-
Posts
535 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Wave9_Lee
-
Telephony Provider Liquidation - What to do next?
Wave9_Lee replied to CHiLL's topic in Internet Related/Filtering/Firewall
That pretty much covers everything (unusual to see SIP and minutes in a lease - normally it's a capital spend tool), so what is the new company trying to sell you? -
Telephony Provider Liquidation - What to do next?
Wave9_Lee replied to CHiLL's topic in Internet Related/Filtering/Firewall
Typically (old school) telephony providers will contract minutes and support, SIP trunks, call plan, software/licencing direct and offload hardware system lease externally where capex is required. This operating model is dying out thankfully, as this situation occurs more than you'd think. In these scenarios, I'm sure there are genuine reasons for the main company to go bust and for the owners/directors to get in touch with their previous customers to hoover up the contracts under a new company (whilst avoiding paying legacy HMRC and other creditors) and many would say they are doing the customer a favour, but it would stick in my throat a bit if I'm honest. Hardware leases are usually pretty tight and difficult to get out of, but worth reviewing your terms in detail. If you're stuck with the LG system for another 2 years, you should be clear what the new 'service contract' is offering you and importantly, for how long. If it's SIP and minutes, these should be available anywhere at inclusive rates, as I'm sure you're aware. If it's more licence and software, then perhaps calculate what terminating now would cost you over, say, 5 years. For instance, if the new company is only offering a minimum 5 year term for an expensive service, your hardware lease expires in 2028 (any warranty after?), then does cancelling, paying termination, but having a new system for 50/30/20% less work out in the long term. -
Broadband, Filter, Firewalling in 2026
Wave9_Lee replied to smarties11's topic in Internet Related/Filtering/Firewall
There is no silver bullet in my view and what suits one school/MAT may not suit another. There are lots of solutions and providers out there, and most will be compliant, but in my view, what counts is what works for your circumstances and if the company providing the service will support you effectively, especially through change. What is the plan ref servers, door access, BMS, cctv, telephony, security, DHCP, VLANs, remote access, multiple sites, hosted services, third party support, etc etc. We tend to offer a co-managed firewall/filter combined service for most schools but my personal view for secondary schools is leaning to more of a hybrid approach as complexity increases. A cloud based filter service, agent on device is fine in many cases and will effectively cater for any off-site requirements too, but we prefer an on-premise enterprise firewall approach for the security element. When configured as HA, with dual, separate (load balanced), internet connections, this will give you a fully compliant service with the added benefit of a base network filter service as a fallback for any unmanaged devices, byod or misconfigured DNS etc. Added benefits are proper network visibility of your LAN and devices/users/applications, remote access, SDWAN, clear audit and ownership, no shared service, and flexibility to change/amend what you like quickly. VPN and prox detection are added insurance for your cloud filter. For smaller schools, with a poor LAN environment, the firewall can even be deployed as a core layer 3 switch, moving the school on a path to VLAN separation and enhanced security profile. Many schools are still operating flat nextworks and VLAN deployment is one of the single biggest things you can do to improve your network security for little cost. This could include routing all internal traffic through the firewall for inspection, not just inbound/outbound. A hosted, multi-tenanted firewall deployment is ok, but I'd want to be satisfied (with evidence) that my main and backup connections are properly diverse, not terminating on firewall or filtering clusters that aren't propery resilient. Too many customers see both their links useless when a suppliers core service falls over. And I'm not sure many 'hosted' providers will allow load-balacning of links to maximise throughput without spending additional money - it creates excess resource demands on core networks/DC that may not be catered for. I'm also not clear on exactly how much visibility of config/changes/patching/users a hosted firewall can give. Back to the support question on hosted services, are you allowed to make unlimited and significant changes to firewall rules, or if reliant on the supplier helpdesk, how much can be done, and how quickly - is the helpdesk responsive. Lots of pros and cons with deployment, happy to chat through any time. -
Telephony Provider Liquidation - What to do next?
Wave9_Lee replied to CHiLL's topic in Internet Related/Filtering/Firewall
This is a 'pre-pack' after liquidation - same owners of both companies. So the new entity does not have any accounts, no trading history etc - what is the service they are asking you to sign up to? -
If any schools in Derbyshire are looking for new provision, we're working closely with DCC to ensure a smooth transition. Drop me a PM or reach out if you'd like information,
-
It's a quirk of the reseller ecosystem that you should probably have an idea of your main preferred vendor/partner before asking for quotes. The deal registration process means that usually the first company you approach for, say, Meraki, will have the deal registration, meaning they get preferential pricing throughout your process. So if you later decide that Meraki is your preferred option, the first company you approached will get the best price (even if you changed your mind about them through the process)
-
this is a pretty niche issue i think but>> Root cause; "Through the joint investigation we were able to identify an anomaly within our Google configuration linked to pupil accounts that had been set to “change password at next login.” As our pupils authenticate using MyLogin QR codes, this requirement was not visible to the user and therefore was not being surfaced or flagged during the login process. This resulted in repeated authentication attempts from accounts unable to complete the password change requirement, which we believe triggered Google’s automated security and IP reputation controls, leading to the CAPTCHA challenges."
