JordanT91 Posted January 13, 2022 Posted January 13, 2022 In my search for a new broadband supplier I've discovered that quite a few different filtering products are offered as part of the packages. What's everyone's opinion on them, and would they be a step up or down from Lightspeed Rocket? Wave9 use Sophos XG Exa use SurfProtect Aspire use Smoothwall SchoolsBroadband use Netsweeper A couple of local companies use Fortigate
PaddyNewman Posted January 13, 2022 Posted January 13, 2022 I've used all of them... it truly depends on your needs as no filtering system is perfect and one size does not fit all. For me, Netsweeper does what we need at the scale we need, but I like the usability of Smoothwall, but I really rate the support of Sophos XG and the features. Usage wise, my personal opinion for my 'generic school needs' and usability within my comfort levels are... Sophos is better than Lightspeed Lightspeed is better than SurfProtect Smoothwall is better than Lightspeed Netsweeper is better than Lightspeed Lightspeed is better than Fortigate Obviously its a personal thing and if I was running the full thing, as above I'd be fighting between Sophos, Netsweeper and Smoothwall, depending on what the needs of the school are, SLT are picky and might want x y z reports, techies might want to be super specific within what goes through SSL, what they pick up and where they get stuff from/how they integrate into their core/ADs etc. 2
paulkerton Posted January 13, 2022 Posted January 13, 2022 Whereas for me Netsweeper is old, outdated and frustratingly unusable. It really comes down to personal opinion. I would be looking at cloud solutions like Lightspeed Filter and Securly now, long before I put an appliance in my building. 2
Aprice Posted January 13, 2022 Posted January 13, 2022 I'm a fan of Fortigate and Smoothwall. Smoothwall's support has been lacking however it's a product we're confident using. The cloud based solutions tend to cause us the most problems, Netsweeper definitely being one of these. It saves so much time when we can just login to the Smoothwall and make the changes and click save, rather than sending off CRFs and waiting for responses.
paulkerton Posted January 13, 2022 Posted January 13, 2022 The cloud based solutions tend to cause us the most problems, Netsweeper definitely being one of these. It saves so much time when we can just login to the Smoothwall and make the changes and click save, rather than sending off CRFs and waiting for responses. That's not a cloud based solution though, really. That's someone managing Netsweeper for you.
StevieM Posted January 13, 2022 Posted January 13, 2022 Last year, we moved from LA provided broadband and Smoothwall to Wave9 and Sophos XG and would highly recommend them. I can't say how Sophos compares with Lightspeed Rocket, but we've been very happy. 2
Wave9_Lee Posted January 13, 2022 Posted January 13, 2022 In my search for a new broadband supplier I've discovered that quite a few different filtering products are offered as part of the packages. What's everyone's opinion on them, and would they be a step up or down from Lightspeed Rocket? Wave9 use Sophos XG Exa use SurfProtect Aspire use Smoothwall SchoolsBroadband use Netsweeper A couple of local companies use Fortigate No doubt you'll find a plethora of opinions, but my two pence is; You will need a firewall as well as web-filtering Web-filtering is not monitoring You can't be an expert in all the technologies No product is perfect Price does not equal value If we assume that your shortlist is comprised of products/services that are compliant with baseline DFE requirements and the companies offering them are reputable and solvent (and they're all affordable) then it's sometimes a case of making sure that any non-standard specific requirements are met (could be technical, could be process/organisational) and then making sure that the service can adapt and facilitate any changes you might encounter. Cloud adoption and Covid have shown that the ground is ever shifting and you'r expected to adapt with it. If you anticipate a large quantity of off-prem devices that need filtering, then an agent based filtering might be the way to go (we offer Lightspeed) If not, (or we think that covid measures will resolve back to in-school 90-100%)then a combined firewall and web-filter will save you money, facilitate easy management and visibility and ensure that support is simplified. You can still use agent based filtering or monitoring products alongside. If you don't have lots of technical resource or the right skillset, then how much support are you offered - conversely, how much are you allowed to change yourself. If you change your entire network architecture or take on additional sites, how is the service going to facilitate or hinder that? What resilience (truly) are you able to get for an increasingly vital resource. Increasingly security is a focus - how much visibility and control do you have over what is on your network and what is being accessed? Everyone will have an opinion based on their specific pain points, experience, their skillset and comfort zone as well as specific pressure from SMT/governors and compliance factors. If you did a feature/service comparison across 20 suppliers, there would be some 'x's in most columns, but only you will know what is a priority for you. What do you like about LS Rocket, what is missing that you really need, what are your plans for the next 3 years? Happy to organise a demo/trial anytime, cheers 3
