Jump to content

Recommended Posts

Posted

We've been with emPSN for our broadband for many years, with the filtering done on prem with a SmoothWall physical box. We also have a 1gbps FTTP backup line (local provider to our area, not OR) which we manually connect to the SmoothWall on the (very many) occasions emPSN have let us down. emPSN are closing in October, and by coincidence this is when our SmoothWall contract ends too. We have been happy with SmoothWall and would happily stay with them IF that's the best solution.

 

My question is, what does the BEST broadband, filter and firewall setup look like in 2026?

 

Our key requirements are:

 

- load balancing / failover of a new leased line and existing FTTP backup

- user level filtering on BYOD (as we do currently with SmoothWall)

- as cyber resilient as possible

- current generation modern filtering

 

We've contacted a couple of companies already - the solutions are very diverse across companies from fully managed service (in their own DCs) to on-prem firewall and filter.

 

My key concerns are:

 

- is the SmoothWall S6 a good enough firewall for a wires only leased line / existing FTTP?

- Using a managed service with the infrastructure in their DCs is a SPOF should they have issues (as emPSN often do)

- I fear that cloud based filters are going to be easy to bypass with VPNs and present challenges for user level BYOD

- do Schools who connect directly to the Internet from their site see more issues with cyber attacks, DDOS etc than those who route through a managed service / JANET

 

What would you do?

 

Thanks!

Posted (edited)

My own take on this:

 

- Whether the S6 (edit: I don't think the S6 exists so guessing that is a typo? Possibly you mean the S5) is good enough depends on how many users are at the school. Different models are built for different capacity. They will all provide the necessary filtering though.

 

- RE managed service infrastructure single point of failure: this is only an issue if the datacentre itself isn't built with redundancy in mind. They can have multiple network links to the datacentre and multiple physical hosts for example.

 

- Cloud based filter effectiveness depends on whether you own the devices it is deployed on. If you own the devices, you can go to town with InTune/group policy to make up for any shortcomings of the cloud filter software. If you don't own the devices, ultimately you can only do so much.

 

- From my own experience, moving from JANET to a direct access line many years ago didn't make any difference with cyber attacks. It did expose some bad server configuration that had been masked by the old setup though...

 

JANET would definitely help protect against DDoS. I can't see many schools being targeted by any serious DDoS attack though, since it is costly to run them and most of those bad actors are motivated by money. There are more tempting targets for them...

Edited by ChetterHummin
clarification on smoothwall model
Posted

Thanks @ChetterHummin!

 

Apologies, it's an S10 we have. I don't know why I put S6, I can't even use the typo excuse......😂 Obviously we have this already so it does make sense to continue with it in many ways, where it can operate as a firewall and is capable of load balancing the two lines. I just wasn't sure how strong it performs as firewall, when compared to for example a FortiGate?

 

Infrastructure wise, we've probably been stung by our emPSN experiences. In the last three years, their service has been down probably 7 or 8 times, and every time it's been because of an issue in their datacentre, affecting all customers, rather than line issues. Also aware of the issues that SchoolsBroadband faced recently - again, DC issues that affected all customers. So I suppose in my brain a solution where the backup line is as diverse as possible from the main line makes sense!

 

 

  • Like 1
Posted

FortiGates are stronger performers for pure firewall features, such as timed policies. Smoothwalls can have timed web filter policies, but not actual firewall policies. Unless you have specific circumstances though, the Smoothwall firewall features should do all that you need.

 

What you want to consider is are you happy with the reporting, ease of navigating/amending the filtering, how well the system performs under typical load...

Posted (edited)

Smoothwall can load balance automatically, or do a straight failover. If you can get lines only, then you can go straight into a Smoothwall for both.

 

if you want throughput the + models of appliances come with 25GB SFP ports. 
 

Something to keep in mind is that with the deployment of Smoothwall Cloud, the onpremise box has a lot less filtering to do, and so is mainly acting as the firewall. 
 

one of the benefits I always find with Smoothwall is if you change broadband provider, you don’t have to start again with filtering. 
 

my experience of cloud hosted platforms has not been great, and a lot more prone to failures. Obviously you can’t control it.

 

you can also do Smoothwall in failover - if you want total piece of mind. 

Edited by ConceroEdu_Matt
Posted

A reminder that Smoothwall offers hybrid filtering - including doing reports in the cloud which puts less stress on hardware.

There's no edu vendor but Smoothwall that matches your requirement, you'd likely need an edu filter plus a-n-other firewall. 

 

Happy to talk through what we can offer at some point, drop me a DM and I can take you through all our latest fun developments 

Posted

There is no silver bullet in my view and what suits one school/MAT may not suit another.  There are lots of solutions and providers out there, and most will be compliant, but in my view, what counts is what works for your circumstances and if the company providing the service will support you effectively, especially through change.   What is the plan ref servers, door access, BMS, cctv, telephony, security, DHCP, VLANs, remote access, multiple sites, hosted services, third party support, etc etc.

 

We tend to offer a co-managed firewall/filter combined service for most schools but my personal view for secondary schools is leaning to more of a hybrid approach as complexity increases.  A cloud based filter service, agent on device is fine in many cases and will effectively cater for any off-site requirements too, but we prefer an on-premise enterprise firewall approach for the security element.  When configured as HA, with dual, separate (load balanced), internet connections, this will give you a fully compliant service with the added benefit of a base network filter service as a fallback for any unmanaged devices, byod or misconfigured DNS etc.  Added benefits are proper network visibility of your LAN and devices/users/applications, remote access, SDWAN, clear audit and ownership, no shared service, and flexibility to change/amend what you like quickly.  VPN and prox detection are added insurance for your cloud filter.  For smaller schools, with a poor LAN environment, the firewall can even be deployed as a core layer 3 switch, moving the school on a path to VLAN separation and enhanced security profile.  Many schools are still operating flat nextworks and VLAN deployment is one of the single biggest things you can do to improve your network security for little cost.  This could include routing all internal traffic through the firewall for inspection, not just inbound/outbound.

 

A hosted, multi-tenanted firewall deployment is ok, but I'd want to be satisfied (with evidence) that my main and backup connections are properly diverse, not terminating on firewall or filtering clusters that aren't propery resilient.  Too many customers see both their links useless when a suppliers core service falls over. And I'm not sure many 'hosted' providers will allow load-balacning of links to maximise throughput without spending additional money - it creates excess resource demands on core networks/DC that may not be catered for.   I'm also not clear on exactly how much visibility of config/changes/patching/users a hosted firewall can give.  

 

Back to the support question on hosted services, are you allowed to make unlimited and significant changes to firewall rules, or if reliant on the supplier helpdesk, how much can be done, and how quickly - is the helpdesk responsive.

 

Lots of pros and cons with deployment, happy to chat through any time.

 

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...