Jump to content

SchoolsBroadband

Sponsor
  • Posts

    1,450
  • Joined

Everything posted by SchoolsBroadband

  1. Hi folks. We've a case open with Netsweeper on this atm. This isn't affecting everyone but is a top priority. Thanks Dave
  2. The only thing we can initially do is to contact the ISP rejecting mail from our IPs and understand why we are on a block list they are using. Once they tell us who they get the block list from then we'll contact that block list provider and essentially argue with them that we shouldn't be blocked. This does happen now and again. It sometimes happens when a customer has a compromised machine that has been dishing out lots of spam and then gets an IP block automatically banned because of it. It might be that the receiver has banned a range an IP resides in our of our netblocks or is actually just a single IP. Sometimes block lists are over sensitive and false positives do occur. This is though down to the blocklist and the mail providers which then use said blocklists. This will I'm sure be with our NOC team to progress. If you'd like to pass me on the case ID i'll see where the team is at with it. It may be that we are waiting to hear from the recipient still. There is generally no quick fix we can do as we have to wait for the other party to unblock us. @chaplic also makes a good point as well. Thanks Dave
  3. Maybe double check they haven't given you a price for a 1Gbps / 1Gbps rather than a 1Gbps / 10Gbps by mistake? As there is a large price difference between the two variants. Dave
  4. It should be easy for Expo-E to give you a couple more IP addresses and make it to a /30. You might have to pay for them but it shouldn't be much
  5. within a number of seconds yes. You can monitor policies via the CLI or use FortiAnalyzer or our hosted Incident Management Platform where logs are exported to these cloud based reporting tools. You can then run whatever reports you want on the data that has just entered the data lake which takes a matter of seconds to be able to be reported on. Dave
  6. Have you definitely put logging on the policy the traffic is hitting on the FortiGate? I'd highly recommend doing this and debugging from there. I've also seen issues with MTU size where this happens although it'd be more frequent than just a single site.... Cheers Dave
  7. Yes. The default solution is using Forticlient endpoint protection which puts web filtering essentially on the endpoint. You can also support it by doing a remote dialing Vpn and applying filtering policies to that. Dave
  8. Hello, as you know we're a massive fan of FortiGates having partnered with them for circa a decade. As standard FortiGates don't come with much reporting. You need to buy one of the different variants of FortiAnalyzer which is cloud based, VM based for physical appliance. I'd recommend the VM based one although they're a touch pricey. You can use FastVue as an addition which i think is currently VM based although I've heard rumours they're also offering a cloud based service. Finally we've also developed our own Incident Manager Platform which can sit on top of Netsweeper or FortiGate (more firewalls to come later) and provide real time alerting and reporting for safeguarding incidents. It's currently FOC for customers using our connectivity but can be purchased as an annual cloud based subscription for schools using other connectivity and onsite FortiGates. See https://www.schoolsbroadband.co.uk/our-services/safeguarding-filtering-and-security/safeguarding-management/ It can even integrate with Teams too for immediate safeguarding alerts which has had some pretty good feedback from customers. Thanks Dave
  9. well if its a BT Openreach FTTP you can have a 1000/115 FTTP for much less than your leased line Dave
  10. So long as its the national Gigabit programme for Schools and not a local LFFN programme then the DFE will pay for the installation of FTTP (normally BT but not always). The carrier *MUST* offer the network wholesale to ISPs (such as ourselves) so you can then choose whichever ISP you want to who can then deliver the service over the carriers infrastructure. Hope that's helpful? Thanks Dave
  11. Hi Stuart, we do offering full firewall logging as part of our Analytics package which is in addition to the UTM package. This is known as FortiAnalyzer and is a simple bolt-on to the current package. This is how FortiGate firewalls log and analyze data and is not unique to us. There's also 3rd party products such as FastVue which also do the same. Other than that I think we can also send all logs from a single VDOM / virtual firewall to any syslog server you require. We find that 99% of customers do not wish to buy FortiAnalyzer as its an increased cost most don't value enough. It is thought available to anyone that wants it. If you haven't been offered this then please do let me know and I'll get someone to discuss with you. You can tailor which data you want to log and which you don't (otherwise disks can get full very quickly) We store all of our Netsweeper filtering logs for 2 years currently which is separate to firewall logs. Thanks Dave
  12. Hi @Zammo, we find its split as follows Primary Schools FTTP (if available) or Leased Line with 4G / 5G or FTTC backup Secondary Schools Leased line with FTTP or FTTC backup and dual router. 99% of the +2,000 schools that use our service take our co-managed and hosted FortiGate virtual firewall and for filtering either Fortinet or Netsweeper hosted. Both filtering products have their advantage with Netsweeper being more cost effective for off-net filtering in particular via their N-Client rather than Fortinets Forticlient (although this has other advantages such as endpoint protection as its not just a filter client) We're now seeing about 50% of secondary schools taking a 10Gbps bearer rather than a 1Gbps bearer. The added advantage of having the FortiGate in the cloud is that we can create and include a WAN as standard between all of your MATs sites, so a single pane of glass for all security. Likewise its the same for Netsweeper. So no big hardware capex costs and as the boxes are huge (we use the carrier versions) you can put a lot of throughput through them without having to upgrade in the future. We look after some of the largest MATs in the UK and you can procure via direct award on certain frameworks or a mini-competition with our competitors. If you'd like to be put in contact with some of our customers I'll happily pass you on their details. Thanks Dave
