Jump to content

Recommended Posts

Posted

In my search for a new broadband supplier I've discovered that quite a few different filtering products are offered as part of the packages.

 

What's everyone's opinion on them, and would they be a step up or down from Lightspeed Rocket?

 

Wave9 use Sophos XG

Exa use SurfProtect

Aspire use Smoothwall

SchoolsBroadband use Netsweeper

A couple of local companies use Fortigate

Posted

I've used all of them... it truly depends on your needs as no filtering system is perfect and one size does not fit all.

 

For me, Netsweeper does what we need at the scale we need, but I like the usability of Smoothwall, but I really rate the support of Sophos XG and the features.

 

Usage wise, my personal opinion for my 'generic school needs' and usability within my comfort levels are...

 

Sophos is better than Lightspeed

Lightspeed is better than SurfProtect

Smoothwall is better than Lightspeed

Netsweeper is better than Lightspeed

Lightspeed is better than Fortigate

 

Obviously its a personal thing and if I was running the full thing, as above I'd be fighting between Sophos, Netsweeper and Smoothwall, depending on what the needs of the school are, SLT are picky and might want x y z reports, techies might want to be super specific within what goes through SSL, what they pick up and where they get stuff from/how they integrate into their core/ADs etc.

  • Thanks 2
Posted
Whereas for me Netsweeper is old, outdated and frustratingly unusable. It really comes down to personal opinion. I would be looking at cloud solutions like Lightspeed Filter and Securly now, long before I put an appliance in my building.
  • Thanks 2
Posted

I'm a fan of Fortigate and Smoothwall. Smoothwall's support has been lacking however it's a product we're confident using.

 

The cloud based solutions tend to cause us the most problems, Netsweeper definitely being one of these. It saves so much time when we can just login to the Smoothwall and make the changes and click save, rather than sending off CRFs and waiting for responses.

Posted
The cloud based solutions tend to cause us the most problems, Netsweeper definitely being one of these. It saves so much time when we can just login to the Smoothwall and make the changes and click save, rather than sending off CRFs and waiting for responses.

That's not a cloud based solution though, really. That's someone managing Netsweeper for you.

Posted
Last year, we moved from LA provided broadband and Smoothwall to Wave9 and Sophos XG and would highly recommend them. I can't say how Sophos compares with Lightspeed Rocket, but we've been very happy.
  • Thanks 2
Posted
In my search for a new broadband supplier I've discovered that quite a few different filtering products are offered as part of the packages.

 

What's everyone's opinion on them, and would they be a step up or down from Lightspeed Rocket?

 

Wave9 use Sophos XG

Exa use SurfProtect

Aspire use Smoothwall

SchoolsBroadband use Netsweeper

A couple of local companies use Fortigate

 

No doubt you'll find a plethora of opinions, but my two pence is;

 

You will need a firewall as well as web-filtering

Web-filtering is not monitoring

You can't be an expert in all the technologies

No product is perfect

Price does not equal value

 

If we assume that your shortlist is comprised of products/services that are compliant with baseline DFE requirements and the companies offering them are reputable and solvent (and they're all affordable) then it's sometimes a case of making sure that any non-standard specific requirements are met (could be technical, could be process/organisational) and then making sure that the service can adapt and facilitate any changes you might encounter. Cloud adoption and Covid have shown that the ground is ever shifting and you'r expected to adapt with it.

 

If you anticipate a large quantity of off-prem devices that need filtering, then an agent based filtering might be the way to go (we offer Lightspeed)

If not, (or we think that covid measures will resolve back to in-school 90-100%)then a combined firewall and web-filter will save you money, facilitate easy management and visibility and ensure that support is simplified. You can still use agent based filtering or monitoring products alongside.

If you don't have lots of technical resource or the right skillset, then how much support are you offered - conversely, how much are you allowed to change yourself.

If you change your entire network architecture or take on additional sites, how is the service going to facilitate or hinder that?

What resilience (truly) are you able to get for an increasingly vital resource.