-
Broadband Recommendations
Wave9_Lee replied to 6Foot3's topic in Internet Related/Filtering/Firewall
Hi @alordcharlie drop me a PM or contact me using my signature info if you'd like some pricing/info, happy to help anytime. Thanks all for the recommendations, Lee -
Sophos XGS and VOIP issues Arrrrrgghhh!
Wave9_Lee replied to Jaan's topic in Internet Related/Filtering/Firewall
We don't see any issues when using Sophos XGS with Voip - on the contrary. you already have an allow any rule on you VLAN So to help rule out LAN issues you could configure a port directly on the XGS and plug a phone(s) in and/or during a quiet period, bypass the XGS and plug a phone(s) directly into your ISP router? Do you have a backup connection you could use for elimination purposed? I would advise having a backup connection in any case and particuarly if you have VoiP. -
Happy to provide a quote - drop me a pm if you like? Are you hosting 3cx onsite? cheers
-
@kennysarmy do you have a preferred brand? Might be worth downselecting on that basis initially. If you choose a delivery partner first, they may not support the vendor you prefer, or be able to obtain gold/platinum/price support from the manufacturer. Appreciate it's a bit chicken and egg, budget-wise - but if you have a min-max budget, then this will also exclude some brands.. happy to chat through if you need some advice, cheers
-
Yeah I was surprised it wasn't mentioned on here earier either.. perhaps lots of people had left already. I would assume your novation might be direct to Nasstar, the underlying provider today (previously KCOM) - But I understand there are other services outside of connectivity to consider too.
-
EMPSN is closing it's doors. https://www.empsn.org.uk/service-closure-faq/ Unusually for this type of thing, they've given plenty of warning, so the change for schools shouldn't be too challenging. Needless to say, Wave 9 can offer a replacement set of services - if any schools need some advice or pricing, please reach out.
-
Firewall/Filtering Replacement
Wave9_Lee replied to geohanson's topic in Internet Related/Filtering/Firewall
My obvious bias aside, in my view schools shouldn't be using any firewall that isn't enterprise class with a solid background in security from a reputable specialist vendor. -
No issues with Horizon for us for years - very solid. Could be local network bottlenecks or as mentioned, your internet link - do you configure QOS anywhere? It may not be worth moving before you elimanate any root cause, or you may end up in the same boat. Do dropouts happen at particular times (local load/logon events/patching/updates) etc? Can you get any stats of switches or routers? You could (should) have a backup internet link and use that for your telephony for a period, or permanently. You would then have failover for both your phones and internet requirements. You can also migrate horizon between partners if you're not happy with your supplier. ref 3cx - major hack a couple of years ago put a lot of people off - but my understanding that was windows app related?
-
Which ISP/ Speed / Redundancy do you have?
Wave9_Lee replied to denzal2k4's topic in Internet Related/Filtering/Firewall
In London There are dozens of Alt-nets now, largely funded by your pension money and PE finance, many with flawed business models and questionable viability. Many will go bust, many will be gobbled up. We deal with several of the ones we believe offer a good service and have a sustainable business model (or have a network that will be valuable to someone if the worst happens) I'd guess there's less than 20 that will survive in some form or other. Check your SLA, contention, security, and make sure you know how they will connect to your premises - if it's their own fibre, then this will involve civils and disruption. Concern I have in London is that it's probably the worst location in the UK to plan/schedule civils, road closures and traffic management (and wayleaves). They have their place and they are having a good impact on bringing/keeping prices down through competition. As per the subject of this thread, route diversity can be an issue. Community Fibre seem to have a decent offer - they now provide backup for LGFL network in london I believe. But I'm not sure how building more connectivity in London where the streets are paved with fibre will be sustainable in the long-term. -
Which ISP/ Speed / Redundancy do you have?
