enough to purchase Fastvue on top and still save pennies. As you rightly point out, it's the lack of content awareness although that has it's own pros and cons. I can't say much about Sophos' support however as we've always gotten it from our ISP @Wave9_Lee who have been absolutely second to none. 1
Wave9_Lee Posted December 4, 2020 Posted December 4, 2020 Morning, Our renewal is due with Smoothwall next year and i have been asked to propose some alternatives from higher up, and i wouldn't mind looking myself as we have had some issues with support delays. Smoothwall was put in before my employment and it seems that it's used for pretty much everything but the safeguarding alerting side as we use Impero for that. Has anyone moved away from Smoothwall recently or are planning to move away? We would need full Firewall/Filtering solution to replace like for like. I have done some searches on here and seen some threads about Securly, Sophos XG. However, i believe Securly is just web filtering? Also, i know Cisco Umbrella is being used by the DfE. Any recommendations? Thanks. Hi @Joko Here's my obligatory post offering info/demo and pricing for Sophos XG and Fastvue if you'd like. PM me or contact me direct anytime for a chat or pricing, cheers
TRS-80 Posted December 4, 2020 Posted December 4, 2020 We've used Cyberhound for years, it's decent. It's due for renewal and we're evaluating Linewize at the moment, it's comparable with some extra features but a fair bit more expensive too. We have Fortinet firewalls and considered getting the web filtering license for them, but we'd rather have an education focused product for filtering.
Joko Posted December 4, 2020 Author Posted December 4, 2020 Hi @Joko Here's my obligatory post offering info/demo and pricing for Sophos XG and Fastvue if you'd like. PM me or contact me direct anytime for a chat or pricing, cheers Emailed 1
Joko Posted December 4, 2020 Author Posted December 4, 2020 I've not moved from Smoothwall so can't make any recommendations, but the popular choices seem to be Sophos XG, Securly, Fortinet, Opendium and a smattering of Barracuda. We looked at all but Securly. My rough reviews from demos, probing and speaking to others are: Sophos XG Pretty. Just as bad at reporting, if not worse, than Smoothwall such that everyone buys a third party reporting engine to bolt on. Still a maturing product so some features seem flaky or under development. Filter is not content aware. Just had a big Injection bug found that had been exploited. Fortinet A firewall with some filtering options. Does what it needs to, more of a help than an actual product for filtering. Filter is not content aware. Not very extensive filters provided Opendium Ugly as sin but a very impressive product. Some really fancy features but just packaged up as if it were still the 90s. Content aware filter Barracuda Expensive. Nice package, very easy to use. Expensive! Filter is not content aware. What it comes down to ultimately is what you are after. The big thing seems to be a lot of these devices are Firewalls that have some filtering and also how geared towards Education they are. This directly leads to how much work you are going to have do. My big concern was the lack of content scanning, URL scanning is a very reactive method especially as people don't label the naughty sites as clearly as they used to I fear I may have to lose this ability eventually with HTTPS tightening further and further. Eventually what I may do is get a second box for Firewall capabilities and stick with Smoothwall for filtering, as that is what they do exceptionally well. Thanks for taking your time doing this. I haven't thought about splitting the costs and having seperate filtering & Firewall. Has anyone else done this? I wonder how cost effective that would be. Thanks again!
TRS-80 Posted December 4, 2020 Posted December 4, 2020 Thanks for taking your time doing this. I haven't thought about splitting the costs and having seperate filtering & Firewall. Has anyone else done this? I wonder how cost effective that would be. We do, and it's not necessarily cheaper but could be depending on what your firewall needs are. You do lose some things like seamless Layer 7 firewalling, but the gain in having an education focused filter and a proper firewall is worth it IMHO.
