Jump to content

Recommended Posts

Posted

Hey Everyone,

 

I work at a UK college that offers residency for the students and we currently have a crazy setup which is being effectively stripped out and started again.

 

The current system involves a forefront's threat management gateway as the firewall solution and if i'm honest it's a right headache and isn't really a solution for a college.

 

What we want is a solution that future proofs us and is well supported, ideally with a company that knows the education sector.

 

The main contenders are obviously smoothwall and sonicwall. I've looked into others like watchguard but thats too enterprise for us, trying to keep it realistic. I've seen Netbox blue the "firewall solution designed for schools" but was a little unsure about it, doesn't seem to be much UK support.

 

What we need it to do is:

 

  • Act as a middle man between clients and servers (protecting the servers from the kids who call themselves hackers).
  • Protect the Servers and Clients from the big bad internet
  • Allow for both a domain network and a "leisure network". The leisure network acting as a lesser filtered internet experience. We offer residency to students, so xbox live, skype, games etc are common requests.
  • To be able to control what times the leisure/domain network can be accessed etc..
  • Some form of indepth report, what students are up to, logging in times, general web filtering/policing
  • Some form of policing of social networking websites
  • Full Active Directory Syncing (aware of security groups etc)
  • Support for mobile devices (PDA's, SmartPhones)
  • Capable of managing a DMZ for Exchange OWA/Outlook Anywhere
  • Managing secure VPN connections into the college.

 

When it comes to the firewall, I'm not the most experienced if i'm honest, I have a lot to look at and plenty to read up on. I am in talks with colleges around the local area about possibly visiting them to see their solutions, as it's easy to talk to a salesman from a firewall company, but the word yes yes yes is easily said but when its comes to the technical nitty gritty, you find that some yes's mean "sort of".

 

The firewall is now becoming the most important decision we need to make, as everything needs to connect through it.

 

I'm interested into what you all have seen, work(ed) with, don't think because you don't offer residential to students (as i know not many places do) that you can't recommend something.

 

I'm looking for simplicity mainly, but obviously if the company's offer training on their product, that's even better.

 

The big word is also cost, ball park figures are always welcome, we are expecting lots of money so it won't be anything we didn't expect.

 

Thanks for all your help!

 

Looking forward to hearing from you all.

Posted (edited)

Pretty Sure a nice Smoothie UTM will do all that - @tom_newton is your person to get in contact with. Brilliant devices and excellent support.

 

Plus top blokes!

 

EDIT: Price depends on what you want such as at the gateway Anti-virus, HA setup, Spam Filtering etc Smoothwall will also do Instant Messaging Proxying as well i beleive al though I have never used this.

Edited by glennda
  • Thanks 1
Posted (edited)

@glennda - I'll be getting in touch with Tom, thanks for the info.

@psydii - That Fastvue look quite impressive, we'll certainly have a look at that. Since we already have TMG, if it can be improved, it'll save the cash.

@FN-GM - I've heard some pretty awful things about sonicwall recently, I wasn't too impressed at BETT, Sales people tell you anything you want to here, though he stumbled when I asked why go for sonicwall over smoothwall.

Edited by DEvans
Posted

The filtering is by far one of the most important requirements of our solution. We need to have potentially three levels of filtering. One for Staff, One for Students during work time an one for the leisure network for students after hours. Don't want those hiding in their rooms playing the xbox all day.

 

Unfortunately if Sonicwall doesn't perform that well, then obviously we won't be going that way. I don't want to mix and match firewalls, ideally one solution, one supplier, one support contract.

 

Thanks for the info

Posted

Tips for TMG:

Keep it up to date (Rollup 2 for Forefront Threat Management Gateway (TMG) 2010 Service Pack 2)

Add your DCs to the Flood Mitigation exceptions.

Make sure you've got your DNS configured right.

If using proxy clients (which you will be) if they are members of the domain make sure they use the FQDN of the TMG to make best use of Kerberos. For large numbers of non domain member computers that require authenticated access to the web you will probably need to monitor the load on the associated DC as they or TMG may struggle to keep up with all the NTLM requests. A way around this might be to authenticate at a captive portal and log the IP, or perhaps use RADIUS authentication for proxy clients in TMG.

Posted
The filtering is by far one of the most important requirements of our solution. We need to have potentially three levels of filtering. One for Staff, One for Students during work time an one for the leisure network for students after hours. Don't want those hiding in their rooms playing the xbox all day.

 

Unfortunately if Sonicwall doesn't perform that well, then obviously we won't be going that way. I don't want to mix and match firewalls, ideally one solution, one supplier, one support contract.

 

Thanks for the info

 

For Filtering Smoothwall is Top Dog. It can do filtering on what, When, who, Where filtering so filtering can be set up like that.

  • Thanks 1
Posted
I would recommend Watchguard but you have knocked them on the head. It will easily do all that and maybe its me been biased but they are good bits of kit and simple.
Posted
I would recommend Watchguard but you have knocked them on the head. It will easily do all that and maybe its me been biased but they are good bits of kit and simple.

 

Watchguards are good but not up to scratch in terms of filtering required for a school - enterprise where filtering isnt a child protection isnt an issue its fine.

Posted
Not too up on the filtering side of things but I was under the impression it went off to a site and pulled blacklists down, don't quote me as filtering isn't a big thing for us.
Posted
Not too up on the filtering side of things but I was under the impression it went off to a site and pulled blacklists down, don't quote me as filtering isn't a big thing for us.

