CyBeRkId2002 Posted November 8, 2024 Posted November 8, 2024 Morning all, We currently use a Sophos XG for both Firewall & Filtering roles. We are strongly considering a move to a cloud based filtering platform (Securly) and finding the cost for the Sophos - when just doing Firewall duties, to be a bit expensive. On the flip-side I don't want to skimp and it needs to be secure and fit for purpose. I wondered what people are using and the key features to look out for Fast VLAN Routing Seemless authentication - could be client, agent on server etc. We do use RADIUS but currently only for Wireless devices 2 Sites - one has approx 1000 devices at any one time, the other possibly 300. Both have 1gb Fibre Redundancy Provider with Secure VPN Connection that has not been subject to many CVE's (I'm thinking Fortigate). This isn't something we use at present but will likely consider in the near future. Have been looking at a pair of Dream Machine Pro Max for both sites but open to any other recommendations that people have used and found works well.
supportman Posted November 8, 2024 Posted November 8, 2024 Have been looking at a pair of Dream Machine Pro Max for both sites but open to any other recommendations that people have used and found works well. Unify would be my choice as well, great pricing and the most modern hardware. Great choice I think.
Wave9_Lee Posted November 8, 2024 Posted November 8, 2024 Morning all, We currently use a Sophos XG for both Firewall & Filtering roles. We are strongly considering a move to a cloud based filtering platform (Securly) and finding the cost for the Sophos - when just doing Firewall duties, to be a bit expensive. On the flip-side I don't want to skimp and it needs to be secure and fit for purpose. I wondered what people are using and the key features to look out for Fast VLAN Routing Seemless authentication - could be client, agent on server etc. We do use RADIUS but currently only for Wireless devices 2 Sites - one has approx 1000 devices at any one time, the other possibly 300. Both have 1gb Fibre Redundancy Provider with Secure VPN Connection that has not been subject to many CVE's (I'm thinking Fortigate). This isn't something we use at present but will likely consider in the near future. Have been looking at a pair of Dream Machine Pro Max for both sites but open to any other recommendations that people have used and found works well. We provide Sophos XGS for 'just' firewall duties for plenty of customers pretty cost effectively - major advantages in a lot of areas compared to many 'non-enterprise' firewalls, it's not just branding. There are a lot of features to consider, even if you're not currently using them just now - I believe that organisations need to be thinking about how to beef up their cyber protections, not deprecate it. Happy to chat through how pricing might be optimised based on your use-case anytime.
Davit2005 Posted November 8, 2024 Posted November 8, 2024 I'd consider a L3 switch for intervlan routing over a firewall (aka router on a stick solution) with 1000 devices. Leave the firewall to deal with the traffic you do not trust as much. My one suggestion would be to use a firewall for Guest WiFi networks and IoT networks, etc. as dealing with firewall rules is a lot easier than ACLs on a switch.
tom_newton Posted November 8, 2024 Posted November 8, 2024 Some good recommendations - the Sophos is definitely a solid firewall. You might want to keep that for fw? Hopefully you don't need anything too clever though - no internal servers etc, so you can probably use something less full featured. We can happily offer you a cloud filter plus a firewall if you'd like to have a look, get in touch (or if you just want to talk to a firewall nerd) [email protected]
CyBeRkId2002 Posted November 8, 2024 Author Posted November 8, 2024 Hi all, thanks for the replies... Lee - Have booked a 15 minute meeting with you Monday to just check we are heading along the right lines, especially as we are likely to be moving to yourselves when our current connectivity contract expires! 1
Norphy Posted November 8, 2024 Posted November 8, 2024 SonicWALL and Fortinet would both be solid choices, although probably as expensive as the Sophos
yac2016 Posted November 8, 2024 Posted November 8, 2024 Pfsense for Firewall and Securly for filtering.
slugshead Posted November 9, 2024 Posted November 9, 2024 Have a look at Watchguard. Had a pair of M670's. They worked REALLY well, like really damn well. The cost of renewal and having to replace the filtering appliance too made the renewal way too expensive though
MatthewL Posted November 10, 2024 Posted November 10, 2024 Do you need the pair? Unless you have dual routers from your ISP you still have a single point of failure. Just a thought to keep costs down. I think Watchguard is well worth the money, some things you just need to spend it on it.
RobFuller Posted November 11, 2024 Posted November 11, 2024 Do you need the pair? Unless you have dual routers from your ISP you still have a single point of failure. Just a thought to keep costs down. I think Watchguard is well worth the money, some things you just need to spend it on it. 100% need a pair its critical infrastructure now. Active Passive is perfectly fine and some vendors don't charge the addtional licence, only for the tin.
