geohanson Posted October 31, 2025 Posted October 31, 2025 Hi all, Looking at potentially replacing firewall/filtering in the next financial year. 1600 students, 200 staff. 1600ish iPads, 60 Macs, 450 Windows PCs, Chromebooks/ChromeFlex PCs, BYOD and everything else you can think of.... Unifi WiFi throughout, with Aruba and UniFi switches Currently running with a 1GB Leased Line with an FTTC backup - Hitting the limits of this especially first thing in the morning. Our Apple Caching servers are definitely saving our connection at the moment! Currently using an Opendium UTM Support is great Filtering is great Reporting is great Firewall side works, but is limited in what I/we can control without going through their support. I think pushing a lot more bandwidth through it (if we moved to a 10G connection) would kill it. It's also doing RADIUS auth for us which I don't think helps performance, especially during lesson changeover and 1500 devices all move round the building. It also does all our intervlan routing - Yes I could move that to the core, however I like the ability to have full control over east-west traffic, and it's easier than doing switch ACLs. Moving forward: We need a network level filter for BYOD/guest and can't rely on a on-device agent only Smoothwall is another option, however it seems like a great filtering product but the firewall doesn't match a dedicated Sophos/Fortinet We could retain the Opendium filtering and move the firewall to something else If we had a separate firewall and filtering would I then need to deploy 2 SSL certs to every device? The UniFi EFG looks interesting, however I'm not sure how well it would work for us. Any reason a pfSense/Opnsense firewall would be a really bad idea, providing we had the support for it? I haven't used Fortinet/Watchguard/Palo Alto I've already had a quote from Wave9 for a pair of Sophos XGS and Smoothwall filter, but we had a bad experience with the old Sophos XG around 5>6 years ago which puts me off a little... Does anyone have any suggestions on other options we could look at or things to avoid? Thanks!
Rob_D Posted October 31, 2025 Posted October 31, 2025 It's a bit out there, but if your considering upgrading your intenrnet, have you considered pushing the webfiltering to the ISP and then just running a firewall on-site?
DWilson1997 Posted October 31, 2025 Posted October 31, 2025 We have recently moved to the setup you describe from Wave9 - Sophos XGS in HA + Smoothwall Filter in HA (On prem box for BYOD/Guest and Browser Extension for managed devices) We are essentially double filtering - so 2 SSL certs for managed devices. The Sophos has a constant very basic filter which covers the basic required categories then we push traffic through the smoothwall box/client for more advanced filtering so even networks such as our IoT VLAN (which we don't push through the smoothwall on prem) get basic KCSIE level filtering. You can auth your BYOD users through Entra SSO on the smoothwall SSL landing page - although we have not set this up yet.
geohanson Posted October 31, 2025 Author Posted October 31, 2025 @DWilson1997 Sounds like this might be the path we take. I suppose we could push guest traffic through the Sophos filter for a basic level of filtering and redirect all other traffic to the Smoothwall. If we weren't doing much/any filtering on the Sophos, then I don't think we'd need the Sophos SSL cert on client devices. It's bad enough trying to manage 1 cert! I'm not sure if having two certs and potentially decrypting and re-encrypting twice would cause any performance issues. Do you do 802.1X/RADIUS for wireless devices?
DWilson1997 Posted October 31, 2025 Posted October 31, 2025 @geohanson It is fairly new but works well for us. We pass guest traffic through the smoothwall and apply student level filtering using Ident by location - same as BYOD. We don't do the certs for guests as it would be too complicated given the number of connections per day! We don't use 802.1X at the moment - we're waiting for Cisco Access Manager to be released in GA before looking at options as we don't have local AD.
Joeloman Posted October 31, 2025 Posted October 31, 2025 (edited) I would recommend looking at Smoothwall Firewall. As far as I know, it lacks nothing that a school needs.. Good Layer 7 app control and Geoblocking etc. If you have a higher bandwidth than 10 Gbit/s, it works to run in your own hardware. Then Smoothwall Cloud Filter is also included, which then relieves the firewall... You run your own Smoothwall browser on the iPad's, which actually works really well. It is also possible to use Smoothwall Firewall as a Core Switch with authorization control for the different networks. Edited October 31, 2025 by Joeloman
geohanson Posted October 31, 2025 Author Posted October 31, 2025 @psydii Our iPad filtering just works over 802.1X - Users sign in to the WiFi with their AD credentials and everything is logged within the Opendium UTM. I believe there is a WPAD file which pushes anything to the web proxy within the UTM. There is a basic level of filtering applied to the iPads through Jamf and Apples own content filtering. We've had the discussion about full offsite filtering/monitoring for iPads, however, the school is happy with the current setup and the workload increase would not be manageable by the safeguarding team. Parents are made aware of this as part of our 1-to-1 scheme. 1
skywalkergr Posted November 3, 2025 Posted November 3, 2025 (edited) Quote Our Apple Caching servers are definitely saving our connection at the moment! Can you elaborate on this? Are you using a 3rd party solution like cachebox (https://www.appliansys.com/cachebox/)? or do you have a dedicated "homemade" linux server like squidproxy/cache? Do you do this only for updates? Microsoft and apple? or for youtube videos as well? Thanks Edited November 3, 2025 by skywalkergr
psydii Posted November 3, 2025 Posted November 3, 2025 https://support.apple.com/en-gb/guide/deployment/depde72e125f/web for (modern) Windows there is delivery optimisation: https://learn.microsoft.com/en-us/windows/deployment/do/waas-optimize-windows-10-updates or the old WSUS of yore. 365 Apps: https://learn.microsoft.com/en-us/microsoft-365-apps/updates/delivery-optimization or the most modern solution: https://petervanderwoude.nl/post/getting-started-with-microsoft-connected-cache/ Finally, for Adobe applications there is the Adobe update server: https://helpx.adobe.com/enterprise/kb/ausst-release-notes.html 1
yac2016 Posted November 3, 2025 Posted November 3, 2025 PFsense for the firewall, then choose a cloud based filter....
Wave9_Lee Posted November 3, 2025 Posted November 3, 2025 My obvious bias aside, in my view schools shouldn't be using any firewall that isn't enterprise class with a solid background in security from a reputable specialist vendor.
geohanson Posted November 3, 2025 Author Posted November 3, 2025 6 hours ago, skywalkergr said: Can you elaborate on this? Are you using a 3rd party solution like cachebox (https://www.appliansys.com/cachebox/)? or do you have a dedicated "homemade" linux server like squidproxy/cache? Do you do this only for updates? Microsoft and apple? or for youtube videos as well? Thanks Just using the content caching service on a pair of Mac Minis. They cache all MacOS and iOS updates and App Store downloads. Saves us around 6TB of download data per month.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now