Jump to content

Recommended Posts

Posted

Making an early start on looking at alternatives to our current web filtering product Censornet due later this year.

Looking for a solution that is VM/Cloud based and not provider specific hardware on site.

Censornet works for us as can spin up multiple VMs for redundancy, and used for Captive Portal guess access, with all the filtering rules, reporting on a cloud platform.

Also allows use of CASB reporting and rules.

Does anyone know of anything which does similar.

NOT looking for an in-line box, agent based, or a box on-site that if fails requires provider to send out a replacement, so that we have HA.

thanks.

Posted

Few I can think of,

 

Smoothwall

 

Sophos XG

 

Fortinet

 

I think all of these have HA / redundancy, I use Fortinet vm’s in HA currently.

  • Thanks 1
Posted
Making an early start on looking at alternatives to our current web filtering product Censornet due later this year.

Looking for a solution that is VM/Cloud based and not provider specific hardware on site.

Censornet works for us as can spin up multiple VMs for redundancy, and used for Captive Portal guess access, with all the filtering rules, reporting on a cloud platform.

Also allows use of CASB reporting and rules.

Does anyone know of anything which does similar.

NOT looking for an in-line box, agent based, or a box on-site that if fails requires provider to send out a replacement, so that we have HA.

thanks.

 

Sophos can do this, but on-prem can also be resilient with very cost effective passive failover. We also provide same-day configured HW replacement with engineer in the unlikely event of hardware failure.

Posted
One issue I encountered with a VM based filtering solution in the past, was with regards to non-proxy aware applications and similar, as in things that will follow the network default route, instead of redirecting to the filtering VM. For us, this traffic just went straight out to the Internet unfiltered (which can be an issue if say a browser doesn't get the proxy setting for whatever reason). We switched to an on-site in-line solution, where the traffic had to flow through it regardless to get to the Internet. A cloud solution, as long as you configure it in your network as your next hop would also be an in-line solution.
Posted
One issue I encountered with a VM based filtering solution in the past, was with regards to non-proxy aware applications and similar, as in things that will follow the network default route, instead of redirecting to the filtering VM. For us, this traffic just went straight out to the Internet unfiltered (which can be an issue if say a browser doesn't get the proxy setting for whatever reason). We switched to an on-site in-line solution, where the traffic had to flow through it regardless to get to the Internet. A cloud solution, as long as you configure it in your network as your next hop would also be an in-line solution.

 

Not an issue with Censornet. Basically on proxy/gateway failure, you can block internet, so isn't allowed and the only IPs which are whitelisted as unfiltered are the Gateway IPs. Any device on the network without a proxy won't get out to anything unless a firewall rule has been created with external provider for the source IP/subnet.

 

One site has in-line before, when the box failed it meant we lost site-to-site access also as had to traverse through the box, and don't want that situation which is why moved away from on-site boxes.

  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...