Increasingly security is a focus - how much visibility and control do you have over what is on your network and what is being accessed?

 

 

Everyone will have an opinion based on their specific pain points, experience, their skillset and comfort zone as well as specific pressure from SMT/governors and compliance factors. If you did a feature/service comparison across 20 suppliers, there would be some 'x's in most columns, but only you will know what is a priority for you.

 

What do you like about LS Rocket, what is missing that you really need, what are your plans for the next 3 years?

 

Happy to organise a demo/trial anytime,

 

cheers

  • Thanks 3
Posted
No doubt you'll find a plethora of opinions, but my two pence is;

 

You will need a firewall as well as web-filtering

Web-filtering is not monitoring

You can't be an expert in all the technologies

No product is perfect

Price does not equal value

 

If we assume that your shortlist is comprised of products/services that are compliant with baseline DFE requirements and the companies offering them are reputable and solvent (and they're all affordable) then it's sometimes a case of making sure that any non-standard specific requirements are met (could be technical, could be process/organisational) and then making sure that the service can adapt and facilitate any changes you might encounter. Cloud adoption and Covid have shown that the ground is ever shifting and you'r expected to adapt with it.

 

If you anticipate a large quantity of off-prem devices that need filtering, then an agent based filtering might be the way to go (we offer Lightspeed)

If not, (or we think that covid measures will resolve back to in-school 90-100%)then a combined firewall and web-filter will save you money, facilitate easy management and visibility and ensure that support is simplified. You can still use agent based filtering or monitoring products alongside.

If you don't have lots of technical resource or the right skillset, then how much support are you offered - conversely, how much are you allowed to change yourself.

If you change your entire network architecture or take on additional sites, how is the service going to facilitate or hinder that?

What resilience (truly) are you able to get for an increasingly vital resource.

Increasingly security is a focus - how much visibility and control do you have over what is on your network and what is being accessed?

 

 

Everyone will have an opinion based on their specific pain points, experience, their skillset and comfort zone as well as specific pressure from SMT/governors and compliance factors. If you did a feature/service comparison across 20 suppliers, there would be some 'x's in most columns, but only you will know what is a priority for you.

 

What do you like about LS Rocket, what is missing that you really need, what are your plans for the next 3 years?

 

Happy to organise a demo/trial anytime,

 

cheers

 

Thanks for that Lee.

 

I don't particularly like Lightspeed Rocket if I'm honest. The interface is slow and the assignments/rulesets can be annoying. However, it does have a reputation for being among the most powerful and 'safest' filters, hence why our LA has used it for a very long time and will continue to do so.

 

Off-prem isn't really an issue, it's very unlikely our pupils will ever have school devices off-premises and they don't do remote learning either. We have a few staff that do now, but that's not really an issue.

 

A demo of Sophos XG would be great.

  • Thanks 1
Posted
You will need a firewall as well as web-filtering

Web-filtering is not monitoring

You can't be an expert in all the technologies

No product is perfect

Price does not equal value

 

Exactly that, well put!

  • Thanks 1
Posted (edited)
Also, you could decouple the web-filtering, firewall service element from the Broadband provision!

 

No reason why you need to take both from the same vendor.

 

It's true and there can be some value to be had by scouring the market for competitive rates, but in my experience it makes it too easy for the 2 (or 3) providers to pass blame between themselves for issues. Straightforward internet outage, not so bad, but certain websites not loading (Filter rules/DNS/firewall policy/authentication?) applications not working, patches not downloading or slowness, etc - not so easy to track down. If you're a whizz across all the technologies then you can probably troubleshoot but prepare for your provders to play the blame game. It's not entirely unreasonble to be fair - a supplier could tie up an engineer for hours troubleshooting something that isn't their fault, so knocking it back until you prove definitively it's them is a valid process.. If you use a single provider for these services, then it's their issue to resove, whichever element is causing the problem - and it's easier to resolve because they (we) have visibility of all the data and logs. You also get a single bill, which admin types quite like.

 

Of course, if all of your eggs are in a crap basket, then your point is very valid!

