CrootUK Posted May 1, 2025 Posted May 1, 2025 Hi folks, Im curious what other trusts are doing on here when it comes to retaining routing/comms to other schools when having two different broadband circuits? is anyone doing this with smoothwall? does it work well? I know SD-WAN is the obvious solution, but we don't have anything capable of this currently. Thanks!
CrootUK Posted May 1, 2025 Author Posted May 1, 2025 Problem with this, is if we failed over too another circuit we would obviously have a different public ip, in smoothwall the ipsec we have currently since being on maiden with have had to specify the public ip of both ends in the settings for the tunnel to establish, I suppose we could just make lots of tunnels of each the possible public ips for each site but i’m not to keen on that idea it could get messy.
SchoolsBroadband Posted May 1, 2025 Posted May 1, 2025 A fortigate box would do this. Sd-wan functionality is foc. No need for any licences or support. You could buy support only pa. As youre using no other functionality of the firewall its quite cpu and memory light so you don't need a big box. You can make a full or partial mesh too. Happy to quote for it if its of interest. Dave
DrCheese Posted May 2, 2025 Posted May 2, 2025 @tom_newton Can Smoothwall do an SD-Wan setup? If not at current, is it planned for future?
Simon_EXA Posted May 6, 2025 Posted May 6, 2025 I would agree with others, a Fortigate Firewall could do this for you, there really are some great deals around as well for Fortigate hardware and licensing at the moment. We can get you some indicative costs if you message me, certainly good value at the moment for Fortigates.
DrCheese Posted May 6, 2025 Posted May 6, 2025 On 02/05/2025 at 10:15, tom_newton said: No immediate plans to support this Ah, that's a shame...... So if Trusts go with the above, would that essentially mean Smoothwall becomes redundant other than filtering? Would still have it in line, but it's Firewalling features would be not required (Believe used to be able to save on a full UTM license if so)
SchoolsBroadband Posted May 6, 2025 Posted May 6, 2025 I think you could probably use it for UTM still but you'd probably not NAT on the external interfaces and let the Fortigate do that instead. You could push all UTM to the FortiGate and leave the smoothwall doing filtering only. Dave
Simon_EXA Posted May 6, 2025 Posted May 6, 2025 Agree with the above, we would recommend Smoothwall to keep doing the filtering and use a dedicated firewall for what you are looking to do.
TechMonkey Posted May 6, 2025 Posted May 6, 2025 It is what we are looking at getting in place. I love the Smoothwall Firewall as it did me well but i have been told Smoothwall are not developing the Firewall. Fortigate looks fantastic and will give a lot more features and capability.
tom_newton Posted May 6, 2025 Posted May 6, 2025 We are still developing the firewall - it will change shape over the coming years to be more edu focussed. 1
Joeloman Posted May 6, 2025 Posted May 6, 2025 Today, quite a few people in Sweden avoid firewall products from the US and Israel. Partly for ideological reasons but also for security reasons, as it is a legal requirement in the US to have a backdoor to the government. It has also not gotten any better when there is a risk that the government in the US who are supposed to ensure that GDPR is followed risk such major down cuts that they may not be able to carry out their control. Then it feels better with a firewall from the UK or Sweden
TechMonkey Posted May 6, 2025 Posted May 6, 2025 1 hour ago, tom_newton said: We are still developing the firewall - it will change shape over the coming years to be more edu focussed. That is very interesting! I was previously informed it was not dead but not something that would be focused on.
Wave9_Lee Posted May 8, 2025 Posted May 8, 2025 +1 for Sophos with included SDWAN as an option on the base licence. The Standard Protect licence includes full fat next gen enterprise firewall and web-filtering, plus synchs with Sophos CIXA (endpoint). You can configure failover within the SDWAN links between dual internet connections and both links can be active, giving you additional capacity. Conditional routing for Trusted/untrusted will improve performance and capacity too - a very flexible platform. And as a co-managed service, you don't need to RTFM if you don't want to. Happy to chat through or quote/demo anytime, cheers, Lee
Jonah Posted May 25, 2025 Posted May 25, 2025 Just to hijack this slightly - if looking at a similar option (SW for filtering, Fortinet for firewall/SD-WAN, etc.), what model(s) would typically be suggested?
SchoolsBroadband Posted May 25, 2025 Posted May 25, 2025 Depends on number of devices, connectivity throughput, session count and the kind of UTM policy you want to put on
Jonah Posted May 25, 2025 Posted May 25, 2025 (edited) 45 minutes ago, SchoolsBroadband said: Depends on number of devices, connectivity throughput, session count and the kind of UTM policy you want to put on Large mainstream secondary, ~600 devices, 1GB leased line, as a start Edited May 25, 2025 by Jonah
SchoolsBroadband Posted May 25, 2025 Posted May 25, 2025 I'm on leave until Tuesday so will dm you then. Dave 1
Simon_EXA Posted May 27, 2025 Posted May 27, 2025 The Fortigate data sheets are available if you do a quick search, a 90G would certainly be more than capable
FN-GM Posted May 27, 2025 Posted May 27, 2025 On 01/05/2025 at 23:58, CrootUK said: Problem with this, is if we failed over too another circuit we would obviously have a different public ip, in smoothwall the ipsec we have currently since being on maiden with have had to specify the public ip of both ends in the settings for the tunnel to establish, I suppose we could just make lots of tunnels of each the possible public ips for each site but i’m not to keen on that idea it could get messy. Sounds like this would be a use case to have BGP.
MatthewL Posted May 27, 2025 Posted May 27, 2025 Watchguard allows you to use multiple external interfaces for VPN's when using site to site for this purpose, works very well.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now