Jump to content

Recommended Posts

Posted

Morning all,

 

We currently use a Sophos XG for both Firewall & Filtering roles. We are strongly considering a move to a cloud based filtering platform (Securly) and finding the cost for the Sophos - when just doing Firewall duties, to be a bit expensive. On the flip-side I don't want to skimp and it needs to be secure and fit for purpose. I wondered what people are using and the key features to look out for

 

  • Fast VLAN Routing
  • Seemless authentication - could be client, agent on server etc. We do use RADIUS but currently only for Wireless devices
  • 2 Sites - one has approx 1000 devices at any one time, the other possibly 300. Both have 1gb Fibre
  • Redundancy
  • Provider with Secure VPN Connection that has not been subject to many CVE's (I'm thinking Fortigate). This isn't something we use at present but will likely consider in the near future.

 

Have been looking at a pair of Dream Machine Pro Max for both sites but open to any other recommendations that people have used and found works well.

Posted
Have been looking at a pair of Dream Machine Pro Max for both sites but open to any other recommendations that people have used and found works well.

 

Unify would be my choice as well, great pricing and the most modern hardware. Great choice I think.

Posted
Morning all,

 

We currently use a Sophos XG for both Firewall & Filtering roles. We are strongly considering a move to a cloud based filtering platform (Securly) and finding the cost for the Sophos - when just doing Firewall duties, to be a bit expensive. On the flip-side I don't want to skimp and it needs to be secure and fit for purpose. I wondered what people are using and the key features to look out for

 

  • Fast VLAN Routing
  • Seemless authentication - could be client, agent on server etc. We do use RADIUS but currently only for Wireless devices
  • 2 Sites - one has approx 1000 devices at any one time, the other possibly 300. Both have 1gb Fibre
  • Redundancy
  • Provider with Secure VPN Connection that has not been subject to many CVE's (I'm thinking Fortigate). This isn't something we use at present but will likely consider in the near future.

 

Have been looking at a pair of Dream Machine Pro Max for both sites but open to any other recommendations that people have used and found works well.

 

We provide Sophos XGS for 'just' firewall duties for plenty of customers pretty cost effectively - major advantages in a lot of areas compared to many 'non-enterprise' firewalls, it's not just branding. There are a lot of features to consider, even if you're not currently using them just now - I believe that organisations need to be thinking about how to beef up their cyber protections, not deprecate it. Happy to chat through how pricing might be optimised based on your use-case anytime.

Posted
I'd consider a L3 switch for intervlan routing over a firewall (aka router on a stick solution) with 1000 devices. Leave the firewall to deal with the traffic you do not trust as much. My one suggestion would be to use a firewall for Guest WiFi networks and IoT networks, etc. as dealing with firewall rules is a lot easier than ACLs on a switch.
Posted

Some good recommendations - the Sophos is definitely a solid firewall. You might want to keep that for fw? Hopefully you don't need anything too clever though - no internal servers etc, so you can probably use something less full featured.

We can happily offer you a cloud filter plus a firewall if you'd like to have a look, get in touch (or if you just want to talk to a firewall nerd) [email protected]

Posted

Hi all, thanks for the replies...

 

Lee - Have booked a 15 minute meeting with you Monday to just check we are heading along the right lines, especially as we are likely to be moving to yourselves when our current connectivity contract expires!

  • Thanks 1
Posted
Have a look at Watchguard.

 

Had a pair of M670's. They worked REALLY well, like really damn well.

 

The cost of renewal and having to replace the filtering appliance too made the renewal way too expensive though

Posted

Do you need the pair? Unless you have dual routers from your ISP you still have a single point of failure. Just a thought to keep costs down.

 

I think Watchguard is well worth the money, some things you just need to spend it on it.

Posted
Do you need the pair? Unless you have dual routers from your ISP you still have a single point of failure. Just a thought to keep costs down.

 

I think Watchguard is well worth the money, some things you just need to spend it on it.

 

100% need a pair its critical infrastructure now. Active Passive is perfectly fine and some vendors don't charge the addtional licence, only for the tin.

