Jump to content

Recommended Posts

Posted

Our Smoothwall is up for renewal in January and I'm torn between sticking with the devil I know - with a new S9 box or opting for a different vendor altogether and the learning curve and network reconfigurations associated with a new vendor etc.

 

So... for people who have recent moved away from Smoothwall (Firewall/Filtering/BYOD)

 

  • what did you opt for and are you happy with the choice
  • how big a nightmare was it moving over?
  • Knowing what you know now, would you have stayed with Smoothwall or you glad you switched?

 

Cheers

Posted

In my last school, I replaced the S14's with S15's just as I left. The Smoothies are pretty solid and everything is under one roof, the newer models have less interfaces but are capable of a much higher throughput.

 

I've come to a school with Watchguard/Lightspeed already in place - It's frustrating having to do things in multiple places rather than one, also found the invoices and the combination was about 10k more than the two S15 Smoothies.

 

I much prefer the workflow on Smoothwall

  • Thanks 3
Posted (edited)
If there's anything bugging you in the "con" column of Smoothwall feel free to reach out for a chat. [email protected]

 

No complaints about smoothwall (other than reporting can be a pain at times) - been using smoothwall for the past 10 years (8 years of which have been here)

 

Just a bad year for renewals as I have lots of things coming up for renewal this year, so making sure I do the due dilligance etc - and to keep the auditors and finance people happy :D

Edited by mdrabble
Posted
Most of the schools i work with have all been replacing smoothwall with either Meraki MX with Umbrella, Fortinet or Lightspeed.

 

Not keen on Meraki due to their high licensing costs at renewal times.

 

What model of Fortinet or Lightspeed have they gone for?

 

Does Fortinet comply with Dfe requirements for web filtering?

Posted

I haven’t used Smoothwall in over 2 years. ForiGate is much better and support are prompt to reply.

 

All firewalls/proxies seem to struggle with user based policies. Trying to accurately track logins and log offs seems to be a dark art.

 

Fortinet has the notion on Internet Services as destinations which self update IPs. This is useful for Office 365 if you don’t proxy the traffic due to the amount of concurrent.

Posted

I replaced smoothwall after 6 years of being with them (S8 and then S10 appliances) back in March with Sophos XGS.

 

I was able to get a 3 year contract, TWO sophos XGS 3300 appliances in HA, plus the secondary PSUs for both (not important but they were cheap) for less than just the 3 year renewal of Smoothwall, no hardware. No brainer imo. Sophos has been great, was easy to setup without any help (though others have used wave9 i think to run through their setup for/with them, which is a handy service if you're not feeling confident) personally prefer it to the Smoothwall way of working. Only thing Smoothwall does better is the content modification stuff as far as I can tell.

  • Thanks 1
Posted
I’ve dealt with Smoothwall a fair bit recently as I built a new server to replace a failed S8 box (Dell R420 based). The support was excellent. Can’t blame them for the old server failing - seems to be a known issue with R420s when they get old.
Posted (edited)
Not a massive issue with Smoothwall but I would like to be able to name the policies so they are easier to manage.

 

This feature is available in our new cloud UI (which also lets you comment on URL blocks)

Edited by tom_newton
  • Thanks 2
Posted
Not a massive issue with Smoothwall but I would like to be able to name the policies so they are easier to manage.
You mean filtering policies? I thought you could?

 

Personally I look at smoothwall, consider what I need to rework to change and stay put.

Posted
replaced with another product that works and doesn't crash every few weeks.....also has an easy to use GUI ! and support that doesn't take a week to reply.... when you have an issue....
  • Thanks 2
Posted

All of ours are with Smoothwall at the moment, On the whole I'm happy with it. I've found the support to be far better if you log a ticket rather than a phone call.

 

I think some better documentation and possibly some troubleshooting guides could help with some of the issues with it.

 

That said I am interested in looking at Fortinet again as I've heard plenty of positive stuff about it lately.

