-
Posts
535 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Wave9_Lee
-
Sophos STAS - dead records
Wave9_Lee replied to neonetman's topic in Internet Related/Filtering/Firewall
You can remove the file entirely - remove the .db file in the stas dir, or you can edit it with an online SQL editor, then pop it back in the dir If you stop the stas service then delete the database file, stas will create a new one when you start the stas service back up again hope that helps -
https://businesscloud.co.uk/leeds-smoothwall-sold-in-75-5m-cash-deal/
-
- 4
-
-
"Or if there's another that I've missed..." Lightspeed are worth a look. I'd be happy to arrange a demo/trial if you'd like - drop me a note anytime regards Lee
-
We can provide a couple of options if needed. One is the device filtering route (Lightspeed) - but you'd ideally need management of the router to prevent other users accessing the internet (i.e. restricting access to only approved devices, by MAC address etc) This is why we used proper 4G routers rather than dongles, for the security and managability. Alternatively, we can provide a SIM with a private APN that uses our hosted Sophos Web-filtering and cannot be bypassed. A managed 4G router is still preferred, to prevent unauthorised use etc.
-
Hi Sheridan, If you'd like any pricing, with or without deployment and support services, please drop me a PM or mail me anytime. cheers
-
I'd vote for Meraki - we have plenty of customers happily using it. Sounds like you already have pricing but if not, happy to help. We also offer a co-managed service whereby we spread the cost of the hardware/licence over a 5 year term and include 3rd line support. This is particularly useful if capital is an issue. Installation and configuration included. cheers
-
I'd be happy to provide some Sophos pricing for you - we can offer this as a supply only, or as a managed service (annual charg, co-managed). Drop me a PM if interested. With 4G backup, just need to be certain that you have the data plan availability when you need it - i.e. if your main link is down, without significant traffic management, you are likely to need 100GBs+ of data. We offer an unlimited data plan on the 4G backup we deploy as resilience for our services for this reason. A consumer 'all you can eat' data SIM will have a 'small print' Fair Use Policy that will actually limit your data.
-
I'd be happy to send you some example pricing, no problem. It depends on the modules you licence and the size of the appliance, but we can generally beat other UTMs for price. You can buy outright or take it as an annual charge and include our co-managed services if preferred, which spreads the cost and gives you additional support resource to call on. Alternatively, as requirements are moving more off-site, we offer a hybrid option with Lighstpeed (cloud/agent) based filtering combined with managed Sophos Firewall. Ref a previous comment, on-prem Sophos is very reliable in our experience, with probably 2 faulty boxes over the last 3 years and 500 customer. Both were replaced either the same day or next day with a pre-configured/built replacement for no charge. An on-premise solution, from a connectivity and UTM point of view, give much more flexibility in my opinion. Both in terms of access to make changes, see network activity, cyber essentials and network security and respond to changing needs, but also in terms of the ISP chosen - it makes you completely ISP agnostic, meaning you can get the best price in the market at that point and not be tied in to a single provider. My two pence!
-
DfE Connecting the Classroom project funding
Wave9_Lee replied to password1234's topic in Wireless Networks
We're supplying schools under this scheme if anyone is interested in a quote for Cisco Meraki. And ref a previous Q - yes Meraki offer a 10 year licence for the price of 5 in education, so not a bad option. We can offer the solution through a single award procurement framework, so you don't necessarily need to go to 3 quotes if that works for you. The specifications are a little overkill, but the people running the program want to get the most future proof solution available and not too concerned that there are more 'cost-effective' options. As is often the case with these kind of programs, they are focussed on delivering the objective, spending the budgets as quickly as possible. -
It's a regular conundrum really. A support company can offer a full-fat support service, with lots of included adds/moves/changes, but also need to protect against the customer wanting a major unpredicted overhaul, or to implement BYOD, etc. Not to mention if the customer wants access too and then makes some incorrect changes that require lots of remediation. Add in regular healthchecks and security review. This is doubly problematic if the network wasn't put in by the new supplier.. We tend to offer network refresh as a managed service (so hardware, install and support as annual charges, limited capital outlay) including 2nd or 3rd line support, all remote changes included, with an allowance for on-site work for simpe projects etc. Customer has training and access if needed.