 

yes thats the problem - filtering via blacklists isn't that good on its own - smoothwall uses dynamic content filtering i.e it looks at each webpage and decides if it is ok or not (as well as blacklists for the obvious such as facebook etc).

 

i do lots of work with watchguards (infact i'm installing 2 tomorrow). But for education i wouldn't use them.

Posted
If you want to control traffic at app-level and have the £££ Palo Alto is well worth looking at... not cheap but it's very powerful. Content filtering might not be up to your standards though but seems Smoothwall is the only well-known one that really covers education primarily.
  • 3 weeks later...
Posted

Watchguard have been mentioned quite a bit, but like I said I think it doesn't provide the true needs of a school. Smoothwall does seem to be the ideal solution as their support for schools is also very good.

 

We have looked at a hell of a lot. I just want to have a proper big brother of the network. Who did what, when and what computer.

 

Sounds like a silly question but can smoothwall also monitor internal Exchange emails. We have Exchange 2007 (going to 2010 soon) and it's all well and good monitoring what comes from the outside world, but bullyinging etc occurs internally and we want the evidence to help crack down and punished the right students over situations like this.

Posted
Not internal mail but if you get something like impero/securus that will do client side monitoring and take screen shots of offending material.
  • Thanks 1
Posted (edited)

We use Sonicwall as the primary firewall and can't sing it's praises high enough.

The VLan support allows it to segregate all physical and logical segments at the firewall creating access rules for each interface as needed.

The detail and granularity of control seems to do everything we throw at it and personally I find it incredibly easy to understand and the application and bandwidth control features are really good however, I have to agree that the content filtering system and more importantly it's management is not as easy to control or manage as other solutions.

 

The Sonicwall relies on a rather annoying agent/service for AD integration and getting it to deliver the correct group membership and ultimately the correct level of filtering to the end user takes a lot of careful planning.

Users inherit content filtering policies based upon AD Group membership, the default policy is and should remain the strictest policy you create alternative policies and link these to your AD groups.

Sounds easy until the agents suddenly stop working and everybody suddenly inherits the strictest policy with the resulting Helpdesk calls to say teachers cannot reach their hotmail or YouTube!

 

Which is probably why Sonicwall offer integration with Websense Enterprise Appliances!

 

Given the choice personally I would always go with the Sonicwall as my firewall and UTM device as you can't get away from the fact that it is what it is, a Firewall device first with a content filtering option!

If filtering however is your primary requirement then maybe the smoothwall is your better option or an inline cache/filter appliance.

Edited by m25man
  • Thanks 1
Posted (edited)

Yes we have a lot of fun and games with Sonicwall(we have E5500) Looked after by our ISP but recently getting more involved with settings etc. agreed that Content filtering not it's strongest point(keyword blocking being weak point, very limited)

 

As a Firewall it just works. We will be installing Lightspeed Bottle Rocket Filtering device to take over CFS when we go BYOD.

Edited by MrWu
Posted
Not internal mail but if you get something like impero/securus that will do client side monitoring and take screen shots of offending material.

 

Interesting. I have heard of screen capturing software, another one that is used in our county is Policy Central by Forensic. I like the overall Idea of them, but the maintenance is a nightmare with so many false positives. Takes a long time to fine tune it, though I haven't played with those mentioned above, i'll have a look into it.

 

I suppose with the ability to prevent attachment types etc within Exchange itself, there is little need for an firewall to monitor internal mail. I'm thinking too much e-safety and not network security.

 

Thanks for the info.

Posted
Interesting. I have heard of screen capturing software, another one that is used in our county is Policy Central by Forensic. I like the overall Idea of them, but the maintenance is a nightmare with so many false positives. Takes a long time to fine tune it, though I haven't played with those mentioned above, i'll have a look into it.

 

I suppose with the ability to prevent attachment types etc within Exchange itself, there is little need for an firewall to monitor internal mail. I'm thinking too much e-safety and not network security.

 

Thanks for the info.

 

Problem with anything looking for key words in always going to be false positives i'm afraid. Until a computer can work out contexts around what is being said. At my last place the most "at risk user" for about 5 months was the business manager as she was arranging lots of meetings! and phrases like I'll meet you etc etc.

 

You could do a basic set of rules like the above inside exchange with transport rules and have them BCC'd to a mailbox but it would be a nightmare to keep up to date and monitor.

Posted

Hi, the College I work at also has a Halls of Residence and we use a Smoothwall UTM-3000 box to handle all our filtering/firewall needs - will do everything on your list.

 

We've had the UTM-3000 in for about 7 months now and haven't had a single problem with it, the UTM-3000 has 6 network cards (which are VLAN capable), with our current setup we've got them plugged into our JANET router, one into a backup broadband line, DMZ, LAN and guest/halls wireless.

 

We basically run the halls of residence wireless as an untrusted zone and allow it access to services in our DMZ - which are the same services other students can access from home.

 

Biggest issue we get frm our residents is high bandwidth applications (ipalyer etc...) we bought the traffic shapping module for Smoothwall but haven;t implemented it yet - planned for the summer, along with a second UTM-3000 box to give us active/passive hardware failover.

Posted

Thanks CScott,

 

Good to hear someone in a similar (if not identical) situation.

 

Thanks everyone on your opinions, i've got a call coming my way this morning from Sean Lazenby at Smoothwall, looks pretty clear on what is the overall best solution for our situation.

 

Much Appreciated!

 

/Dan

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...