CHiLL Posted December 4, 2020 Posted December 4, 2020 (edited) We've been very disillusioned from Smoothwall over the past few years of using it. It's difficult to use and the support has been absolutely terrible. We have booked a demo with Wave9 for Sophos XG, so we'll see what that's like. Sophos XG Filter is not content aware. What do you mean by not content aware? I'm seeing in the Smoothwall marketing about being content aware, but not what it actually is. Edit: Is it just that it checks the content of the page, such as the source code and includes that to decide whether the allow or block the page? If so, does that mean Sophos is just URL based filtering...and from that, does Sophos require the deployment of a SSL certificate to clients for HTTPS decryption like Smoothwall does? Edited December 4, 2020 by CHiLL
TechMonkey Posted December 4, 2020 Posted December 4, 2020 (edited) What do you mean by not content aware? I'm seeing in the Smoothwall marketing about being content aware, but not what it actually is. Edit: Is it just that it checks the content of the page, such as the source code and includes that to decide whether the allow or block the page? If so, does that mean Sophos is just URL based filtering...and from that, does Sophos require the deployment of a SSL certificate to clients for HTTPS decryption like Smoothwall does? Correct. A page could have a url or http://www.safeandhappypage.com/goodcontent and be full of nasties. Sophos would see http://www.safeandhappypage.com/nastystuff as the SSL cert will allow it to see the sub pages. Smoothwall will look at the content and block on nasties within the page. This also helps if a page is taken over, hijacked or later changes use. URL filtering is reactive, as you either need to guess intent by words in the URL (the classic Scunthorpe or Sussex issue) or by someone going through can classifying it. I prefer content aware as I personally feel it gives better coverage and is a massive benefit in this dynamic content age, though it can be a bit over sensitive for example if an EduGeek thread talks about something considered naughty. EDIT: You do have to be careful as some suppliers say they are content filters when actually what they mean is that they filter web content, not they filter the actual content. Barracuda were particularly slippery on this, saying they were a content filter until I laid out the exact case of picking out terms in a page. Edited December 4, 2020 by TechMonkey
Wave9_Lee Posted December 7, 2020 Posted December 7, 2020 Correct. A page could have a url or www.safeandhappypage.com/goodcontent and be full of nasties. Sophos would see www.safeandhappypage.com/nastystuff as the SSL cert will allow it to see the sub pages. Smoothwall will look at the content and block on nasties within the page. This also helps if a page is taken over, hijacked or later changes use. URL filtering is reactive, as you either need to guess intent by words in the URL (the classic Scunthorpe or Sussex issue) or by someone going through can classifying it. I prefer content aware as I personally feel it gives better coverage and is a massive benefit in this dynamic content age, though it can be a bit over sensitive for example if an EduGeek thread talks about something considered naughty. EDIT: You do have to be careful as some suppliers say they are content filters when actually what they mean is that they filter web content, not they filter the actual content. Barracuda were particularly slippery on this, saying they were a content filter until I laid out the exact case of picking out terms in a page. As a counterpoint to this, many of our customers have said that content-aware filtering can report too many false-positives and creates wasted time in dealing with them. If systems that use category based web-filtering are using a proper categorisation service and updated regularly and quickly, that's enough for many. On the other point about combined filter/firewall, the benefits of this include lower cost, easier management and better visibility. Just my 2p.
danielghares Posted December 7, 2020 Posted December 7, 2020 (edited) We (and by extension, the trust) all use Securly for our filtering, and aside from a few small issues it's been great. From a managed windows client, you can either use a SmartPAC proxy or DNS based filtering. For chromebooks, they have a chomeOS extension. It's also working nicely with our BYOD network too (using the DNS filtering method). The reporting aspects of it are really good, and it can audit all content in Google Apps so you will get alerts if anything bad is going through them. Some other schools in the trust who are running 1:1 devices utilize the 'take home' aspect of it, so that filtering can be flexible off site and parents can control what their specific students are viewing, and allow certain content, etc.. We did have an issue recently where students figured out they could get on to facebook, twitter, reddit, etc.. via the 'share' function in YouTube. Don't know how this got through the filtering as all social medias are blocked, but we've got a ticket open with them now. For firewalls, I installed pfsense on some old proliants we had and configured them in a HA cluster. It's been rock solid since day one, and even with the older hardware we're still able to nearly max out our gig leased line Edited December 7, 2020 by danielghares
PlantHead Posted December 7, 2020 Posted December 7, 2020 We dumped Smoothwall for Fortinet 2 years ago and haven't looked back. The price is comparable but the fortigate is leaps and bounds easier to use. The reporting takes some getting used too but other than that it all works very well.
