Jump to content

Recommended Posts

Posted

Hi folks,

Im curious what other trusts are doing on here when it comes to retaining routing/comms to other schools when having two different broadband circuits?

 

is anyone doing this with smoothwall? does it work well? 

I know SD-WAN is the obvious solution, but we don't have anything capable of this currently. 

Thanks!

Posted

Problem with this, is if we failed over too another circuit we would obviously have a different public ip, in smoothwall the ipsec we have currently since being on maiden with have had to specify the public ip of both ends in the settings for the tunnel to establish, I suppose we could just make lots of tunnels of each the possible public ips for each site but i’m not to keen on that idea it could get messy.

Posted

A fortigate box would do this.

 

Sd-wan functionality is foc. No need for any licences or support. You could buy support only pa. 

 

As youre using no other functionality of the firewall its quite cpu and memory light so you don't need a big box.

 

You can make a full or partial mesh too.

 

Happy to quote for it if its of interest.

 

Dave

Posted

I would agree with others, a Fortigate Firewall could do this for you, there really are some great deals around as well for Fortigate hardware and licensing at the moment. We can get you some indicative costs if you message me, certainly good value at the moment for Fortigates.

Posted
On 02/05/2025 at 10:15, tom_newton said:

No immediate plans to support this 

Ah, that's a shame...... So if Trusts go with the above, would that essentially mean Smoothwall becomes redundant other than filtering?

 

Would still have it in line, but it's Firewalling features would be not required (Believe used to be able to save on a full UTM license if so)

Posted

I think you could probably use it for UTM still but you'd probably not NAT on the external interfaces and let the Fortigate do that instead. You could push all UTM to the FortiGate and leave the smoothwall doing filtering only.

 

Dave

 

Posted

Agree with the above, we would recommend Smoothwall to keep doing the filtering and use a dedicated firewall for what you are looking to do.

Posted

It is what we are looking at getting in place.  I love the Smoothwall Firewall as it did me well but i have been told Smoothwall are not developing the Firewall. Fortigate looks fantastic and will give a lot more features and capability.

Posted

Today, quite a few people in Sweden avoid firewall products from the US and Israel.


Partly for ideological reasons but also for security reasons, as it is a legal requirement in the US to have a backdoor to the government.


It has also not gotten any better when there is a risk that the government in the US who are supposed to ensure that GDPR is followed risk such major down cuts that they may not be able to carry out their control.

Then it feels better with a firewall from the UK or Sweden 

Posted
1 hour ago, tom_newton said:

We are still developing the firewall - it will change shape over the coming years to be more edu focussed.

That is very interesting! I was previously informed it was not dead but not something that would be focused on.

Posted

+1 for Sophos with included SDWAN as an option on the base licence.  The Standard Protect licence includes full fat next gen enterprise firewall and web-filtering, plus synchs with Sophos CIXA (endpoint).  You can configure failover within the SDWAN links between dual internet connections and both links can be active, giving you additional capacity.  Conditional routing for Trusted/untrusted will improve performance and capacity too - a very flexible platform.  And as a co-managed service, you don't need to RTFM if you don't want to.  Happy to chat through or quote/demo anytime,

 

cheers, Lee

  • 3 weeks later...
Posted

Just to hijack this slightly - if looking at a similar option (SW for filtering, Fortinet for firewall/SD-WAN, etc.), what model(s) would typically be suggested?

Posted (edited)
45 minutes ago, SchoolsBroadband said:

Depends on number of devices, connectivity throughput,  session count and the kind of UTM policy you want to put on


Large mainstream secondary, ~600 devices, 1GB leased line, as a start 

Edited by Jonah
Posted
On 01/05/2025 at 23:58, CrootUK said:

Problem with this, is if we failed over too another circuit we would obviously have a different public ip, in smoothwall the ipsec we have currently since being on maiden with have had to specify the public ip of both ends in the settings for the tunnel to establish, I suppose we could just make lots of tunnels of each the possible public ips for each site but i’m not to keen on that idea it could get messy.

 

Sounds like this would be a use case to have BGP.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...