Jump to content

Recommended Posts

Posted

Hi all,

 

I am keen to know what your schools/academies/trusts are doing for web filtering?

 

I have seen many solutions thus far such as dns filtering, browser add-on based filtering which both I don't see us pursuing.

 

We are currently a mix of on-prem filtering appliances and I am keen to bring this into one solution, which would also filter devices outside of the network too.

 

Thanks.

Posted

Just smoothwall - Via a server in house & then the cloud solution for devices at home (Win Laptops/Chromebooks/Ipads etc)

 

Admittedly we're just one secondary tho!

  • Thanks 1
Posted
Hi all,

 

I am keen to know what your schools/academies/trusts are doing for web filtering?

 

I have seen many solutions thus far such as dns filtering, browser add-on based filtering which both I don't see us pursuing.

 

We are currently a mix of on-prem filtering appliances and I am keen to bring this into one solution, which would also filter devices outside of the network too.

 

Thanks.

A smoothwall appliance to protect the network perimeter with smoothwall cloud filter would have you covered for both on-prem and offsite filtering.
  • Thanks 1
Guest Guest
Posted
We have a Sophos XG appliance on-prem, all our laptops run always on VPN and we route all web traffic through the VPN to filter via the appliance
Posted

We use Smoothwall appliance and cloud for firewall and on-site/off-site filtering.

Also used Sophos for cloud filtering (never had the appliance).

Posted
We use Securly across our MAT (28 Schools). Depending on the device it extension, DNS or SMARTPac. Filtering works anywhere. One dashboard for the entire Trust and easy to deploy and scale. We tend to use UDM Pros for firewalls at primaries and PFSense+ at secondaries.
Posted
Smoothwall appliances pretty much everywhere now.

Anecdotally, I'm starting to see Sophos and Fortigate take a reasonable amount of market-share.

Posted (edited)

We use iboss cloud web filtering across our MAT

 

Agent based filtering for domain joined devices and school owned non domain joined devices which works both onsite and ofssite.

 

Agent deployed to ipads and Chromebooks for filtering both onsite and offsite.

 

DNS filtering for visitor wifi

 

VPN to iboss for filtering BYOD devices.

Edited by jonnykewell1
  • 8 months later...
Posted (edited)

Wanted to bring this up again, hope thats OK.. as our renewal is this year, still keen to hear peoples thoughts.

We are smoothwall at secondaries and LA/ISP filter at primaries, we have a MPLS connection at 1GB between all but two schools where it’s only 100MB.

 

We are yet to go out to providers, but we are building a list of potential ones and what are must haves / nice to haves are.

 

we are looking for a central solution, whether thats a box at each school then managed via cloud/master box or a pair of boxes at secondaries and everything is split through them. (need something that can manage guest/byod (non managed) onsite)

 

I have been digging in palo alto / cisco meraki subreddits asking about their https inspection/dynamic filtering but really keen to hear more from people using anything apart from smoothwall… eg fortigate/iboss/watchguard/sonicwall/sophos/securly/lightspeed/impero content keeper/palo alto/meraki mx? etc

 

I hear some products need things like fastvue or netsweeper to be practical in edu, interested to hear more about that also.

 

really would prefer a filter/firewall combo but appreciate we cant have everything lol.

 

thanks for your time.

Edited by CrootUK
Posted

Hi Croot,

 

I would strongly suggest separating filtering and firewalling if possible.

 

In my experience only smoothwall have a miminal acceptable functionality for both, and the firewall isn't very flexible at all.

 

We settled on a Fortigate and Netsweeper Combination.

 

Fortis on site and Netsweeper cloud based.

 

This allows resilience for when the filtering is problematic as the SD-WAN rule sets allow us to send traffic direct if needed (for example, MIS traffic to Arbour/Bromcom and ScholarPack is all direct - there is no need to filter it).

 

We also have a Fortimanager to maintain the estate.

 

Netsweeper's reporting isn't great (it's week point I feel, especially for use by DSLs), but the filtering and alerting does the job well. We don't share the instance - it's our own so we can make all technical decisions ourselves.

 

This was all bought through a single ISP, we do the basic maintenance of all the systems for us (whilst we retain full access to inspect and make changes if needed).

  • Thanks 2
Posted

Appreciate you're looking for peer recommendations, but I'd be happy to arrange a demo/trial of our services if it's of interest.

 

Our approach is slightly different than some others, happy to discuss the pros and cons.

