Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Wave9_Lee

Sponsor
  • Posts

    535
  • Joined

Everything posted by Wave9_Lee

  1. Do you still need to re-address your internal network?
  2. Hi Uber22, if you'd like a quote for Fastvue, let me know - happy to oblige. I can arrange a demo too if needed. cheers
  3. You should speak to your provider to rule in or out any options. If you're a month into a 3 year term, it's a different answer to being in month 30. A new Gbps link could cost between £4.5 - £10k depending where you are. We're frequently offering 1Gbps for the price of 500Mbps, so sometimes it's not worth going up in half steps. A second link is a good idea, but budget is a big factor here. Anyone in month 30 of a 3 year contract now, (especially on some LA contracts) is likely to be able to afford 2 x Fibre ethernet services for their current annual bill. As others have said, using different exchanges can be expensive and take time. Unless you are happy to pay for east/west different ingerss into the building, you will often be using same or adjacent duct. If you're lucky to be in the right area, you can look at an openreach (BT) tail, and a VMB tail, but resilience is all about cost-vs-risk. A risk analysis would (generally) show that the impact of an ethernet fibre failure is high, but the risk should be very low (availability is approx 99.95%) so would you want to pay thousands for a service you might not need? It's often sensible to use a backup FttC, because although this isn't enough to run the whole school; it's cheap it's on a different network you can load-balance and use both links (which at 80mbps isn't bad) it can be configured to mainly transport key traffic in the event of a Fibre failure, so that the school 'business' can keep operating Target fix time on an Ethernet fibre service is between 5-6 hours. Ironically 'big' outages of multiple sites often get fixed the quickest : )
  4. You should have had a replacement or tech support by now? Where did you buy it? We could possibly ship you a temp box, give me call? cheers Lee
  5. Each to their own : ) My advice would be to have both from the same provider, that way you have one support organisation to call, one bill and no arguments about who is responsible for what. If you deploy QOS properly, then voice quality won't be affected by a busy broadband line. I take your point about potential for both services to fail, but would suggest a second line, with both voice and broadband balanced across the two, so you have resilience for both data and voice. Our packages include free handsets and free calls and minimal set up. cheers
  6. +1 for Sophos (obviously!) Reporting is much improved with some tweaks, and there are some improvements coming in the next updates.
  7. Hi there are exceptions that should be entered, yes - if you want to PM me, I'd be happy to chat though this.
  8. Hi Techmonkey, there is a blocked request report. A report on failed/blocked attempts. As I said, the information is all there, it just needs some investment in time to create customer reports to be presented better. Sophos are working on these and other improvements all the time. cheers
  9. Hi Uber22 has your provider not offered any installation services? cheers
  10. Hi Techmonkey, Happy to arrange a demo for you anytime. The reporting is very comprehensive and compliant, but is not the most user-friendly as I would say it gives more insight than most systems, but is almost too much info, so there is a process of setting up custom reports to do to fine tune for your specific needs. Users are identified in the 'blocked attempts' log. In addition the Threat Quotient report is very useful as this highlights users who have the most 'risky' behaviour, which isn't just down to inappropriate web-requests, but also other activity such as application, VPN, etc. In addition for those that want a less detailed, more visually helpful dashboard, we offer Fastvue alongside the service too. cheers
  11. Hi Uber22 subject to which licence you bought, there should be some support from Sophos included, and you can buy a 'remote' assistance set up service from them (through your reseller). We can also help if you need a day/half-day on site at a reasonable rate. PM me if this is of interest. cheers
  12. We’d be happy to provide a quote any time, please PM if you’d like one. Regards Lee
  13. A quick/temp fix, might be to ask them to change your external IP address? Or if you have a backup link, switch traffic to that. You should check internally too, we've seen DDOS attacks originating from inside.
  14. Hi Simcfc73, you have a call open with us ref this and I can see that it seems related to your ESET AV disconnecting users, think our technician is waiting for an update after it was excluded from STAS? If you can respond, we can progress accordingly. If you need anything else, drop us a line at [email protected] cheers
  15. This might help? https://community.sophos.com/kb/en-us/120345
  16. Hi mflanders There's plenty of historical discussion on here ref filtering if you use the search box - probably a post every week or so! We offer a good solution (I think) based on Sophos XG. I'll leave it for actual users to comment further and provide advice, but if you'd like more information and some pricing I'd be happy to help. cheers Lee
  17. Just fyi, Wave 9 offer a full install service as well as annual charging for Sophos and include ongoing support as standard. In addition we can provide free training for customers. I appreciate many will be happy to 'have a go' but I think we offer a good service that serves as a safety net, even if you're skilled in Network etc. Always worth asking for a quote : ) cheers