Wave9_Lee replied to denzal2k4's topic in Internet Related/Filtering/Firewall
Apart from the DFE standards stating that you should be having resilence, if you did a simple risk matrix for your internet service going down, it simply doesn't make sense not to have a backup connection. If you look at the impact of the internet going down, and the option to get a backup connection for less than £1k per annum, it's a simple decision. Clearly budgetary factors apply and you have local telecom availability to factor in but I think we come across maybe <1% of schools that couldn't get either a decent 4/5G or SOGEA connection. Where is your firewall/filtering provided? If separate from your ISP (i.e. agent based or local appliances/firewalls) then you have a few options. If provided by your ISP (i.e. hosted by them) then you may have slightly less. Others have asked what the £600 includes, but if it's just internet, then if you are anywhere near the end of your current term, you should be looking to replace that, add resilence and still save money. In fact, unless you are particularly rural, or in an anomolous area, you should be able to get a 10Gbps connection for around what you're currently paying. Due to the increased prevalence of alt-nets (ITS, Cityfibre, etc) this list is not exhaustive. Resilience options in descending bandwidth and cost order: 2 x leased lines RO2 - guaranteed diverse delivery, different ducts, different exchanges, same ISP, so physical diversity but not L3 £££££ 99.999% 2 x leased lines - 2 providers (i.e. 1 x openreach + 1 x VMB/alt-net) different fibres, different ducts, different ISP (if not hosted fw/filter) L2 and L3 diversity ££££ 2 x leased line - 2 openreach providers (ie not alt-net available), different exchanges, same duct for part of the last mile, different ISP, part L2 diversity, L3 diversity ££££ 1 x leased line + FttP/SOGEA/5G - mostly different infrastructure, different ISP L2 and L3 diverse £££ 2 x FttP ideally different ISP, shared fibre/duct and exchange ££ FttP + 5G (SOGEA is not available where FttP is enabled) ££ There are various tunes that can be played (i.e. starlink, alt-nets) Leased Line and FttP are available with a 6 hour fix target SLA, although leased line is typically more 'robust'. In reality they both hardly ever fail. 5G doesn't have an SLA. You can see that the top section is mostly large secondary schools, perhaps hosting core services for a Trust, healthy budget. I think the last 3 options are the most commonly deployed. Worth mentioning that if you have your firewall and/or filtering hosted by the same provider as the connectivity, you should satisfy yourself that the hosted service is itself diverse, resilient, especially if you have multiple Trust schools on the same service. -
You'll only be able to keep your SOGEA connection for a short period once FttP becomes available fyi - will be stopsell from that exchange and existing services decommissioned eventually. The Openreach engineer you get is often a bit of a lottery as many engineers are sub-contracted (i.e. Kellys etc) and more suited to consumer, many OR engineers not trained up on FttP etc. Openreach have increased install prices to differentiate the service and 'add some value' for commercial/education installs, and are training up more engineers so should improve. Ref FttP resilience, best you can do currently is utilise 2 separate ISPs for 2 FttP connections - not brilliant physical separacy, but you will have some L3 diversity. Bear in mind Openreach were charging sun £200 for install, so you get what you pay for. Openreach also keep evolving the offer (evolving is the marketing term for changing their mind), so they used to install an ONT for each new FttP (costly but slightly more resilence) and now usually install a multiport ONT for FttP so second and third lines can be added easily (cheaper/quicker long term, but less on-prem resilience) - although this is also a lottery.. Given the critical nature of Internet for schools, Leased line still has a place in the market - uncontended, symmetrical, low latency and guaranteed physical separacy for those that need/can afford it. In my mind, for larger schools, lease line with fttp backup, in active-active and via alternate ISPs is pretty optimum. Key thing is choose a supplier who offers a good level of project management and proactive comms who will go to bat for you.
-
Backup Internet Connection
Wave9_Lee replied to JonnyAlpha's topic in Internet Related/Filtering/Firewall
Assuming you have local firewall/filtering or true cloud, it's fine to go direct with a backup connection, but just be aware of some of the pros and cons. We provide a backup connection using premium wholesale services with low contention or prioritised traffic. We include project management for installation - (increasingly important for FttP as schools are now classified as business premises with an uplifted installation charge, as well as varying levels of installation services excluded) In addition we offer enhanced support (20 hour fix) or critical support (6 hour fix) which attracts a premium price. We can ensure, as per DFE guidelines that the main and backup connection are using differnet technologies and importantly, ISP nodes (not much of a backup if both links ternminate in the same locations/pops/DCs). In addition, there is the benefit of one help desk for both connections, (and firewall/filtering if taken), one bill and relationship. No need for credit card or direct debit. Management of failover and load-balancing is in our scope so you have end-to-end service wrap. SLA to cover all elements and pro-active 24x7 monitoring. Onshore support with direct access to 2nd/3rd line engineer. Like many products/services, the reason for price differences become evident when something goes wrong : ) Caveat emptor! -
On-Premise firewall alternative
Wave9_Lee replied to discoveranother's topic in Internet Related/Filtering/Firewall
You presume wrong! : ) Agree ref rules/policies/patching - that's why we have a co-managed service where we ensure that best practice is followed, whilst providing flexibility for customers. -
On-Premise firewall alternative
Wave9_Lee replied to discoveranother's topic in Internet Related/Filtering/Firewall
I think regardless of the size or site, a fully featured firewall (UTM) is a must to be honest. I'd argue that smaller schools sometimes more so, given constraints on resources, tech etc. As a Sophos Platinum partner I'd obviously advocate for a Sophos solution (Enterprise class, industry leading etc) - usually for both firewall and filter. But if you prefer to filter using something else, then I'd still advocate for a separate, Next Gen firewall with a good security ecosystem and support. I think that the demarcation and risks/benefits between security/filtering/monitoring/reporting etc require careful consideration these days, and increasingly so.. As an aside, customers using our managed service typically see costs come down on renewal
