SchoolsBroadband
Sponsor-
Posts
1,450 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by SchoolsBroadband
-
We're on a blacklist and can't get off!
SchoolsBroadband replied to Jawloms's topic in Internet Related/Filtering/Firewall
The only thing we can initially do is to contact the ISP rejecting mail from our IPs and understand why we are on a block list they are using. Once they tell us who they get the block list from then we'll contact that block list provider and essentially argue with them that we shouldn't be blocked. This does happen now and again. It sometimes happens when a customer has a compromised machine that has been dishing out lots of spam and then gets an IP block automatically banned because of it. It might be that the receiver has banned a range an IP resides in our of our netblocks or is actually just a single IP. Sometimes block lists are over sensitive and false positives do occur. This is though down to the blocklist and the mail providers which then use said blocklists. This will I'm sure be with our NOC team to progress. If you'd like to pass me on the case ID i'll see where the team is at with it. It may be that we are waiting to hear from the recipient still. There is generally no quick fix we can do as we have to wait for the other party to unblock us. @chaplic also makes a good point as well. Thanks Dave -
Anyone head of this ISP supplier
SchoolsBroadband replied to mdrabble's topic in Internet Related/Filtering/Firewall
Maybe double check they haven't given you a price for a 1Gbps / 1Gbps rather than a 1Gbps / 10Gbps by mistake? As there is a large price difference between the two variants. Dave -
Smoothwall and ISP with /31 subnet
SchoolsBroadband replied to mikeglover's topic in Internet Related/Filtering/Firewall
It should be easy for Expo-E to give you a couple more IP addresses and make it to a /30. You might have to pay for them but it shouldn't be much -
Cyber Explorers nightmare
SchoolsBroadband replied to Techie-Tech's topic in Internet Related/Filtering/Firewall
within a number of seconds yes. You can monitor policies via the CLI or use FortiAnalyzer or our hosted Incident Management Platform where logs are exported to these cloud based reporting tools. You can then run whatever reports you want on the data that has just entered the data lake which takes a matter of seconds to be able to be reported on. Dave -
Cyber Explorers nightmare
SchoolsBroadband replied to Techie-Tech's topic in Internet Related/Filtering/Firewall
Have you definitely put logging on the policy the traffic is hitting on the FortiGate? I'd highly recommend doing this and debugging from there. I've also seen issues with MTU size where this happens although it'd be more frequent than just a single site.... Cheers Dave -
Fortinet echo system - your opinions
SchoolsBroadband replied to mdrabble's topic in Internet Related/Filtering/Firewall
Yes. The default solution is using Forticlient endpoint protection which puts web filtering essentially on the endpoint. You can also support it by doing a remote dialing Vpn and applying filtering policies to that. Dave -
Fortinet echo system - your opinions
SchoolsBroadband replied to mdrabble's topic in Internet Related/Filtering/Firewall
Hello, as you know we're a massive fan of FortiGates having partnered with them for circa a decade. As standard FortiGates don't come with much reporting. You need to buy one of the different variants of FortiAnalyzer which is cloud based, VM based for physical appliance. I'd recommend the VM based one although they're a touch pricey. You can use FastVue as an addition which i think is currently VM based although I've heard rumours they're also offering a cloud based service. Finally we've also developed our own Incident Manager Platform which can sit on top of Netsweeper or FortiGate (more firewalls to come later) and provide real time alerting and reporting for safeguarding incidents. It's currently FOC for customers using our connectivity but can be purchased as an annual cloud based subscription for schools using other connectivity and onsite FortiGates. See https://www.schoolsbroadband.co.uk/our-services/safeguarding-filtering-and-security/safeguarding-management/ It can even integrate with Teams too for immediate safeguarding alerts which has had some pretty good feedback from customers. Thanks Dave -
So long as its the national Gigabit programme for Schools and not a local LFFN programme then the DFE will pay for the installation of FTTP (normally BT but not always). The carrier *MUST* offer the network wholesale to ISPs (such as ourselves) so you can then choose whichever ISP you want to who can then deliver the service over the carriers infrastructure. Hope that's helpful? Thanks Dave
-
Hi Stuart, we do offering full firewall logging as part of our Analytics package which is in addition to the UTM package. This is known as FortiAnalyzer and is a simple bolt-on to the current package. This is how FortiGate firewalls log and analyze data and is not unique to us. There's also 3rd party products such as FastVue which also do the same. Other than that I think we can also send all logs from a single VDOM / virtual firewall to any syslog server you require. We find that 99% of customers do not wish to buy FortiAnalyzer as its an increased cost most don't value enough. It is thought available to anyone that wants it. If you haven't been offered this then please do let me know and I'll get someone to discuss with you. You can tailor which data you want to log and which you don't (otherwise disks can get full very quickly) We store all of our Netsweeper filtering logs for 2 years currently which is separate to firewall logs. Thanks Dave
-
Talk to me about Broadband and Filtering!