  • Thanks 2
Posted
Our Smoothwall is up for renewal in January and I'm torn between sticking with the devil I know - with a new S9 box or opting for a different vendor altogether and the learning curve and network reconfigurations associated with a new vendor etc.

 

So... for people who have recent moved away from Smoothwall (Firewall/Filtering/BYOD)

 

  • what did you opt for and are you happy with the choice
  • how big a nightmare was it moving over?
  • Knowing what you know now, would you have stayed with Smoothwall or you glad you switched?

 

Cheers

@mdrabble Hi, I'd be happy provide some pricing and demo for a Sophos alternative if that would be of interest. We configure and switchover for you, and included ulimited support (rapid response), resilient hardware, as well as free training so you can self-manage - this is useful in terms of learning curve, as you can pick up tasks at your own pace, using us while you find your feet. Or never make any changes yourself at all..

 

Added advantage of intergating with Sophos endpoint too.

 

Drop me a PM if it would be of interest.

Posted

Hi,

I no longer work in a school but do still enjoy checking out the Edugeek Forums :)

 

Here is part of a post I posted a couple years ago when i change (briefly) from Smoothwall to Sophos and could not turn back quick enough!

This was a couple of years ago and things may have improved but this is was as I found it:

 

 

We moved to the Sophos XG as at the time I was really annoyed at Smoothwall because they changed to that daft “support allowance” system. And also wouldn’t let use our S8 box when renewing our license even though it was only a couple of months old (had been replaced under warranty).

 

Sophos gave us a great deal with a free appliance but I can honestly say it was the worst purchase decision I have ever made. The thing was a complete disaster, we spent months and months with issues. It wasn’t even as if we installed it wrong as we had Sophos professional services do the installation. It lacks some really basic features that the Smoothwall excels at. The website categorisation is pretty much worthless with most sites coming up as unclassified and so your unblock list is pretty huge as our students found the “uncategorised” category has all kinds of terrible stuff on it so we had to block at and manually unblock loads of sites. Chromebook Authentication implementation, forget about it, it’s dreadful. Custom url lists are limited to 128 sites each, No safeguarding built in at all. Unblocking and blocking of sites is a massive pain as you have to use all the regex characters e.g

^([A-Za-z0-9.-]*\.)?example\.com\.?/

 

 

The worst part is the dreadful support. Support in UK time is fed out of India which is no problem in itsefl but in the experience we had you will be on hold for up to 3 hours at a time and then you will get put in an escalation queue which might take a few days. We went days without internet at times due to bugs in the firmware which meant the proxy engines kept refusing to restart. We went several months with our chromebooks not working properly and I spoke with over 5 sophos support agents who didn’t know what a Chromebook was. Sophos professional services set the firewall rules incredibly strict, as you would expect but everytime we had a problem getting an app or service through the firewall, support would just create a allow any any rule which would fix the problem, but kind of got rid of the whole point of the firewall! Sophos use 123rescue for their remote support. They could not get it to work though their own firewall, so they made a any any rule for my machine that I had to turn on when they wanted to remote in.

 

Our support experience was so bad that when I complained so much to the head of Sophos education they actually paid another 3rd party sophos support company in the UK to help us out, who told me they only have a business because sophos XG customers had Sophos’ own support service so much. They also told me that when they install the XG that they don’t do it the way Sophos recommends as in their words, it doesn’t work for schools”.

 

Most recently we had basically no internet for a week as the authentication service kept breaking, I spent 8 hours on the phone with sophos and they couldn’t figure it out.

 

I can’t give full details here at the moment but once I found out Smoothwall had changed management and had changed it’s support quota system I contacted them, told them my predicament and said I wished I never left and even though we are still under license with sophos we have come up with a deal that we will be using Smoothwall from now on. We put it in last week and it’s been smooth sailing ever since.

 

Personally, my biggest thing working in a school is safeguarding and the sophos gives me no confidence that it was being done correctly. I am sure in a business environment where web filtering is not the main concern, the sophos would be fine , but for a school where you have to be 110% sure the students are protected against all the nasty, it’s a big failure.