-
The more 'enterprise' manufacturers will have long and well documented EOL/EOS plans. With ref to Meraki, standard offer for Education is a 10 year licence at a heavy discount, so you get all updates, dashboard etc, new features and hardware replacement even if the AP dies in year 10. I think 10 years is a decent enough life, protocols and technologies will change by then too. So average cost for MR36 AP and 10 year licence would be around £410-420, so £42 a year. We can supply these as an annual charge model if you are struggling with capital budgets.
-
Monitoring iPad internet use, what do you guys do?
Wave9_Lee replied to Mimi-'s topic in Internet Related/Filtering/Firewall
You could reserve IP Addresses for each IPad. If you track who is using which IPad by number or whatever, you can tie the two together? I don't know if Safetynet would show you a report based on IP Address/URL Visited. But on-premise firewall/filter would do. Alternatively, as suggested you can purchase a small number of endpoint filtering agents for specific devices? -
Surf Protect Quantum thoughts
Wave9_Lee replied to johbreaking's topic in Internet Related/Filtering/Firewall
Hope you don't mind a recommendation from an interested party - worth a look at Sophos as a Smoothwall replacement. If you're used to an on-prem option, then Sophos XG will do a good job, and with free training and unlimited support from us throughout, low risk. Going from on-prem to cloud will generally mean less visibility and flexibility (not referring to any specific product/provider) and of course, there is firewall, anti-virus/malware and VPN considerations. I'd be happy to provides some prices to compare for you if you like - PM me if interested. -
You could try and work out if it happens at a particular time or day. And if so, try to isolate any network events that happen at the same time, perhaps on specific segments. I.e. periods of heavy usage (updates, backups, logons etc) If there is no QOS on the LAN or the broadband connection it will be difficult to guarantee call quality. Having QOS applied on the Smoothwall won't help a lot if the ISP won't/can't honour the packets.
- 1 reply
-
- 1
-
-
Internet filtering outside school
Wave9_Lee replied to Caffeine11's topic in Internet Related/Filtering/Firewall
You could do worse than look at Lighstpeed, good product, priced per licence, easy to deploy and manage with good reporting and alerting. https://www.lightspeedsystems.com/en-uk/solutions/lightspeed-filter/ If you need pricing, I'd be happy to help, cheers -
Suggestions for MAT filtering?
Wave9_Lee replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Hi Shaun sent you a PM - I can recommend Sophos XG, or Lightspeed, there are pros and cons for both, and mainly pros if used in combination - Let me know if you'd like a demo or to speak to any reference customers. cheers -
There some other factors to bear in mind in terms of sizing/performance etc, i.e: What features will you be using -if you're utilising the advanced stuff (IPS, Https inspection, Antivirus, Threat Protection, Application Control, nature of reporting/storage etc) these will have an impact on performance What size internet connection are you using, do you have/want resilience/failover? VPN remote access? Are you looking to buy outright and manage yourself, or take a managed service/spread the cost? Do you have any off-site filtering requirements? Not rocket surgery, but on-premise appliances vary in terms of features, quality, support, performance etc - I'd be happy to provide info and options and pricing anytime, just drop me a mail or PM, cheers
-