Posted
100% need a pair its critical infrastructure now. Active Passive is perfectly fine and some vendors don't charge the addtional licence, only for the tin.

 

Yes, agree — you always want a pair. It lets you update one and ensure it's behaving before updating the other. The last thing you want is a patch that takes out your only firewall and leaves you without Internet. (It also lets you keep services whist updating)

 

In terms of having one ISP router - You should have two separate connections now if you are following DFE guidance. Our backup link is via a completely separate ISP & physical infrastructure.

  • Thanks 1
Posted
Yes, agree — you always want a pair. It lets you update one and ensure it's behaving before updating the other. The last thing you want is a patch that takes out your only firewall and leaves you without Internet. (It also lets you keep services whist updating)

 

In terms of having one ISP router - You should have two separate connections now if you are following DFE guidance. Our backup link is via a completely separate ISP & physical infrastructure.

And don't forget to propery cross-connect WAN links

 

XGS CC ex1.jpg

  • Thanks 2
Posted
Interesting to to see that UniFi Dream Machine Pro Max is under consideration by some, are the firewall/filtering options comparative these days to things like Smoothwall? Can you be granular enough to filter based on AD group membership etc ?
Posted
We use UDM Pro/SE at our primaries. Filtering is cloud based with Securly and auths against out Google Workspace accounts - works well. Seocndary we load balance 2 x 1Gbps connections with PFsense+ and also use Securly cloud filtering. Although I am temped by by the new Unifi EFG...... AD was retired some time ago.
Posted
Just having a look at that EFG myself and looks like a tempting offer worth at least looking into as the costs for Sophos Firewall are becoming ridiculous, they are upping the price significantly each time we renew. For 3k you can get a pair of EFG for high availability...
Posted
Just having a look at that EFG myself and looks like a tempting offer worth at least looking into as the costs for Sophos Firewall are becoming ridiculous, they are upping the price significantly each time we renew. For 3k you can get a pair of EFG for high availability...

Something odd somewhere - Sophos amongst the cheapest enterprise firewalls in my view?

 

I'm sure Unifi does a decent job, but if it was me, I'd be looking at a proper security eco-system with a proven pedigree in threat protection and mitigation. Given the number and cost of Ransomware attacks and other threats, I wouldn't be surprised to see some minimum standards enforced by DFE in due course. We have a few Trust Governors in our organisation and this is becoming a hot-topic from a governance and compliance point of view.

Posted

I dont think anyone is intending that you use your firewall as a filter - you'd want to add one of the accredited filters on top https://saferinternet.org.uk/guide-and-resource/teachers-and-school-staff/appropriate-filtering-and-monitoring/appropriate-filtering/filtering-accreditation-scheme-for-uk-schools [or of course combine it with those guys who do both]

 

Interesting to to see that UniFi Dream Machine Pro Max is under consideration by some, are the firewall/filtering options comparative these days to things like Smoothwall? Can you be granular enough to filter based on AD group membership etc ?
  • Thanks 1
Posted (edited)

Love my UDM Pro Max, highly recommended, be warned however that creating the firewall rules is a bit of a mind bender and time consuming!

 

P.S. In before someone says "You have an STP network loop warning", I know, its 1 of my 2 core switches because I have so many fibre links and the router doesn't support MLAG (yet) so the 2 cores are connected together with 2x 25gbE links lagged and then each switch has a 10gbE link to the router and I leave Unifi blocking one with STP in case of switch or link failure and then STP unblocks and voula!

 

Unfortunately I only have 1 internet line so only 1 router, if the router goes pete tong I have a supplier I can get another from within a day or 2 on my doorstep.

 

Screenshot 2024-11-11 152535.png

 

Screenshot 2024-11-11 153307.png

 

EDIT 2: Yes those are the real names for my router and core switches!

Edited by Tefters
  • Thanks 1
Posted
I would never get a Sophos firewall ever again the configuration is a pain. The log viewing is slow and poor on the firewall. I used PaloAlto watch guard and PFsenese all of those have better user interface for working out what your doing.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...