 

If you do want to go with it I would recommend buying through the 3rd party sophos company and buying support from them, wave9 I think they are called as they were really helpful and knowledgeable, but would have worked out quite expensive.

 

There might be other schools who had a much better experience then me, but I can honestly say it’s been a disaster for us.

  • Thanks 1
Posted

Here's the original thread for context http://www.edugeek.net/forums/internet-related-filtering-firewall/178329-smoothwall-web-filtering-re-purchase-replacement.html

 

I think most direct vendor support is below par and many don't have a sector specific team or processes - it's part of the reason Wave 9 exists, to provide a better experience, more pro-active support and 100% focus on the education sector. The UTM is 100% compliant with KCSIE and DFE guidelines and we have 100's of customers using Sophos XG and XGS. A search through the forum for 'Wave9' would demonstrate many happy customer and recommendations for which we're very grateful.

 

Sophos sell their UTM and security products across the world in all customer sectors, which is a testament to the capability of the product and the trust customers have in it. There are lots of products that are sold into education that aren't used in enterprise as they lack the credentials and capability to provide a service that enterprise customers expect. A quick look at Gartner reviews would show it as a market leader https://www.gartner.com/reviews/market/network-firewalls/vendor/sophos/product/sophos-firewall/reviews?marketSeoName=network-firewalls&vendorSeoName=sophos&productSeoName=sophos-firewall&industry=260

Posted

A school I have inherited looking after has a virtualized Sophos XG setup.

 

I don't know whether it's just the setup there specifically, but I find the config far more convoluted compared to Smoothwall (this could also be down to my familiarity with the products).

 

All the firewall and filtering rules seem to be overly intertwined and there are a lot of nested options with ambiguous names that you'd think would just change something in the firewall or filter independently, which actually have an affect on other aspects (but you have to trawl through a hell of a lot of out of date support articles to find out).

 

I can see that the firewall offering is more feature rich on Sophos, but to be honest in the majority of school deployments (not saying all) there's a lot there that people aren't going to need that can't be recreated with a solid config on a smoothwall.

 

I know you can manage in the cloud with central, but do they offer cloud filtering for mobile devices?

  • Thanks 1
Posted
Just thought I should add that I've had experience with Fortigate, Cisco ASA/Firepower, Opendium and Watchguard as well as Sophos and Smoothwall, so I like to think I vaguely know my way around things.
Posted

Our school just moved over to Sophos before I started here, and frankly everything on it seems more faff than Smoothwall, as mentioned above by Chris

 

Four months into it and we are seriously considering taking the hit and dropping the UTM and moving back to Smoothwall. Had more issues in these four months than years on Smoothwall, and honestly just lack confidence in the reliability of the product/setups

 

Especially as going forwards our Trust is looking to merge all connections to single Brands/contracts etc and if we are struggling this much to get one school sorted out, can’t imagine the pain of getting 10+

 

Steve

Posted
Hi @ChrisC I'd be happy to review your setup and provide some advice/assistance. It sounds like the previous admin has left you with some complicated exceptions/policies.
Thanks for the offer Lee, to be honest the school is starting to move towards another vendor at the end of the current agreement (likely to be Smoothwall).

 

The only thing that was a stumbling block was a legacy setup of REDs implemented off-site, but this need has been replaced by an RD Gateway with MFA.

Posted

Just to add my experience to the list:

 

We have been with Smoothwall for the last 8 years, at each renewal we have seriously considered Sophos and have come very close to going with them on one occasion. One of the major things when it came to the last renewal (when we were in lockdown), was shortcomings of Sophos for off-site filtering, at the time it was just a simple allow / deny list, this may have changed since but as we were looking at offsite filtering for over 100 devices at the time it was a big factor. Smoothwall on the other hand, allowed us to replicate our in school policies, regardless of location, without much effort at all.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...