Jump to content

Recommended Posts

Posted

Hi all,

 

Hope you are well.

 

I've been looking at our schools firewall situation for months now and I'm no closer to finding a solution that I'm 100% happy with.

 

We have been using a council provided Smoothwall for years which I am happy with in terms of the filtering side but find the unit frustrating to use when it comes to the firewall side of things.

 

The council agreement is now coming to an end and I have been looking at either going down the route of replacing the Smoothwall for a new unit (ours is ageing) or going down the route of Fortigate or WatchGuard. I've also looked at NetSweeper.

 

The pricing for all three is fairly similar overall.

 

Ideally I'd like a higher end firewall (such as Fortigate or WatchGuard) combined with a filtering solution separately but budgets will not allow for this.

 

If I was go to with a Fortigate, will this give me the same level of filtering, dynamic content inspection etc? I am concerned from a safeguarding point of view that I'm going to a product which is less education focused although it will clearly be a step up in the firewall side of things.

 

Please feel free to advise, I am going around in circles!

 

Thanks,

 

Tom

Posted

I'd take a look at what you need from the firewall - we (Smoothwall) rarely find that our customers need more than what our firewall can provide. You will need to prioritise based on those requirements - what part is the most important in your situation.

 

Filtering wise I don't think there is a real contest, especially with the new cloud filter option that comes with the Smoothwall license.

Posted
Hi all,

 

Hope you are well.

 

I've been looking at our schools firewall situation for months now and I'm no closer to finding a solution that I'm 100% happy with.

 

We have been using a council provided Smoothwall for years which I am happy with in terms of the filtering side but find the unit frustrating to use when it comes to the firewall side of things.

 

The council agreement is now coming to an end and I have been looking at either going down the route of replacing the Smoothwall for a new unit (ours is ageing) or going down the route of Fortigate or WatchGuard. I've also looked at NetSweeper.

 

The pricing for all three is fairly similar overall.

 

Ideally I'd like a higher end firewall (such as Fortigate or WatchGuard) combined with a filtering solution separately but budgets will not allow for this.

 

If I was go to with a Fortigate, will this give me the same level of filtering, dynamic content inspection etc? I am concerned from a safeguarding point of view that I'm going to a product which is less education focused although it will clearly be a step up in the firewall side of things.

 

Please feel free to advise, I am going around in circles!

 

Thanks,

 

Tom

 

Yes, Fortigate is fine for deploying in educational environments and the filtering is good.

 

However there is no in built reporting so you also need to add in a reporting engine. Paid for services are FortiAnalyzer and Fastvue.

 

However, our Incident Management Platform takes e portrs filtering logs from FortiGate and gives enhanced web filtering reports. This is FOC for anyone taking our hosted and virtualised FortiGate solution when bolted on to our connectivity. You have access to your own dedicated virtual firewall and have the same access as you would do with a device on site, only our very big firewalls scale much better.

 

The only thing to be aware of is that currently FortiGate without additional bolt-ons does not correctly support logging on and off correctly with Azure / Entra ID without additional payable FortiAuthenticator which is very expensive for most schools. We are though working with them on that and also creating our own solution to overcome it.

 

On site AD is absolutely fine though.

 

Do send me a PM if you'd like any more information.

 

Thanks

 

Dave

Posted

I'd say Forti is the 'best' firewall, I certainly thought it was the most intuitive of the ones I've used.

 

Smoothwall as a firewall I think is fine if it's just a stateful firewall you're after. It does have IDS / IPS just not maybe as fully featured as something like Forti or Watchguard.

 

As a filtering solution, I'm quite happy with Smoothwall and am now rolling out cloud filter, so we're less reliant on the actual box.

 

Definitely wouldn't want to go near Netsweeper again.

Posted

There is a fear of netsweeper for sure, I've built plenty of instances and had very few issues, all filtering platforms have some nuances though!

 

Fortigates used to have pretty rough filtering but they look to have changed over the years, but it's a firewall first and foremost with a filtering product tacked on.

 

Smoothwall is a filter with firewalling capabilities.

 

I guess it's all down to budget and what you need, I've not really seen any proper content mod or filtering stuff outside of a Smoothwall.

