njreynolds Posted October 16, 2023 Posted October 16, 2023 This is a personal review on my experience in switching from Smoothwall to Fortinet in my school. Reason: For years I have been unhappy with the quality & timescale of Smoothwall Support. Most recently, I called for something urgently and was told “No that cannot be done”. Once I was cancelling, I explained why & I was told “Yes, that can be done”. Basically, the support engineer didn’t know how, so I was told no. My Set up: My previous setup was a CISCO Firewall (old) and a Smoothwall box, which was just used as a proxy/filtering. My new Set up: I decided to go with a Fortigate F400, which is my Firewall and Content Filter. I decided on FortiGate as it seems the best at identifying “APP’s”. For example if someone is using the YouTube APP, I can tell & block is necessary. The Transition: When you buy FortiGate you have to buy via a third party to get the licensing & the hardware. Fortinet themselves don’t really support you, so you have to get support via the same third party. Yes, this is an extra expense – but it does mean the support is good. If its not, you can simply move to a different third party. I assume this is why my support has been generally good, because third parties know you can move! The basic installation was reasonably straightforward. It was a bit more of a hassle for me, as I was replacing the Firewall and filter at the same time. The FortiGate blocked a lot more than my old firewall, which I guess is good and bad ! My main worry area was the content filtering, so I tested this a lot before rolling out. Smoothwall works with bad lists, good lists and dynamic filtering (ie: whats on the page). FortiGate works differently. All websites have a category and you block or allow these categories. For example: ALLOW: Business, Education, Arts, Entertainment, etc BLOCK: Adult, Gambling, Dating, etc As far as I know it doesn’t do any dynamic filtering, which I thought was bad at first. BUT, it works ! We have not had over blocking and we have had no dodgy content so far. There is an option for UNRATED. So, if a website is unrated (ie: unknown) you can block or allow by default. I had read that blocking UNRATED could over block, but it my experience its fine. So, the only way I can get something dodgy would be if an adult website was mis-categorized. I have had a few things blocked, because they were in a slightly wrong category. Nothing as serious as something like onlyfans classed as GAMES. The bad bits: There are some bugs that I have found, mainly GUI stuff. Some are pretty annoying and there is no quick fix. Once Fortinet agree its an issue, it will get fixed. BUT it goes into the ALPHA firmware release first, then a few months later into the BETA release, then finally a few months later into the STABLE release (called Mature). So, basically you can be waiting 6 months for the fix – as its recommended only to use the STABLE release. The good bits: It works fine, it feel more secure. I went for the F400 models and it doesn’t break a sweat for 2000 users. Overall: It was a lot more work, than I expected. However, I am pleased I did it. Performance seems better & I know if I need support, I can get it. Hope this helps. 2
RLR Posted October 16, 2023 Posted October 16, 2023 (edited) We've been with FortiGate for years now and just updated to 400F also. We also blocked the unrated category and it rarely causes any issues. It's usually newer sites that get blocked becaus they haven't been categorised yet. As for dynamic filtering, we have recently setup our fortigate to block websites based on the contents of the page. For example, if it contains a bad word. This has worked well but we do get quite a few urls that need exempting from this. We have third party support that we sometimes use but not very often. Although, when we came to upgrade our fortigate, they did the config for us and it was smooth. I also see a lot of people asking about filtering options for off site devices. Most of the time it is suggested to use another service (securly for example) but this comes at an extra cost. We are able to filter our 1:1 devices off site by forcing the devices to login to our firewall portal. This means they get the same filtering at home as they do in school. They only have to login to the firewall portal when connecting from outside of network. This is done with a PHP proxy windows server and a PAC file. This is probably possible on Smoothwall also but thought I'd let people know. Edited October 16, 2023 by RLR 1
Joeloman Posted October 17, 2023 Posted October 17, 2023 (edited) Our experience with Fortinet is that it is a very good firewall. However, the firewall from Smoothwall is usually sufficient and is fairly easy to maintain for e.g. a teacher. In Sweden, almost everyone uses their own hardware for Smoothwall, with a fast server the throughput is very good even for Smoothwall. Today most run Smoothwall Cloud Filter and the web filter in the firewall is only for BYOD. Our experience with Fortguard in school environments is that it is not really sufficient for a school environment at least about 1.5 years ago.... 1. Fortinet content filter does not work very well compared to Smoothwall. I don't know if the Fortinet today can handle several languages, often the students use another language to try to get past the filter. Very common to use Google translate for a whole page. We have experienced problems with Fortinet for e.g. forums, Youtube, social media etc. where the content changes quickly 2. Fortinet only makes a classification of a domain and often a very general classification such as business, shopping For example. this site httpX://www.screambox.com classifies Smoothwall as "Adult Sites, Audio and Video, Piracy and Copyright Infringement" I don't know what it is classified as in Fortinet... 3. Fortinet blocks drugs (medicines and fungi) very badly, at least about 1.5 years ago, when I last tried fortinet. Maybe they have gotten better today..A quick Google search found these that Smoothwall blocks. httpX://bestdealpills.com httpX://lundapotek.com httpX://gluckspilze.com httpX://tramadol-lakare.com I don't know what it looks like for Fortinet today, but in the past, almost all pages were released as business, shopping, which is not wrong, but we don't want the students to shop there! Summary: (About 1.5 years ago this applied) Fortinet good firewall, but the web filter is not enough for a Swedish school environment with many different languages I recommend trying several different products and comparing them in your own environment. Today, the firewall and the web filter do not have to come from the same supplier, as Cloud Filter is available from most companies and then the filter works even when the student is at home with his computer. Edited October 17, 2023 by ZeroHour
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now