SchoolsBroadband replied to Zammo's topic in Internet Related/Filtering/Firewall
Hi @Zammo, we find its split as follows Primary Schools FTTP (if available) or Leased Line with 4G / 5G or FTTC backup Secondary Schools Leased line with FTTP or FTTC backup and dual router. 99% of the +2,000 schools that use our service take our co-managed and hosted FortiGate virtual firewall and for filtering either Fortinet or Netsweeper hosted. Both filtering products have their advantage with Netsweeper being more cost effective for off-net filtering in particular via their N-Client rather than Fortinets Forticlient (although this has other advantages such as endpoint protection as its not just a filter client) We're now seeing about 50% of secondary schools taking a 10Gbps bearer rather than a 1Gbps bearer. The added advantage of having the FortiGate in the cloud is that we can create and include a WAN as standard between all of your MATs sites, so a single pane of glass for all security. Likewise its the same for Netsweeper. So no big hardware capex costs and as the boxes are huge (we use the carrier versions) you can put a lot of throughput through them without having to upgrade in the future. We look after some of the largest MATs in the UK and you can procure via direct award on certain frameworks or a mini-competition with our competitors. If you'd like to be put in contact with some of our customers I'll happily pass you on their details. Thanks Dave -
I have a similar issue with a new Samsung large monitor I've bought to work with my Dell Windows 11 PC at home. Once in sleep mode a simple move of a mouse won't bring the monitor back on. It can sometimes take up to 2 minutes of bashing keyboard, moving mouse and turning monitor on and off to get the screen back on. Sometimes I even have to unplug the cable too. Nightmare....
-
Type of filtering
SchoolsBroadband replied to chekmate1984's topic in Internet Related/Filtering/Firewall
User based all the way. FortiGate uses numerous authentication methods. Before you buy make sure it supports the one you need as standard in the firewall. Some third party auth's such as Google will require the additional purchase of FortiAuthenticator. Thanks Dave -
Extending Lease Line fibre
SchoolsBroadband replied to snagrat's topic in Internet Related/Filtering/Firewall
You can, but Openreach will get angry and if you've every an issue your ISP will get charged which they'd need to pass on. I'd suggest you let your ISP know and instruct Openreach to move it for you, which they will do but they'll obviously charge for the privilege. Dave -
Smoothwall MAT Alternatives
SchoolsBroadband replied to chrisjako's topic in Internet Related/Filtering/Firewall
Fortinet will do this for you no problem. You can do boxes on site or if you used an ISP with cloud and virtualised FortiGates (such as our selves) then we could simply VPLS sites together via a single pane of glass for all schools or each school can have its own virtual firewall. Either way you wouldn't need to setup or manage any VPN's using hosted. If you used FortiGates onsite you could use FortiManager to give you a single pane of glass to managed security and filtering policies over your estates of Fortinet Firewalls. You could also use FortiAnalyzer for advanced reporting or our new hosted Incident Management Platform which takes exported Fortinet syslogs in real time and creates real time safeguarding alerts for any pupil or staff member at any site. I'd be more than happy for one of our technical chaps to chat through this if you'd like? We've now over 2,300 schools using FortiGate services so they're very well established in the education market with us. Thanks Dave -