JordanT91 Posted January 14, 2022 Author Posted January 14, 2022 No doubt you'll find a plethora of opinions, but my two pence is; You will need a firewall as well as web-filtering Web-filtering is not monitoring You can't be an expert in all the technologies No product is perfect Price does not equal value If we assume that your shortlist is comprised of products/services that are compliant with baseline DFE requirements and the companies offering them are reputable and solvent (and they're all affordable) then it's sometimes a case of making sure that any non-standard specific requirements are met (could be technical, could be process/organisational) and then making sure that the service can adapt and facilitate any changes you might encounter. Cloud adoption and Covid have shown that the ground is ever shifting and you'r expected to adapt with it. If you anticipate a large quantity of off-prem devices that need filtering, then an agent based filtering might be the way to go (we offer Lightspeed) If not, (or we think that covid measures will resolve back to in-school 90-100%)then a combined firewall and web-filter will save you money, facilitate easy management and visibility and ensure that support is simplified. You can still use agent based filtering or monitoring products alongside. If you don't have lots of technical resource or the right skillset, then how much support are you offered - conversely, how much are you allowed to change yourself. If you change your entire network architecture or take on additional sites, how is the service going to facilitate or hinder that? What resilience (truly) are you able to get for an increasingly vital resource. Increasingly security is a focus - how much visibility and control do you have over what is on your network and what is being accessed? Everyone will have an opinion based on their specific pain points, experience, their skillset and comfort zone as well as specific pressure from SMT/governors and compliance factors. If you did a feature/service comparison across 20 suppliers, there would be some 'x's in most columns, but only you will know what is a priority for you. What do you like about LS Rocket, what is missing that you really need, what are your plans for the next 3 years? Happy to organise a demo/trial anytime, cheers Thanks for that Lee. I don't particularly like Lightspeed Rocket if I'm honest. The interface is slow and the assignments/rulesets can be annoying. However, it does have a reputation for being among the most powerful and 'safest' filters, hence why our LA has used it for a very long time and will continue to do so. Off-prem isn't really an issue, it's very unlikely our pupils will ever have school devices off-premises and they don't do remote learning either. We have a few staff that do now, but that's not really an issue. A demo of Sophos XG would be great. 1
PaddyNewman Posted January 14, 2022 Posted January 14, 2022 You will need a firewall as well as web-filtering Web-filtering is not monitoring You can't be an expert in all the technologies No product is perfect Price does not equal value Exactly that, well put! 1
kennysarmy Posted January 14, 2022 Posted January 14, 2022 Also, you could decouple the web-filtering, firewall service element from the Broadband provision! No reason why you need to take both from the same vendor. 3
Wave9_Lee Posted January 14, 2022 Posted January 14, 2022 (edited) Also, you could decouple the web-filtering, firewall service element from the Broadband provision! No reason why you need to take both from the same vendor. It's true and there can be some value to be had by scouring the market for competitive rates, but in my experience it makes it too easy for the 2 (or 3) providers to pass blame between themselves for issues. Straightforward internet outage, not so bad, but certain websites not loading (Filter rules/DNS/firewall policy/authentication?) applications not working, patches not downloading or slowness, etc - not so easy to track down. If you're a whizz across all the technologies then you can probably troubleshoot but prepare for your provders to play the blame game. It's not entirely unreasonble to be fair - a supplier could tie up an engineer for hours troubleshooting something that isn't their fault, so knocking it back until you prove definitively it's them is a valid process.. If you use a single provider for these services, then it's their issue to resove, whichever element is causing the problem - and it's easier to resolve because they (we) have visibility of all the data and logs. You also get a single bill, which admin types quite like. Of course, if all of your eggs are in a crap basket, then your point is very valid! Edited January 14, 2022 by Wave9_Lee 1
ITGURU Posted January 15, 2022 Posted January 15, 2022 Split the service - we have our leased line providing the connection but then we run Censornet USS for filtering. A gateway (linux VM) sits on site (2 for redundancy/load balacing) to do the AD authentication but all the policies/reporting etc is done in the cloud. Stable and reliable and instant online chat support and any issues they will remote on straight away. I moved away from inline filters as meant if the box crashed you lost your WAN connection getting to anything - important when a MAT so you can still access all sites if you lose internet. 1
JordanT91 Posted January 17, 2022 Author Posted January 17, 2022 One important point to make is that I am sole IT in my school. And even then, IT is not part of my main job now so I have less time to spend on it than I used to.