Edited by Wave9_Lee
  • Thanks 1
Posted

Split the service - we have our leased line providing the connection but then we run Censornet USS for filtering. A gateway (linux VM) sits on site (2 for redundancy/load balacing) to do the AD authentication but all the policies/reporting etc is done in the cloud.

Stable and reliable and instant online chat support and any issues they will remote on straight away.

I moved away from inline filters as meant if the box crashed you lost your WAN connection getting to anything - important when a MAT so you can still access all sites if you lose internet.

  • Thanks 1
Posted
One important point to make is that I am sole IT in my school. And even then, IT is not part of my main job now so I have less time to spend on it than I used to.
Posted
One important point to make is that I am sole IT in my school. And even then, IT is not part of my main job now so I have less time to spend on it than I used to.

 

You must have been very bad in a former life ;)

Posted
You must have been very bad in a former life ;)

It's a good thing I set it up so well when I started 7 years ago, it just ticks along nicely (mostly) now! The time will come soon where I need to totally step back from IT though.

Posted
It's true and there can be some value to be had by scouring the market for competitive rates, but in my experience it makes it too easy for the 2 (or 3) providers to pass blame between themselves for issues.

In my experience (and not naming names) is that this doesn't stop providers passing blame, at all. "Oh the filter had an update overnight and caused this..." is a regular excuse I hear, regardless of whether it's bundled.

Posted
In my experience (and not naming names) is that this doesn't stop providers passing blame, at all. "Oh the filter had an update overnight and caused this..." is a regular excuse I hear, regardless of whether it's bundled.

 

Any supplier who continually tried to blame others for any issues rather than just supporting to their best ability would be unlikely to get a chance at any future contract. So it's a short-sighted view, in my opinion.

 

Value for money comes in very different options though.

Posted
One important point to make is that I am sole IT in my school. And even then, IT is not part of my main job now so I have less time to spend on it than I used to.

 

This is a key point to consider too. If you're flying solo, it's particularly important to 'outsource', consolidate and simplify where possible. I personally don't think a full outsource 'managed service' works most of the time, which is why we operate a hybrid managed service so you retain as much control as you need, but are getting good support and backup resource for a sensible budget for when things get too complex or resource issues occur.

  • Thanks 2
Posted
One important point to make is that I am sole IT in my school. And even then, IT is not part of my main job now so I have less time to spend on it than I used to.

Jordan, I was looking for something that works and didn't need to time and input that Smoothwall did as I need to spend my time on other parts of the job. Move to Securly in the summer on a new 1gb leased line and not looked back since, brilliant system with reasonable reporting and does what it says. Importantly any issues are swiftly dealt with either Securly direct or our leased line supplier.

  • Thanks 2
  • 10 months later...
Posted

We use Censornet USS too but truth being told it seems to be getting very expensive! Anyone used it & can offer a comparison with other providers - particularly Lightspeed who we already use for MDM purposes?

 

Thanks!

Posted
We use Fortigate for our Firewall and filtering to some devices with Forti Analzyer for some logging. We then use Lightspeed on student devices for Filtering/Safeguarding/Monitoring on student iPads and Mac's in the labs.
Posted
@SteveB_NI I'm not familiar with Censornet, but if you'd like a demo or free trial of Lightspeed, I can arange this no problem - PM if interested

 

Thanks but being a N.Ireland school we need to keep to government framework tendered contracts :( We already have a supplier who we purchase Lightspeed MDM through.

 

I've signed up for a free demo of the filtering software on Lightspeed's website but haven't heard anything back at all - which is super start :rolleyes:

  • Thanks 1
Posted (edited)
Just to say, regardless of the quality of the product, if it does not involve a dedicated device or configuration, you also have to trust that your Broadband Provider's pre-set settings are appropriate for your school or you can spend a lot of time tweeking. By appropriate, I mean are any word block lists likely to be sexist or non-inclusive by current standards? If computer science is taught, will common terms relevant to that couurse be blocked? In our case, we have found some defaults to be overblocked/inappropriate. Edited by sigma
  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...