TechMonkey Posted December 7, 2020 Posted December 7, 2020 As a counterpoint to this, many of our customers have said that content-aware filtering can report too many false-positives and creates wasted time in dealing with them. If systems that use category based web-filtering are using a proper categorisation service and updated regularly and quickly, that's enough for many. One anecdote against another, when people suggest sites that need blocking I have generally found Smoothwall has it blocked already, either due to the content filtering or their filter lists. I guess it depends on the priority. In a school which is worse, a false positive that you need to open up or a false negative you then need to explain to parents why little Jane saw that explicit content?
TRS-80 Posted December 7, 2020 Posted December 7, 2020 We run a pretty tight filter, but let teachers unblock sites themselves by adding them to our LMS, which has an integration with our filter. Best of both worlds.
DGardiner Posted December 7, 2020 Posted December 7, 2020 One anecdote against another, when people suggest sites that need blocking I have generally found Smoothwall has it blocked already, either due to the content filtering or their filter lists. I guess it depends on the priority. In a school which is worse, a false positive that you need to open up or a false negative you then need to explain to parents why little Jane saw that explicit content? and id rather a false positive than a missed emergency, instant alerts on the smoothwall and a nightly "sh*t list" to read through take a couple of minutes to scan over. Sophos did look nice last time we looked at it but the lack of edu focused reporting/alerts won it for smoothwall. many dns based filtering is childsplay to work around, ill pass.
TechMonkey Posted December 8, 2020 Posted December 8, 2020 and id rather a false positive than a missed emergency, instant alerts on the smoothwall and a nightly "sh*t list" to read through take a couple of minutes to scan over. Sophos did look nice last time we looked at it but the lack of edu focused reporting/alerts won it for smoothwall. many dns based filtering is childsplay to work around, ill pass. Exactly. The nightly emails were highlighted in our last inspection as a very good thing the inspectors hadn't seen. I doubt we are the only schools using it but it is obviously not widespread enough for it not to be exceptional. Fortinet Reporting, which could be scheduled, looked very interesting. You could build reports using widgets. But in the end we don't do that much reporting, Safeguarding is the big one and to have it readily there without having to build and kept current, it is a massive plus.
DGardiner Posted December 8, 2020 Posted December 8, 2020 Exactly. The nightly emails were highlighted in our last inspection as a very good thing the inspectors hadn't seen. I doubt we are the only schools using it but it is obviously not widespread enough for it not to be exceptional. Fortinet Reporting, which could be scheduled, looked very interesting. You could build reports using widgets. But in the end we don't do that much reporting, Safeguarding is the big one and to have it readily there without having to build and kept current, it is a massive plus. we have fortinet in some of our schools, not through my choice like - sent the provider a copy of our smoothwall reports to replicate as its an amazing product hurhurhurh and can do better! then that email chain quickly dried up
rabsmith Posted December 18, 2020 Posted December 18, 2020 100% regret our decision to move to Smoothwall a year ago. Took them the best part of 9 months to fix an ongoing issue. Only really sped up when the CEO became involved. Counting down the days of the contract and will be looking at Sophos & Sonicwall more than likely.
TechMonkey Posted December 18, 2020 Posted December 18, 2020 Sonicwall is an interesting choice if you think Smoothwall is not good.
Cazale Posted December 18, 2020 Posted December 18, 2020 I've found Smoothwall to be fine until recently. Our support tickets are now taking over a month (!!!) to get answered. It's an absolute joke. We are also now thinking of moving elsewhere.
Simcfc73 Posted December 19, 2020 Posted December 19, 2020 Sophia reporting is average, the add-on (fastvue ) you can get makes it as good as smoothwall imho.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now