  18. Resilience is basically a cost vs risk vs impact calculation. With leased lines, the vast majority will have 100% up time over many years. If there is an outage with the fibre provider, this will mostly be rectified pretty quickly. There will be the odd occasion where something more fundamental happens (digger) but these are rare. So by having a leased line you are already in a good place risk-wise. If you are using cloud or data centre hosted shared filtering and firewalls, there can be issues out of your control/visibility, but these (from anecdotal evidence on here) get rectified pretty quickly. EoFttC has better fix time targets that FttC, but in both cases, faults on these are more frequent and longer lasting - even with robust SLAs, due to the lower cost of the underlying services, the penalties aren't as motivating as they could be. The next issue is capacity during an outage. If you have the ability to control your traffic, and, say, restrict usage to power users, admin, or restrict video streaming for instance, then you can still have critical functionality during an outage with lower cost backup solution (4G/FttC). The data usage on 4G shouldn't be a concern, as it should be included in your overall service, and it's quite possible to get 30-60Mbps in many areas (a survey and research of different mobile carriers should be done pre-install). If your main service is EoFttC or FttC, then a backup FttC is a good idea. It's low cost, and you can use both lines simultaneously, so as well as a backup service, you have an increase in available bandwidth. Whichever route you take, you should where possible, utilise different carriers/ISPs and technologies to ensure as much separacy as you can afford. i.e. BT+Virginmedia or Fibre+Copper, Fibre/Copper + 4G. We have occasionally delivered 2xFttC + 4G as the costs are low. Lastly of course, if it's all plugged into a single bit of kit at the far end, or on-site, you need to consider how much of that can be mitigated and at what cost (and what the risk actually is) MTBF figures, robust SLA for HW swaps will help here. Hopefully you can get some info about what your service provider is doing in their core if you're taking a centralised service. At the end of the day if your risk analysis says that you have a higher than acceptable risk of downtime and the impact is high, you need to find some money for more resilience. The problem is that it's seen a bit like insurance - everyone resents paying for it until the insured risk occurs... and there's not a lot of money around!
  19. I think you should start from fresh. Use of the migration tool is not 'optimum'. It's usually a good opportunity to review rules and policies and tidy up in any case, I believe. It's not that onerous. cheers
  20. Some fair points here. Having deployed and worked in aggregated networks, both LA and corporate networks for years, I can safely say that even when the architects, engineers, telcos and data centre tell you that there are no single points of failure, one almost always turns up. And the fact of not knowing it was there, makes it a much more exciting experience trying to fix it. I find it's safer to trust what you can see/prove : )
  21. You could take a service that includes the firewall, filtering on-premise, gives you admin access to make your own changes, but also includes unlimited access to help-desk to make changes on your behalf or advise as required. The consolidation of Firewall, router and filtering and inclusive support will often save money and certainly save time. It also has the advantages of being a single SLA, and bill. Best of both worlds - ultimate flexibility, low cost, expert support. But I'm biased : ) Seriously though, for a large, complex environment, I would always recommend an on-premise security platform. It will facilitate BYOD, multiple changing application scenarios, resilient WAN options (including 4G) amongst other benefits such as VPNs, VLAN routing, DHCP, Radius Authentication, 2FA, fully combined reporting (firewall.filtering) for better visibility, inline anti-virus etc. In addition, some say that best practice is to route internal traffic through your next gen firewall as this will help protect against infected/rogue devices inside the LAN. As cyber threats increase in diversity and frequency, I think that the best way of keeping your users and information secure is to have on-premise security, combined with end-point protection, supported by a skilled partner. My 2P
  22. This is probably not do-able due to timing, but XG is a great firewall/filtering/security solution and it's quote cost-effective to have email protection added as part of the software bundle, so you're not buying an appliance just for mail. As far as I can tell, the O365 protection isn't too bad, but the dedicated products tend to offer a bit more. Sophos Mail protection comes with Encryption and DLP for instance. Comprehensive list of features here: You can also get a trial of central email to see how you get on. cheers
  23. Hi Scorpio, Our service for a managed service with Sophos XG and licence, with inclusive support starts at £650/annum for a small school. Happy to provide a quote if it's of interest.
  24. You only need a solution until Easter?
  25. Hi mp4-dave This is something we can help with if you'd like to have a chat. cheers
×
×
  • Create New...