kennysarmy Posted January 17, 2022 Posted January 17, 2022 One important point to make is that I am sole IT in my school. And even then, IT is not part of my main job now so I have less time to spend on it than I used to. You must have been very bad in a former life
JordanT91 Posted January 17, 2022 Author Posted January 17, 2022 You must have been very bad in a former life It's a good thing I set it up so well when I started 7 years ago, it just ticks along nicely (mostly) now! The time will come soon where I need to totally step back from IT though.
paulkerton Posted January 17, 2022 Posted January 17, 2022 It's true and there can be some value to be had by scouring the market for competitive rates, but in my experience it makes it too easy for the 2 (or 3) providers to pass blame between themselves for issues. In my experience (and not naming names) is that this doesn't stop providers passing blame, at all. "Oh the filter had an update overnight and caused this..." is a regular excuse I hear, regardless of whether it's bundled.
kennysarmy Posted January 17, 2022 Posted January 17, 2022 In my experience (and not naming names) is that this doesn't stop providers passing blame, at all. "Oh the filter had an update overnight and caused this..." is a regular excuse I hear, regardless of whether it's bundled. Any supplier who continually tried to blame others for any issues rather than just supporting to their best ability would be unlikely to get a chance at any future contract. So it's a short-sighted view, in my opinion. Value for money comes in very different options though.
Wave9_Lee Posted January 17, 2022 Posted January 17, 2022 One important point to make is that I am sole IT in my school. And even then, IT is not part of my main job now so I have less time to spend on it than I used to. This is a key point to consider too. If you're flying solo, it's particularly important to 'outsource', consolidate and simplify where possible. I personally don't think a full outsource 'managed service' works most of the time, which is why we operate a hybrid managed service so you retain as much control as you need, but are getting good support and backup resource for a sensible budget for when things get too complex or resource issues occur. 2
TheRobins Posted January 17, 2022 Posted January 17, 2022 One important point to make is that I am sole IT in my school. And even then, IT is not part of my main job now so I have less time to spend on it than I used to. Jordan, I was looking for something that works and didn't need to time and input that Smoothwall did as I need to spend my time on other parts of the job. Move to Securly in the summer on a new 1gb leased line and not looked back since, brilliant system with reasonable reporting and does what it says. Importantly any issues are swiftly dealt with either Securly direct or our leased line supplier. 2
SteveB_NI Posted November 28, 2022 Posted November 28, 2022 We use Censornet USS too but truth being told it seems to be getting very expensive! Anyone used it & can offer a comparison with other providers - particularly Lightspeed who we already use for MDM purposes? Thanks!
Wave9_Lee Posted November 29, 2022 Posted November 29, 2022 @SteveB_NI I'm not familiar with Censornet, but if you'd like a demo or free trial of Lightspeed, I can arange this no problem - PM if interested
slugshead Posted November 29, 2022 Posted November 29, 2022 With a watchguard/lightspeed combination now. Not impressed with it coming from a smoothwall setup school.
2ilent8cho Posted November 29, 2022 Posted November 29, 2022 We use Fortigate for our Firewall and filtering to some devices with Forti Analzyer for some logging. We then use Lightspeed on student devices for Filtering/Safeguarding/Monitoring on student iPads and Mac's in the labs.
SteveB_NI Posted December 2, 2022 Posted December 2, 2022 @SteveB_NI I'm not familiar with Censornet, but if you'd like a demo or free trial of Lightspeed, I can arange this no problem - PM if interested Thanks but being a N.Ireland school we need to keep to government framework tendered contracts We already have a supplier who we purchase Lightspeed MDM through. I've signed up for a free demo of the filtering software on Lightspeed's website but haven't heard anything back at all - which is super start 1
sigma Posted December 2, 2022 Posted December 2, 2022 (edited) Just to say, regardless of the quality of the product, if it does not involve a dedicated device or configuration, you also have to trust that your Broadband Provider's pre-set settings are appropriate for your school or you can spend a lot of time tweeking. By appropriate, I mean are any word block lists likely to be sexist or non-inclusive by current standards? If computer science is taught, will common terms relevant to that couurse be blocked? In our case, we have found some defaults to be overblocked/inappropriate. Edited December 2, 2022 by sigma 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now