Jump to content

Recommended Posts

Posted

Hi all,

 

Looking at potentially replacing firewall/filtering in the next financial year. 

1600 students, 200 staff. 1600ish iPads, 60 Macs, 450 Windows PCs, Chromebooks/ChromeFlex PCs, BYOD and everything else you can think of.... Unifi WiFi throughout, with Aruba and UniFi switches

Currently running with a 1GB Leased Line with an FTTC backup - Hitting the limits of this especially first thing in the morning. Our Apple Caching servers are definitely saving our connection at the moment!

 

Currently using an Opendium UTM

  • Support is great
  • Filtering is great
  • Reporting is great
  • Firewall side works, but is limited in what I/we can control without going through their support.
  • I think pushing a lot more bandwidth through it (if we moved to a 10G connection) would kill it. 
  • It's also doing RADIUS auth for us which I don't think helps performance, especially during lesson changeover and 1500 devices all move round the building. 
  • It also does all our intervlan routing - Yes I could move that to the core, however I like the ability to have full control over east-west traffic, and it's easier than doing switch ACLs. 

 

Moving forward:

  • We need a network level filter for BYOD/guest and can't rely on a on-device agent only
  • Smoothwall is another option, however it seems like a great filtering product but the firewall doesn't match a dedicated Sophos/Fortinet 
  • We could retain the Opendium filtering and move the firewall to something else
  • If we had a separate firewall and filtering would I then need to deploy 2 SSL certs to every device? 
  • The UniFi EFG looks interesting, however I'm not sure how well it would work for us. 
  • Any reason a pfSense/Opnsense firewall would be a really bad idea, providing we had the support for it?
  • I haven't used Fortinet/Watchguard/Palo Alto

 

I've already had a quote from Wave9 for a pair of Sophos XGS and Smoothwall filter, but we had a bad experience with the old Sophos XG around 5>6 years ago which puts me off a little... 

 

Does anyone have any suggestions on other options we could look at or things to avoid?

 

Thanks! 

Posted

It's a bit out there, but if your considering upgrading your intenrnet, have you considered pushing the webfiltering to the ISP and then just running a firewall on-site?

Posted

We have recently moved to the setup you describe from Wave9 - Sophos XGS in HA + Smoothwall Filter in HA (On prem box for BYOD/Guest and Browser Extension for managed devices)

 

We are essentially double filtering - so 2 SSL certs for managed devices. The Sophos has a constant very basic filter which covers the basic required categories then we push traffic through the smoothwall box/client for more advanced filtering so even networks such as our IoT VLAN (which we don't push through the smoothwall on prem) get basic KCSIE level filtering.

 

You can auth your BYOD users through Entra SSO on the smoothwall SSL landing page - although we have not set this up yet. 

 

 

Posted

@DWilson1997 Sounds like this might be the path we take. I suppose we could push guest traffic through the Sophos filter for a basic level of filtering and redirect all other traffic to the Smoothwall. If we weren't doing much/any filtering on the Sophos, then I don't think we'd need the Sophos SSL cert on client devices. It's bad enough trying to manage 1 cert! I'm not sure if having two certs and potentially decrypting and re-encrypting twice would cause any performance issues. 

 

Do you do 802.1X/RADIUS for wireless devices? 

Posted

@geohanson It is fairly new but works well for us. We pass guest traffic through the smoothwall and apply student level filtering using Ident by location - same as BYOD. We don't do the certs for guests as it would be too complicated given the number of connections per day! 

 

We don't use 802.1X at the moment - we're waiting for Cisco Access Manager to be released in GA before looking at options as we don't have local AD.

Posted (edited)

I would recommend looking at Smoothwall Firewall.
As far as I know, it lacks nothing that a school needs..
Good Layer 7 app control and Geoblocking etc.
If you have a higher bandwidth than 10 Gbit/s, it works to run in your own hardware.


Then Smoothwall Cloud Filter is also included, which then relieves the firewall...

You run your own Smoothwall browser on the iPad's, which actually works really well.


It is also possible to use Smoothwall Firewall as a Core Switch with authorization control for the different networks.

Edited by Joeloman
Posted

@psydii Our iPad filtering just works over 802.1X - Users sign in to the WiFi with their AD credentials and everything is logged within the Opendium UTM. I believe there is a WPAD file which pushes anything to the web proxy within the UTM. There is a basic level of filtering applied to the iPads through Jamf and Apples own content filtering. We've had the discussion about full offsite filtering/monitoring for iPads, however, the school is happy with the current setup and the workload increase would not be manageable by the safeguarding team. Parents are made aware of this as part of our 1-to-1 scheme. 

  • Thanks 1
Posted (edited)
Quote

Our Apple Caching servers are definitely saving our connection at the moment!

Can you elaborate on this?

Are you using a 3rd party solution like cachebox (https://www.appliansys.com/cachebox/)? or do you have a dedicated "homemade" linux server like squidproxy/cache?

Do you do this only for updates? Microsoft and apple? or for youtube videos as well?

Thanks

Edited by skywalkergr
Posted

My obvious bias aside, in my view schools shouldn't be using any firewall that isn't enterprise class with a solid background in security from a reputable specialist vendor.  

Posted
6 hours ago, skywalkergr said:

Can you elaborate on this?

Are you using a 3rd party solution like cachebox (https://www.appliansys.com/cachebox/)? or do you have a dedicated "homemade" linux server like squidproxy/cache?

Do you do this only for updates? Microsoft and apple? or for youtube videos as well?

Thanks

Just using the content caching service on a pair of Mac Minis. They cache all MacOS and iOS updates and App Store downloads. Saves us around 6TB of download data per month.  

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...