Jump to content

Recommended Posts

Posted

Hi, appreciate you are looking for community responses rather than 'supplier', but I will offer Sophos as an alternative.  We have many happy customers using this as a firewall and web-filtering appliance on-prem.  Happy to provide more info or a demo anytime

 

cheers, Lee

  • Like 1
Posted

Sophos is pretty good as a firewall, I do think Smoothwall is the best as an education focused web filter though. 

 

If you're looking to move to a cloud filtering solution like Smoothwall cloud, then something like a Ubiquiti UDM may be perfect for a small primary and doesn't have the recurring licence fees.

 

  • Like 1
Posted
17 hours ago, SchoolsBroadband said:

Fortinet #1 in the world when it comes to firewalls.

 

Dave

 

Considering their security issues in recent years, I would question this.

  • Like 3
Posted

We use Smoothwall too, at renewal we did look at other companies but found Smoothwall was the best in terms of filtering since it's made for education

  • Like 1
Posted
20 hours ago, FN-GM said:

 

Considering their security issues in recent years, I would question this.

Would tend to agree here, like their interface but I think they've started to develop a bit a of a reputation now for security issues.

Posted
1 hour ago, Aprice said:

Would tend to agree here, like their interface but I think they've started to develop a bit a of a reputation now for security issues.

They've not had the best 12 months with the SSL issues in particular which caused us and I'm sure others massive headaches, but still all vendors have bugs / vulnerabilities. Last time I checked Fortinet were still very much in the upper right hand corner of firewall, UTM and various other similar Gartner Magic quadrants. I think they are the largest firewall / security stack vendor in the world and also hold contracts with a plethora of government agencies including HMRC I believe.

 

I suspect they also protect the most schools in the UK too. Both we and LGFL for example use them.


Dave

Posted (edited)

Would agree with the above, Fortinet are a Cyber Security business and it is their area of expertise. From our own customer feedback and our own experiences it appears better to keep Firewalls with Firewall specific vendors and filtering with filtering specialist. The issues we get feedback around is when trying to have a vendor do both. Smoothwall filtering and monitoring is very good, our recommendations is to let them do what they are good at and let a Firewall specific vendors do what they are good at.

Edited by Simon_EXA
extra words
Posted

Thanks guys for great replies.

 

I was wondering about costs really of other firewall providers but the general feedback seems to be stay with Smoothwall. My reasons for enquiring are that Smoothwall quite often on renewal send quotes out increasing prices significantly even for small loyal customers and these types of customers do not need overkiil appliances that are necessary for much larger organisations. This is where Smoothwall are frustrating and they don't want to budge on price.

Posted

Smaller schools can really benefit from low cost hosted firewall options, if you are using a less than 300 Mbps connection the cost can be good value. Not always as many features as on premises firewalls, sometimes less reports and stats but the important stuff is there. This may take your Smoothwall costs down if you have a renewal cost for Filter and Firewall and if you do have a Smoothwall appliance on site it may reduce the CPU load if its just in Filter mode. Many of our smaller schools will just have our managed router on site, hosted firewall and then a per user cost for Smoothwall Filter and then add if required Smoothwall Monitor.

Posted (edited)
On 12/05/2025 at 09:19, SchoolsBroadband said:

They've not had the best 12 months with the SSL issues in particular which caused us and I'm sure others massive headaches, but still all vendors have bugs / vulnerabilities. Last time I checked Fortinet were still very much in the upper right hand corner of firewall, UTM and various other similar Gartner Magic quadrants. I think they are the largest firewall / security stack vendor in the world and also hold contracts with a plethora of government agencies including HMRC I believe.

 

I suspect they also protect the most schools in the UK too. Both we and LGFL for example use them.


Dave

Nearly all firewalls (and for that matter other security products,) have had their issues but what really counts is how they deal with them (i.e. LastPass) and their security practices. Gartner rates PaloAlto highly along side Fortinet and Checkpoint

Edited by Davit2005
Posted
13 hours ago, discoveranother said:

Thanks guys for great replies.