 

cheers

  • 2 months later...
Posted
Hi, I disagree with Mr Ben. You can't have a separated firewall and filter in a modern network. Why? Because both the firewall and the Web filter require SSL certificates deployed on all machines including byod for their advanced security functionality and education rich reporting and content controls. Just some examples are that all firewalls that offer next gen security include sandboxing. 95% of all sanboxing features require ssl inspection enabled to work. Secondly most advanced, or machine learning/ deep learning or even AI based security features will require deep packet security inspection to work too. The web filtering solution will also need to do this to meet the safeguarding requirements. Sadly only one of the two solutions can do the man in the middle (SSL) inspection at any given time therefore meaning only 1 of the 2 solutions offers its full capabilities. Most of the time that means the school priorities web filtering over network security for kcsie and reporting. Sadly this often leads to a poor security posture as nearly all of the advanced firewall security features are not enabled .
Posted
Hi, I disagree with Mr Ben. You can't have a separated firewall and filter in a modern network. Why? Because both the firewall and the Web filter require SSL certificates deployed on all machines including byod for their advanced security functionality and education rich reporting and content controls. Just some examples are that all firewalls that offer next gen security include sandboxing. 95% of all sanboxing features require ssl inspection enabled to work. Secondly most advanced, or machine learning/ deep learning or even AI based security features will require deep packet security inspection to work too. The web filtering solution will also need to do this to meet the safeguarding requirements. Sadly only one of the two solutions can do the man in the middle (SSL) inspection at any given time therefore meaning only 1 of the 2 solutions offers its full capabilities. Most of the time that means the school priorities web filtering over network security for kcsie and reporting. Sadly this often leads to a poor security posture as nearly all of the advanced firewall security features are not enabled .

 

You can achieve all that with separation.

 

I can’t think of any good all in one firewall and filtering solution. For that alone they should be separate components.

  • Thanks 2
Posted
Layering on an Impero type product is another strand of safeguarding and reporting that reaches into local devices where firewalls and internet filters have no visibility.
Posted (edited)
Sorry but that is not really possible.... this is because the certificate is installed on the device, you can't really install multiple ssl certificates, or it's will just eventually break, or bring the network speed right down. It might seem to work for a short period of time but eventually it just breaks. Can you explain how you do this with 'seperation'. Most market leading vendors have a firewall and filter as one solution in a UTM style offering or often referred to as a next generation firewall. The main benefit this offers is because most traffic is now application based and app controls is a firewalls responsibility not the dns or url filter. By having a combined solution you get a more comprehensive holistic solution with a single reporting tool. A dual offering will require dual reporting to meet safeguarding requirements. Edited by KDW1987
Posted

Aren't a lot of filtering solutions getting around the need for SSL by filtering at the end-point now. Although this means needing a client installed on the endpoint machine which brings a whole new set of potential issues.

 

Also, why can't a separate firewall and web-filter use the same root certificate?

Posted (edited)

Hi Rob, It's not that you can't deploy it this way, it is more that you are doing dual man in the middle inspection and that is very heavy on performance. Also the firewall and filter will need a trusted CA to do DPI and the web filter for the same without that it does not work. I have seen schools use the same certificate on both solutions many times and evently it either stops working on one, or the other appliance without you knowing, or it was never really working in the first place, or it grinds everything to hault.

 

You are right about if you are doing this with an agent on the device. However most agent based solutions are swig solutions, or web proxies which means they are not doing the filtering locally on the device. Traffic is being routed via a cloud hosted solution, working as a web proxy. The key is to know if the filtering is happening locally or not.

 

The only draw back to a local agent based solutions is the performance impact on the device and you can't deploy this on byod as the end user retains the right to remove any software and will mean you can not enforce that filtering because of this.

Edited by KDW1987
Posted (edited)

I know others have mentioned using a virtual appliance for this sort of thing, but we were put off using our Smoothwall virtual appliance several years ago and we swapped it for their hardware appliance instead, specifically so it was in-line filtering. We found that if a client/user didn't apply it's proxy settings for whatever reason, the traffic would flow via the network route, which was typically client > edge switch > core switch > router > Internet. This meant that the traffic wasn't being diverted via the proxy settings to the virtual appliance and therefore was unfiltered. Having a hardware appliance that sat in-between the core switch and firewall meant that the traffic had no choice but to go through the filter.