  13. I have a similar issue with a new Samsung large monitor I've bought to work with my Dell Windows 11 PC at home. Once in sleep mode a simple move of a mouse won't bring the monitor back on. It can sometimes take up to 2 minutes of bashing keyboard, moving mouse and turning monitor on and off to get the screen back on. Sometimes I even have to unplug the cable too. Nightmare....
  14. User based all the way. FortiGate uses numerous authentication methods. Before you buy make sure it supports the one you need as standard in the firewall. Some third party auth's such as Google will require the additional purchase of FortiAuthenticator. Thanks Dave
  15. You can, but Openreach will get angry and if you've every an issue your ISP will get charged which they'd need to pass on. I'd suggest you let your ISP know and instruct Openreach to move it for you, which they will do but they'll obviously charge for the privilege. Dave
  16. Fortinet will do this for you no problem. You can do boxes on site or if you used an ISP with cloud and virtualised FortiGates (such as our selves) then we could simply VPLS sites together via a single pane of glass for all schools or each school can have its own virtual firewall. Either way you wouldn't need to setup or manage any VPN's using hosted. If you used FortiGates onsite you could use FortiManager to give you a single pane of glass to managed security and filtering policies over your estates of Fortinet Firewalls. You could also use FortiAnalyzer for advanced reporting or our new hosted Incident Management Platform which takes exported Fortinet syslogs in real time and creates real time safeguarding alerts for any pupil or staff member at any site. I'd be more than happy for one of our technical chaps to chat through this if you'd like? We've now over 2,300 schools using FortiGate services so they're very well established in the education market with us. Thanks Dave
  17. We think Fortigates are great. We've been a partner of them for circa 10 years. Yes, they are not education specific filtering solutions BUT if you put a cloud based reporting engine on top of them then its everything you need and more as well as being able to use all of their wonderful firewall technology as well of which they're Gartner market leaders with. We've just launched our new education reporting platform which exports all syslogs from a FortiGate firewall, whether our own hosted cloud based solution or a physical onsite box whether its on our ISP network or not. Check out https://www.schoolsbroadband.co.uk/e-safety-filtering-security/incident-management/ for more info. Also FortiGate firewalls are full virtualisable. They are known in FortiGate language as a Virtual Domain (VDOM). We fully support this and have thousands of customers using them already in our cloud environment. All FortiGate firewalls have the options to use this. All sub 1000 series devices can only have a maximum of 10 VDOMs. Larger boxes can have up to either 250 or 500 VDOMs and there are licences charges to upgrade to more than 10. If you need any further advice do send me a PM, I'd be happy to help. Thanks Dave
  18. FortiGate fully integrates with Azure AD and thus its web filtering functionality. Are you on a recent software version? Is there anything specific the FortiGate can't do for you? Perhaps we could help and give you some pointers as we're a Fortinet partner. Thanks Dave
  19. Hi @mdrabble we're a certified Fortinet partner so can happily quote you for your requirements. Also launched at BETT is our new incident management platform which works in conjunction with FortiGate devices (so no specific need for FortiAnalyzer for reporting and incident management purposes). We'd be more than happy to give you a demo too just send me a PM and I'll get one of out technical consultants to give you a buzz. See https://www.schoolsbroadband.co.uk/e-safety-filtering-security/incident-management/ Thanks Dave
  20. There's a big difference in wholesale costs between 1000/115 and 1000/220 too. That'll certainly have saved your provider a few quid. I know RM use Talk Talk, not sure if they use BT Wholesale or someone else as well to provide FTTP. BT Openreach currently don't offer any higher upload bandwidths than 220Mbps. I suspect they will do when they eventually start to roll out XGS-PON rather than normal GPON. Most altnets (e.g Cityfibre) will offer synchronous FTTP. Id be happy to check if there is an altnet in your area for you? Alliteratively, its leased line or SD-WAN with 2 or more connections Thanks Dave
  21. We highly recommend Fortinet. It does it all at a competitive price whether and onsite device or a virtualised version in our cloud. If you'd like a quote we'd be happy to oblige as official Fortinet partners. Thanks Dave
  22. Might not be specific to a Sophos box but i've seen similar things on other devices with a NAT session timeout setting. Might be worth looking at that and setting to higher if you find its the issue. Good luck Dave
  23. Have you checked the timeout on the filtering solution you use? I've seen it on numerous filtering solutions where if a session is left open (say over night) that it hits an automatic settings that means a new login has to occur to re-authenticate to the authentication service. Can a user still ping the internet or the gateway when they have no Internet connection? That'll help diagnose where there issue is. Thanks Dave
  24. Hi folks, there's no general issues we're aware of. As per my PM's to @Frodo_Baggins and @Alastairb25 please do escalate your issues via the escalation matrix who will take your cases and ensure a more senior engineer takes a look if you're unhappy with our general response. Thanks Dave
  25. I wonder if they blocked outbound and / or inbound dns to the general Internet....
×
×
  • Create New...