 

I was wondering about costs really of other firewall providers but the general feedback seems to be stay with Smoothwall. My reasons for enquiring are that Smoothwall quite often on renewal send quotes out increasing prices significantly even for small loyal customers and these types of customers do not need overkiil appliances that are necessary for much larger organisations. This is where Smoothwall are frustrating and they don't want to budge on price.


We've not really shifted our prices too much in a long while - so this is a bit of a surprise. Happy to discuss individual details in private!

Posted
On 13/05/2025 at 22:52, discoveranother said:

Thanks guys for great replies.

 

I was wondering about costs really of other firewall providers but the general feedback seems to be stay with Smoothwall. My reasons for enquiring are that Smoothwall quite often on renewal send quotes out increasing prices significantly even for small loyal customers and these types of customers do not need overkiil appliances that are necessary for much larger organisations. This is where Smoothwall are frustrating and they don't want to budge on price.

 

I think regardless of the size or site, a fully featured firewall (UTM) is a must to be honest.  I'd argue that smaller schools sometimes more so, given constraints on resources, tech etc.  As a Sophos Platinum partner I'd obviously advocate for a Sophos solution (Enterprise class, industry leading etc)  - usually for both firewall and filter.  But if you prefer to filter using something else, then I'd still advocate for a separate, Next Gen firewall with a good security ecosystem and support.  I think that the demarcation and risks/benefits between security/filtering/monitoring/reporting etc require careful consideration these days, and increasingly so..

 

As an aside, customers using our managed service typically see costs come down on renewal

Posted

FortiGate is what I'd have. I don't know the cost of Sophos firewalls but I'd presume costly. FortiGate for basic school firewalling and perhaps a bit of filtering is more then enough for primaries. 

 

A firewall, regardless of features, will have some faults somewhere, nothing is perfect. Keeping items updated is key, but updates contain exploits, need another patch etc. happens to Cisco, happens to Fortinet, probably somewhere at sometime a fault was found with Sophos/Smoothwall etc.

 

The biggest flaw in firewalls from my side is relaxed rules. They are more costly and destructive than a potential fault with a potential service within a firewall. I've seen plenty of any source any destination on random ports, or inbound 3389 from the world, those to me are the scariest thing, not a minor weakness in something that's known and patchable. 

 

Obviously I speak for myself, but bad rules and bad filtering are the things I see often enough to make me consider giving up IT. 

Posted
2 minutes ago, PaddyNewman said:

FortiGate is what I'd have. I don't know the cost of Sophos firewalls but I'd presume costly. FortiGate for basic school firewalling and perhaps a bit of filtering is more then enough for primaries. 

 

A firewall, regardless of features, will have some faults somewhere, nothing is perfect. Keeping items updated is key, but updates contain exploits, need another patch etc. happens to Cisco, happens to Fortinet, probably somewhere at sometime a fault was found with Sophos/Smoothwall etc.

 

The biggest flaw in firewalls from my side is relaxed rules. They are more costly and destructive than a potential fault with a potential service within a firewall. I've seen plenty of any source any destination on random ports, or inbound 3389 from the world, those to me are the scariest thing, not a minor weakness in something that's known and patchable. 

 

Obviously I speak for myself, but bad rules and bad filtering are the things I see often enough to make me consider giving up IT. 

You presume wrong! : )

 

Agree ref rules/policies/patching - that's why we have a co-managed service where we ensure that best practice is followed, whilst providing flexibility for customers.

  • Like 2
Posted

I'm not a Sophos user or aware of prices so my presumed price point was that it'd higher than £1500/1800 for a 10G Forti appliance and 3 years FortiCare and FortiGuard licencing. 

 

I won't probe your practices, but it sounds like you experience similar requests and try to push them down the right path too!

 

In terms of small or even medium primaries with little to no IT, managed services really help them and stop them falling into the voids, but if I was a techy in my own school at primary level I'd have a FortiGate as the firewall, personally :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...