 

Sorry but that is not really possible.... this is because the certificate is installed on the device, you can't really install multiple ssl certificates, or it's will just eventually break, or bring the network to speed right down. It might seem to work for a short period of time but eventually it just breaks. Can you explain how you do this with 'seperation'. Most market leading vendors have a firewall and filter as one solution in a UTM style offering or often referred to as a next generation firewall. The main benefit this offers is because most traffic is now application based and app controls is a firewalls responsibility not the dns or url filter. By having a combined solution you get a more comprehensive holistic solution with a single reporting tool. A dual offering will require dual reporting to meet safeguarding requirements.

We currently have a Sophos XGS that does both filtering and firewall duties, but prior to that we had a hardware Smoothwall filtering device and a Cisco ASA firewall. Only the Smoothwall was performing HTTPS decryption, so only the Smoothwall certificate needed deploying to domain clients via GPO or manually to BYOD devices. The Cisco ASA was purely performing firewall and NAT duties, so it had no reason to have certificates on clients. Even with our Sophos XGS, we still deploy certificates to clients to perform HTTPS decryption. Though our Guest/BYOD networks don't have HTTPS decryption enabled, so purely rely on URL lists for filtering - which since they're either password protected networks that students can't access or access controlled, it doesn't concern us too much.

Edited by CHiLL
Posted

@KDW1987 Sorry, I may have got the wrong end of the stick, but are you representing a supplier or vendor here?

 

At a far less spohisticated level...

 

Since most filtering solutions still seem to be rather crude, in that they really do still seem to rely mainly on domain categorization (or so I was told recently by somebody who I would expect to know(?)), with some work done at the url level for some domains - even if there is full decryption (although always beneficial for reporting). So much for marketing "intelligent dynamic categorization" fluff.

 

Hell, our ISP still configures their filter to whitelist twitter images, and gstatic.com (which includes Google image search thumbnails), for pupils, which means in reality they rely on Google Safesearch to do the image search filtering which also means there's no reporting available for what Safesearch blocks.

 

County supplied broadband default filtering allows KS1/2 to get on to Andrew Tate's website and have a one 2 one chat "with one of their people" (not a bot), and read about whether they should cleanse their vagina with a cucumber - BBC is allowed. Presumably for older pupils too.

 

I don't think its the products that are the problem so much as poor configuration in these instances.

Posted

1. We need someone to test the classification systems of major vendors. What percentage of sites are classified correctly?

2. Which systems don't just rely on domain classification but per page?

3. Set up some automated tests for our own networks, when logged in as test student, test post 16 student, staff - which sites can/can't be accessed. With proxy on/off, on windows/mac/ipad/etc.

  • Thanks 1
Posted (edited)

Hi , represent only myself and am just sharing my experiance of helping deploy next generation firewalls and filtering systems within education settings.

 

Most URL and DNS filtering tool are built around traditional web crawlers to help detect and profile domains and urls for their categories . Most next generation vendors are now using machine and deep learning and AI to go further. These tools offer live profiling capabilities which help to detect newly registered and uncategorised urls and Domains that are using techniques to avoid security scanning tools and web crawlers. This is mostly being done by malicious attackers, but we also see this being used for filtering avoidance by students too.

Edited by KDW1987
  • Thanks 1
Posted (edited)

Sorry what I should have said is it is not technically impossible to deploy multiple certificates, what I am saying is that is not recommended and this can makes things very challenging and fragile and often breaks things, often 1 of the SSL certificate stops working and goes unnoticed and without regular monitoring and maintenance this set up does not really work.

 

From experience I have never seen this be the recommendation as the set up in nearly all of situations with a dual web filter and firewall I have only ever see the schools do SSL on 1 of the 2 solutions that are deployed, which is always the web filter for safeguarding reasons understandably .

 

From what I know the reason behind this is that this can cause conflict on traffic and have a huge performance impact on the speed of the network, as doing ssl is heavy work for a single filter / firewall as it is, so doing dual inspection on all traffic on the network will start to have very heavy performance impact on throughput capabilities of the appliances. I have also seen that this can have issues with TLS 1.2 and if web traffic gets blocked it becomes challenging to trouble shoot where the problem lays.

 

In most dual set ups the the education web filter will normally be set up as a web proxy and often the rule at the firewall is set to not decrypt any traffic coming from the web proxy and therefore the all of the advanced security features such as sand-boxing, as I mentioned wont be scanning this traffic.

 

This is why it's recommended to use a single appliance to reduce this complexity not have to face this challenge.

 

Sorry for any confusion.

Edited by KDW1987

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...