Posted
I was reviewing all of this about 9 months ago, I came to conclusion that the ideal solution would be Fortigate for firewall and Smoothwall for filtering. However, as mentioned it is more expensive, and I simply didn't have the headroom in the budget. My frustration with Smoothwall firewall is the reporting, we had a threat analysis done about 12 months ago, it just involved putting a Fortigate on the network and port mirroring the traffic that was going to the Smoothwall, the data we got out of it was brilliant, we had malware threats detected on the BYOD network, we could see who was trying to access VPNs (and witch ones), we had no visibility of any of this on the Smoothwall. That said, Smoothwall is (in my opinion) the best filter around and conversely, that is partly due to the reporting.
Posted
I was reviewing all of this about 9 months ago, I came to conclusion that the ideal solution would be Fortigate for firewall and Smoothwall for filtering. However, as mentioned it is more expensive, and I simply didn't have the headroom in the budget. My frustration with Smoothwall firewall is the reporting, we had a threat analysis done about 12 months ago, it just involved putting a Fortigate on the network and port mirroring the traffic that was going to the Smoothwall, the data we got out of it was brilliant, we had malware threats detected on the BYOD network, we could see who was trying to access VPNs (and witch ones), we had no visibility of any of this on the Smoothwall. That said, Smoothwall is (in my opinion) the best filter around and conversely, that is partly due to the reporting.

 

Good analysis, just a note - enabling the IDS feature on LAN and BYOD interfaces on the Smoothwall can give you some of the same information, not with a fancy report though.

Posted (edited)

We went through this recently and I had the Head and both DSLs involved from in the process from the outset.

 

I had2 sets of demos from each product - first was a technical demo for just myself, so I could see what each product had to offer and then the other demo was the filtering, reporting for Head and DSLs.

 

We looked at Smoothwall (Cloud Reporting including Monitor for Safeguarding), Fortinet (Fastvue and Replog for Reporting) and Sonicwall (Fastvue for Reporting)

 

I gave them my honest and unbiased opinions - Smoothwall definitely the better filtering product and Fortinet the better Firewall Product and for reporting I kept quiet on this as I wanted to let them decide on their own.

 

I made sure the DSLs and Head made the overall decision as it was based on Filtering and Reporting.

 

They ended up going with Fortinet with FastVue and RepLog (for Safeguarding) from SwitchShop - as this gave the reporting features they were happy with- I know Smoothwall have worked on this and have introduced their Cloud Report, but Head and DSLs didnt feel it was quite up the other reporting options.

 

I'll be honest, the decision was a total surprise as we were a Smoothwall customer for years.

 

I would have been happy for Fortinet and Smoothwall combo, but cost was also factored into this as with most things.

Edited by mdrabble
Posted

Thank you all for your responses so far.

 

I am in agreement that a Fortigate with Smoothwall for filtering would be the ideal solution but our budgets just don't stretch that far.

 

My main issue with Smoothwall is the visibility, I just don't feel I get enough back from the firewall but the filtering is very good - I need to balance the needs of overall network security with making sure that our filtering and monitoring is as strong as possible.

 

We've got Cloud Filter (recently rolled out to Macs and soon to Windows devices) and are now using Cloud Reporting too.

 

In regard to Fortigate, the quote I've got includes FortiAnalyzer, is this as good as FastVue?

 

Thanks,

 

Tom

Posted

If there's any particular visibility you would like, we can help you with that. There are firewall logs, but they arent generally exposed.

 

Most schools are not hosting their own servers these days so most of the true firewall functions dont add a ton of value. If there's something we can tweak though I am happy to help

Posted

Heya,

 

If it is any help we do have an agnostic view of things and partnered with all the brands mentioned above and have an inhouse security specialist available for consultations, Q & A etc , if you would like any assistance , let us know :)

Posted
Hi all,

 

Hope you are well.

 

I've been looking at our schools firewall situation for months now and I'm no closer to finding a solution that I'm 100% happy with.

 

We have been using a council provided Smoothwall for years which I am happy with in terms of the filtering side but find the unit frustrating to use when it comes to the firewall side of things.

 

The council agreement is now coming to an end and I have been looking at either going down the route of replacing the Smoothwall for a new unit (ours is ageing) or going down the route of Fortigate or WatchGuard. I've also looked at NetSweeper.

 

The pricing for all three is fairly similar overall.

 

Ideally I'd like a higher end firewall (such as Fortigate or WatchGuard) combined with a filtering solution separately but budgets will not allow for this.

 

If I was go to with a Fortigate, will this give me the same level of filtering, dynamic content inspection etc? I am concerned from a safeguarding point of view that I'm going to a product which is less education focused although it will clearly be a step up in the firewall side of things.

 

Please feel free to advise, I am going around in circles!

 

Thanks,

 

Tom

We're very pro on-prem at Wave 9 for maximum flexibiity and control - Happy to add Sophos into the mix - I can provide some pricing/demo etc as required anytime, thanks

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...