ITGURU Posted June 22, 2023 Posted June 22, 2023 Making an early start on looking at alternatives to our current web filtering product Censornet due later this year. Looking for a solution that is VM/Cloud based and not provider specific hardware on site. Censornet works for us as can spin up multiple VMs for redundancy, and used for Captive Portal guess access, with all the filtering rules, reporting on a cloud platform. Also allows use of CASB reporting and rules. Does anyone know of anything which does similar. NOT looking for an in-line box, agent based, or a box on-site that if fails requires provider to send out a replacement, so that we have HA. thanks.
Jcx500 Posted June 23, 2023 Posted June 23, 2023 Few I can think of, Smoothwall Sophos XG Fortinet I think all of these have HA / redundancy, I use Fortinet vm’s in HA currently. 1
jonnykewell1 Posted June 23, 2023 Posted June 23, 2023 Take a look at this as an option for your cloud filtering. https://www.iboss.com/education/web-filtering-for-cipa-compliance/
TheRobins Posted June 23, 2023 Posted June 23, 2023 Securly - https://www.securly.com/ Been a fantastic product for us, hosted on Azure.
Wave9_Lee Posted June 26, 2023 Posted June 26, 2023 Making an early start on looking at alternatives to our current web filtering product Censornet due later this year. Looking for a solution that is VM/Cloud based and not provider specific hardware on site. Censornet works for us as can spin up multiple VMs for redundancy, and used for Captive Portal guess access, with all the filtering rules, reporting on a cloud platform. Also allows use of CASB reporting and rules. Does anyone know of anything which does similar. NOT looking for an in-line box, agent based, or a box on-site that if fails requires provider to send out a replacement, so that we have HA. thanks. Sophos can do this, but on-prem can also be resilient with very cost effective passive failover. We also provide same-day configured HW replacement with engineer in the unlikely event of hardware failure.
CHiLL Posted June 26, 2023 Posted June 26, 2023 One issue I encountered with a VM based filtering solution in the past, was with regards to non-proxy aware applications and similar, as in things that will follow the network default route, instead of redirecting to the filtering VM. For us, this traffic just went straight out to the Internet unfiltered (which can be an issue if say a browser doesn't get the proxy setting for whatever reason). We switched to an on-site in-line solution, where the traffic had to flow through it regardless to get to the Internet. A cloud solution, as long as you configure it in your network as your next hop would also be an in-line solution.
ITGURU Posted June 26, 2023 Author Posted June 26, 2023 One issue I encountered with a VM based filtering solution in the past, was with regards to non-proxy aware applications and similar, as in things that will follow the network default route, instead of redirecting to the filtering VM. For us, this traffic just went straight out to the Internet unfiltered (which can be an issue if say a browser doesn't get the proxy setting for whatever reason). We switched to an on-site in-line solution, where the traffic had to flow through it regardless to get to the Internet. A cloud solution, as long as you configure it in your network as your next hop would also be an in-line solution. Not an issue with Censornet. Basically on proxy/gateway failure, you can block internet, so isn't allowed and the only IPs which are whitelisted as unfiltered are the Gateway IPs. Any device on the network without a proxy won't get out to anything unless a firewall rule has been created with external provider for the source IP/subnet. One site has in-line before, when the box failed it meant we lost site-to-site access also as had to traverse through the box, and don't want that situation which is why moved away from on-site boxes.
DJ_MonkeyBoy Posted July 5, 2023 Posted July 5, 2023 I use PFsense and diladele.com: https://www.diladele.com/licensing.html
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now