We think Fortigates are great. We've been a partner of them for circa 10 years. Yes, they are not education specific filtering solutions BUT if you put a cloud based reporting engine on top of them then its everything you need and more as well as being able to use all of their wonderful firewall technology as well of which they're Gartner market leaders with. We've just launched our new education reporting platform which exports all syslogs from a FortiGate firewall, whether our own hosted cloud based solution or a physical onsite box whether its on our ISP network or not. Check out https://www.schoolsbroadband.co.uk/e-safety-filtering-security/incident-management/ for more info. Also FortiGate firewalls are full virtualisable. They are known in FortiGate language as a Virtual Domain (VDOM). We fully support this and have thousands of customers using them already in our cloud environment. All FortiGate firewalls have the options to use this. All sub 1000 series devices can only have a maximum of 10 VDOMs. Larger boxes can have up to either 250 or 500 VDOMs and there are licences charges to upgrade to more than 10. If you need any further advice do send me a PM, I'd be happy to help. Thanks Dave
-
Filtering for schools
SchoolsBroadband replied to cdwyersandysecondary's topic in Internet Related/Filtering/Firewall
FortiGate fully integrates with Azure AD and thus its web filtering functionality. Are you on a recent software version? Is there anything specific the FortiGate can't do for you? Perhaps we could help and give you some pointers as we're a Fortinet partner. Thanks Dave -
Filtering/Firewall quotes
SchoolsBroadband replied to mdrabble's topic in Internet Related/Filtering/Firewall
Hi @mdrabble we're a certified Fortinet partner so can happily quote you for your requirements. Also launched at BETT is our new incident management platform which works in conjunction with FortiGate devices (so no specific need for FortiAnalyzer for reporting and incident management purposes). We'd be more than happy to give you a demo too just send me a PM and I'll get one of out technical consultants to give you a buzz. See https://www.schoolsbroadband.co.uk/e-safety-filtering-security/incident-management/ Thanks Dave -
There's a big difference in wholesale costs between 1000/115 and 1000/220 too. That'll certainly have saved your provider a few quid. I know RM use Talk Talk, not sure if they use BT Wholesale or someone else as well to provide FTTP. BT Openreach currently don't offer any higher upload bandwidths than 220Mbps. I suspect they will do when they eventually start to roll out XGS-PON rather than normal GPON. Most altnets (e.g Cityfibre) will offer synchronous FTTP. Id be happy to check if there is an altnet in your area for you? Alliteratively, its leased line or SD-WAN with 2 or more connections Thanks Dave
-
Replacing On-Prem Sophos
SchoolsBroadband replied to Rob446's topic in Internet Related/Filtering/Firewall
We highly recommend Fortinet. It does it all at a competitive price whether and onsite device or a virtualised version in our cloud. If you'd like a quote we'd be happy to oblige as official Fortinet partners. Thanks Dave -
Might not be specific to a Sophos box but i've seen similar things on other devices with a NAT session timeout setting. Might be worth looking at that and setting to higher if you find its the issue. Good luck Dave
-
Intermittent Internet Issues
SchoolsBroadband replied to faza's topic in Internet Related/Filtering/Firewall
Have you checked the timeout on the filtering solution you use? I've seen it on numerous filtering solutions where if a session is left open (say over night) that it hits an automatic settings that means a new login has to occur to re-authenticate to the authentication service. Can a user still ping the internet or the gateway when they have no Internet connection? That'll help diagnose where there issue is. Thanks Dave -
Internet Issues - Hive mind thunk
SchoolsBroadband replied to TechMonkey's topic in Internet Related/Filtering/Firewall
I wonder if they blocked outbound and / or inbound dns to the general Internet....
