Jump to content

Recommended Posts

Posted

Hi there

 

We are considering an upgrade in our hardware firewall for a mid sized primary school.

Has anyone tried firewalla (https://firewalla.com) for filtering?

 

I've checked out their basic version for home use where it performs fine.

I've contacted them and they support that their gold series and the above can cover a small school with a max of 400-500 devices simulaneously browsing.

 

It's a cheaper solution than fortigate/draytek without the yearly subscription fees.

 

Any opinions on this?

 

Thanks in advance for your time and effort!

Posted

One look at their website and I'll file it under a "hell no". It might be the best thing in the world but Ling Ling's Car Emporium is less embarrasing.

Assuming of course you're not in the UK, as that wouldn't tick any boxes in your safeguarding obligations.

Posted (edited)

I don't know about firewalla, but it seems to lack Layer 7, i.e. application control, etc.

 

In Sweden we have no legal requirements for web filters, but there are a lot of people who use them anyway..

Many principals are often scolded if the school doesn't have a web filter.

 

In Sweden, students are almost always allowed to take their school computers home, so it is important that the web filter is on its own device and works in real time.

In Sweden, people very often use their own hardware to run the Smoothwall firewall.

Often, two regular PCs are enough.

 

It is quite common to reuse the ones that the school already has and just change the disk and put in more network cards.

Since the web filter is located on the school computers and is managed via a cloud service, it doesn't need much computing power.

 

Of course, the web filter itself costs quite a lot of money at Smoothwall, but then it is also extremely good.

The opportunity to use Smoothwall as a firewall in your own hardware is low.

 

The firewall is extremely competent with lots of good features such as Failover, Geblockning, Layer 7, DNS cache.

Even large customers such as municipalities use it.

Edited by Joeloman
Posted

I see comic sans, I close. :p

 

I did have a look through some of their stuff, personally its not something I'd consider. There's a reason the bigger names exist.. I'd be tempted to fire one up behind my firewall and see what it's doing. You don't keep up to date without talking to somewhere for updates...what else is it doing etc.

 

Cynic in me, that's the edge of my secure network, security is paramount. A degree of trust is needed. I can't trust that.

Posted

Hi there

 

You raise some legitimate concerns.

E.g your website is your image it should depict that you have certain standards. On the other hand i think it's an indigogo/kickstarter company so it's natural not to have the appropriate procedures to hold against big network players like cisco, draytek, aruba, tplink etc.

 

From their relevant manual page they seem to have some basic application control features

https://help.firewalla.com/hc/en-us/articles/360050863873-How-do-I-block-an-application

 

It is what it is guys a small company providing a more basic solution. The question is if it is a viable solution.

Posted

Oh I understand, but a RaspPi is viable. Its a basic firewall and can do hella cool stuff, doesn't mean I would put it in the forefront of my network fingers and toes crossed.

It could be fantastic, but my last line above still stands.

Posted
Hi there

 

You raise some legitimate concerns.

E.g your website is your image it should depict that you have certain standards. On the other hand i think it's an indigogo/kickstarter company so it's natural not to have the appropriate procedures to hold against big network players like cisco, draytek, aruba, tplink etc.

 

From their relevant manual page they seem to have some basic application control features

https://help.firewalla.com/hc/en-us/articles/360050863873-How-do-I-block-an-application

 

It is what it is guys a small company providing a more basic solution. The question is if it is a viable solution.

 

It won't tick nearly any of the boxes that schools are obliged to follow in many countries, certainly not in the UK for a list of reasons too long to list here, but well documented in things like https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/filtering-and-monitoring-standards-for-schools-and-colleges

Posted
It won't tick nearly any of the boxes that schools are obliged to follow in many countries, certainly not in the UK for a list of reasons too long to list here, but well documented in things like https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/filtering-and-monitoring-standards-for-schools-and-colleges

 

Well from a scanning the link of your reply (which is very general) many points seem to be covered from firewalla.

 

I am asking for an honest opinion. You can reply something generic like this but it won't lead to any productive conversation.

 

For example could you tell me what piece of equipment do you use to filter in your school? @synaesthesia, @PaddyNewman, @Joeloman

 

Thanks

AK

Posted

Firewalla definitely does not cover the majority. It's not just about capability - there's responsibility too. Who can support it? Do they have a support desk, with what SLA?

I, like the apparent majority (there was a recent poll) use Smoothwall. Lightspeed, Fortinet, Sophos XG, Netsweeper are the other big players along with some ISP specifics like Exa Surfprotect.

That link is far from generic; I'm not just citing something and running away - it is in depth and links to many other resources directly related. The UK is subject to very strict guidelines, so they need to be as clear as possible. Doesn't mean it's always right of course! And I am only speaking from experience in the UK.

Posted (edited)

In order to be able to give you good advice regarding the choice of a firewall and perhaps also a web filter.

 

We probably need to know a little more about your needs.

 

What different operating systems do you use for students and teachers?

That is, if you have Chromebooks for students, it is easy to restore and you probably also have control over the devices themselves so that they are not so vulnerable.

 

Maybe you have your own servers that can be accessed from the Internet that must be protected against intrusions and attacks?

 

Are students allowed to use their own equipment in your network? (BYOD)

 

What is the speed of your connection and do you have any form of redundancy regarding the connection and do you have any limitation on the amount of data?

 

What do you want to protect?

For example, the students so that they do not access porn, violent sites, drugs, etc.

Protect the school against information leaks.

Protect the users' systems against various viruses and other attacks.

 

If you want to protect students from porn, violent sites, drugs, etc., you must ensure that the web filter understands the different languages ​​you use at school.

And that the web filter must look at the content in real time to be safe.

 

I.e. different needs different solutions.

If you want to protect students, I would say Smoothwall, which supports many different languages. And that you can keep the cost down by using your own hardware.

 

If you want to protect yourself against information leaks Cisco.

 

We would definitely not choose a firewall or web filter that is not made for a school environment.

Edited by Joeloman

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...