Hi couple of links that might help; setting up hostname allowlist https://support.google.com/chrome/a/answer/6334001?hl=en&ref_topic=3504941 troubleshooting sync etc; https://support.google.com/a/users/answer/2622308?hl=en Chromebooks don't like having SSL inspection turned on but the following XG exceptions can be added to allow them to work ^([A-Za-z0-9.-]*\.)?1e100\.net1/ ^([A-Za-z0-9.-]*\.)?accounts\.google\.com/ ^([A-Za-z0-9.-]*\.)?accounts\.google\.co\.uk/ ^([A-Za-z0-9.-]*\.)?gstatic\.com/ ^([A-Za-z0-9.-]*\.)?accounts\.youtube\.com/ ^([A-Za-z0-9.-]*\.)?clients1\.google\.com/ ^([A-Za-z0-9.-]*\.)?clients2\.google\.com/ ^([A-Za-z0-9.-]*\.)?clients3\.google\.com/ ^([A-Za-z0-9.-]*\.)?clients4\.google\.com/ ^([A-Za-z0-9.-]*\.)?commondatastorage\.googleapis\.com/ ^([A-Za-z0-9.-]*\.)?cros-omahaproxy\.appspot\.com/ ^([A-Za-z0-9.-]*\.)?dl\.google\.com/ ^([A-Za-z0-9.-]*\.)?dl-ssl\.google\.com/ ^([A-Za-z0-9.-]*\.)?gvt1\.com/ ^([A-Za-z0-9.-]*\.)?gvt2\.com/ ^([A-Za-z0-9.-]*\.)?gvt3\.com/ ^([A-Za-z0-9.-]*\.)?gweb-gettingstartedguide\.appspot\.com/ ^([A-Za-z0-9.-]*\.)?m\.google\.com/ ^([A-Za-z0-9.-]*\.)?omahaproxy\.appspot\.com/ ^([A-Za-z0-9.-]*\.)?pack\.google\.com/ ^([A-Za-z0-9.-]*\.)?policies\.google\.com/ ^([A-Za-z0-9.-]*\.)?safebrowsing-cache\.google\.com/ ^([A-Za-z0-9.-]*\.)?safebrowsing\.google\.com/ ^([A-Za-z0-9.-]*\.)?ssl\.gstatic\.com/ ^([A-Za-z0-9.-]*\.)?tools\.google\.com/ ^([A-Za-z0-9.-]*\.)?googleapis\.com/
-
Chromebook filtering
Wave9_Lee replied to EssentialRug's topic in Internet Related/Filtering/Firewall
If you're interested in looking at other options, Sophos XG will filter Chromebooks, as well as provide an extensive range of other features including per user reportin/multiple authentication methods, (firewall, deep packet inspection, VPN, Intrusion Prevention, AV, etc) You can replace filtering, firewall and router if taken with our Internet service too. Happy to provide more info or a quote if you're interested. cheers -
Alternative to Smoothwall cloud filter?
Wave9_Lee replied to TJ7's topic in Internet Related/Filtering/Firewall
Just a reminder that Sophos Central Endpoint Protection includes web-filtering (along with market leading AV, Application Control etc) and schools that have a Sophos XG UTM can benefit from Synchronised Security. This give you a central dashboard from which to manage each device and your firewall. The Endpoint talks to the firewall, even when off-site and protects your network when devices come back on-site. We have some great offers currently due to the increased need for home-schooling including extended free trials. Get in touch if you'd like more info. -
Hi Garacesh, The Network Auth agent should be able to help with this scenario, as it would authenticate your users once the initial details are entered and that should be that. Otherwise for RADIUS, if you set up accounting on your wireless controller, then enter those details into the XG (IP of your WiFi controller /shared secret), and away you go. (note: Administration->Device Access: Radius SSO, should be enabled by default on the LAN zone, but you may want to check that also). Drop me a PM if you need more assistance, I can put you in touch with one of our engineers.
-
Content Filtering in Different Languages
Wave9_Lee replied to nathan's topic in Internet Related/Filtering/Firewall
The XG operates its web filtering engine on categorisations of web pages, so no matter which website the user tries to access (in English, French, German, etc), these websites will be treated based on their category determined by Sophos (Online Shopping, Nudity, Auctions, etc). If you wish to do keyword filtering you can populate the list with foreign language words. -
Hi Garacesh, If you enable the Captive Portal on your unauthenticated (pupil) firewall rule, un-authenticated users (iPads, iPhones..) will be prompted to log in with valid credentials before they can access the Internet. Once they're authenticated, they'll then hit the same firewall rule as your Windows devices and the username will be logged. (Just to say that you will need the certificate pushed out if you have SSL inspection enabled...). Alternatively, there's the Sophos Network Agent which is a downloadable app, which does the same kind of thing. More details on that can be found here: https://apps.apple.com/us/app/sophos-network-agent/id1025058173