DrCheese Posted November 11, 2024 Posted November 11, 2024 100% need a pair its critical infrastructure now. Active Passive is perfectly fine and some vendors don't charge the addtional licence, only for the tin. Yes, agree — you always want a pair. It lets you update one and ensure it's behaving before updating the other. The last thing you want is a patch that takes out your only firewall and leaves you without Internet. (It also lets you keep services whist updating) In terms of having one ISP router - You should have two separate connections now if you are following DFE guidance. Our backup link is via a completely separate ISP & physical infrastructure. 1
Wave9_Lee Posted November 11, 2024 Posted November 11, 2024 Yes, agree — you always want a pair. It lets you update one and ensure it's behaving before updating the other. The last thing you want is a patch that takes out your only firewall and leaves you without Internet. (It also lets you keep services whist updating) In terms of having one ISP router - You should have two separate connections now if you are following DFE guidance. Our backup link is via a completely separate ISP & physical infrastructure. And don't forget to propery cross-connect WAN links 2
aac Posted November 11, 2024 Posted November 11, 2024 Interesting to to see that UniFi Dream Machine Pro Max is under consideration by some, are the firewall/filtering options comparative these days to things like Smoothwall? Can you be granular enough to filter based on AD group membership etc ?
rogerdnixon Posted November 11, 2024 Posted November 11, 2024 We use UDM Pro/SE at our primaries. Filtering is cloud based with Securly and auths against out Google Workspace accounts - works well. Seocndary we load balance 2 x 1Gbps connections with PFsense+ and also use Securly cloud filtering. Although I am temped by by the new Unifi EFG...... AD was retired some time ago.
aac Posted November 11, 2024 Posted November 11, 2024 Just having a look at that EFG myself and looks like a tempting offer worth at least looking into as the costs for Sophos Firewall are becoming ridiculous, they are upping the price significantly each time we renew. For 3k you can get a pair of EFG for high availability...
Wave9_Lee Posted November 11, 2024 Posted November 11, 2024 Just having a look at that EFG myself and looks like a tempting offer worth at least looking into as the costs for Sophos Firewall are becoming ridiculous, they are upping the price significantly each time we renew. For 3k you can get a pair of EFG for high availability... Something odd somewhere - Sophos amongst the cheapest enterprise firewalls in my view? I'm sure Unifi does a decent job, but if it was me, I'd be looking at a proper security eco-system with a proven pedigree in threat protection and mitigation. Given the number and cost of Ransomware attacks and other threats, I wouldn't be surprised to see some minimum standards enforced by DFE in due course. We have a few Trust Governors in our organisation and this is becoming a hot-topic from a governance and compliance point of view.
tom_newton Posted November 11, 2024 Posted November 11, 2024 I dont think anyone is intending that you use your firewall as a filter - you'd want to add one of the accredited filters on top https://saferinternet.org.uk/guide-and-resource/teachers-and-school-staff/appropriate-filtering-and-monitoring/appropriate-filtering/filtering-accreditation-scheme-for-uk-schools [or of course combine it with those guys who do both] Interesting to to see that UniFi Dream Machine Pro Max is under consideration by some, are the firewall/filtering options comparative these days to things like Smoothwall? Can you be granular enough to filter based on AD group membership etc ? 1
Tefters Posted November 11, 2024 Posted November 11, 2024 (edited) Love my UDM Pro Max, highly recommended, be warned however that creating the firewall rules is a bit of a mind bender and time consuming! P.S. In before someone says "You have an STP network loop warning", I know, its 1 of my 2 core switches because I have so many fibre links and the router doesn't support MLAG (yet) so the 2 cores are connected together with 2x 25gbE links lagged and then each switch has a 10gbE link to the router and I leave Unifi blocking one with STP in case of switch or link failure and then STP unblocks and voula! Unfortunately I only have 1 internet line so only 1 router, if the router goes pete tong I have a supplier I can get another from within a day or 2 on my doorstep. EDIT 2: Yes those are the real names for my router and core switches! Edited November 11, 2024 by Tefters 1
nicholab Posted November 11, 2024 Posted November 11, 2024 I would never get a Sophos firewall ever again the configuration is a pain. The log viewing is slow and poor on the firewall. I used PaloAlto watch guard and PFsenese all of those have better user interface for working out what your doing.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now