-
Posts
535 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Wave9_Lee
-
MPLS is fine, but as others have said, there needs to be proper consideration of traffic flows, resilience and flexibility. The cost of MPLS is now much lower than it used to be, probably a premium of between 10 and 25% of direct internet circuits, so cost is less of a barrier. But you still need to consider why you would want to pay the premium. As most traffic these days is Internet bound and applications are increasingly cloud-hosted, then there's less need for inter-site traffic. I would generally say that MPLS is needed when S2S QOS is a must, and I guess this would be in the case of a central PBX and SIP all routed from one site - again, less requirement for this than before. Corporate networks can have legacy time-sensitive applications, or perhaps CCTV, that demand MPLS, but there are cheaper and more flexible ways to connect sites together for the (slightly) more standard education requirements. Some downsides of MPLS: More expensive few options of telco generally less control of firewall, changes routing etc resilience is more costly more single points of failure potentially Some of these downsides exist in a local P2P (hub and spoke or daisychained) topology too. Not to bore everyone (again!) but as a network manager I would be looking for as flexible, dynamic solution as possible to take account of predicted and unpredicted changes in IT strategy and application roadmap as possible. I would want as few hops or obstacles between my devices and the internet as possible. Can I make or action changes quickly? MPLS has it's place. But I'm not sure it's in the education market.
-
Leased Line - Openreach cost
Wave9_Lee replied to Simcfc73's topic in Internet Related/Filtering/Firewall
Yeah, fair enough. It's non-standard, and they have to charge and it's in the price book as you say. Ironically, if you'd installed it in the second location straight away it would probably have cost nothing. Appreciate it probably wasn't an option at the time! I'm not here to defend them - I think it's just that engaging them on standard, process driven, established products is pretty reliable. -
Filtering for MAT?
Wave9_Lee replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
We'll have to disagree (on some of these points) Dave : ) I don't propose we have a multi-page debate and bore everybody, (and these are only opinions after all) but there are pro's and con's to both approaches. The vast majority of our sites have had 100% uptime for more than 4 years and have had much more control and visibility of traffic, users, applications etc during this time than would generally be available from a cloud hosted platform. I would reiterate your own point, that IF there is sufficient investment, capacity and is reliable, then this can be a good option. This isn't generally the case though, in my experience. The team at Wave 9 have (in our previous life) run some of the largest UK school networks and Grids in the way that you describe. We wouldn't do it again. I actually don't think that the architecture suits the cloud-oriented direction of travel - many apps require a direct internet connection, unencumbered by double NAT, proxies, centralised infrastructure etc. Not to mention the issues you can get with having limited, aggregated internet peers (i.e. much more likely to suffer DDoS and the now common Google Captcha stuff). Appreciate that a lot of this can be mitigated, but why try to when an alternative is already there that's simple and cost-effective. If was running a MAT with a number of sites, I would want to know what appliance or hardware was running my service, how it's configured, where it is and how to change it on demand. I'd want to be certain that if there was a fault, ALL my sites wouldn't be hit by the same issue (I would like to have my sites patched at different times - to suit me, so if there was an issue it's not for 100% of my sites on a Monday morning). I'd like to be certain that if I have resilient links, that they are on different networks (ideally different technology), terminate in separate equipment on different ISPs. I'd like to manage them from anywhere, have single pane of glass policy distribution when required, but also have the ability to configure each site for specific requirements, say BYOD, or specific users/applications. I'd like to be able to pull a report, the minute a safeguarding incident arises, identify the user, site, application, device or whatever. Fundamentally I would want as much control, visibility, flexibility and management as I could get. Anyway - as I say, there's room for multiple approaches, pro's and cons for both. -
Leased Line - Openreach cost
Wave9_Lee replied to Simcfc73's topic in Internet Related/Filtering/Firewall
Mmm not sure about this. To be fair to Openreach, their pricing is totally transparent (bear in mind this is only from the end user site to the nearest exchange, no aggregation, routing, back-haul, peering or internet, so only a small proportion of the cost). The survey charge is included in any order, so usually free. If any ECCs (extra costs for dig, duct etc) are identified, Openreach will cover the first £2,800 and if the ECC bill is higher than this, you can cancel the order, no penalty. ECCs are pretty rare these days, usually only very rural sites, and then only if they've never had fibre before. Probably 1-2% of our orders have ECCs. This is of course for EAD (i.e. used in fibre 'leased line'), not FttP , which has gone (is going) through various iterations in terms of install costs and ECC mitigation/recharge. Once this has become more standardised, it will be pretty transparent and consistent. I have plenty of reasons to be frustrated at Openreach, but as their products are largely regulated by OFCOM and have standard process end-to-end, at least they're (mostly) predictable. We had an install last week that literally took 5 working days from order to completion. Maybe some people have a bad experience, but this might be in a difficult to serve area - when averaged out over 100's of installs, the experience is much more positive than negative, in my view. -
Filtering for MAT?
Wave9_Lee replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
I agree with most of what you say Roy ref IWF etc, but would have to disagree about Cloud - what happens if the central filtering service goes down or is over-utilised? Any fault is a problem, but when it's across 20 of your sites, it becomes a drama. -
Filtering for MAT?
Wave9_Lee replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Hi Shaun, thanks for the comments. Sophos have put a lot of effort into the education market in the last couple of years, and many of the features their education partners have requested have been (or are being) incorporated into the latest XG platform. In my view, the fact that Sophos XG is foremost a security company, makes it MORE able to deal with modern cyber threats in schools than most other platforms. Appreciate your comment is about filtering - we don't see many complaints from customers about this, in fact I would guess that most users experience is that Smoothwall offers a MARGINALLY better filtering experience, but the inclusion of advanced firewall, routing, AV, management platform, application control and integration with Sophos Endpoint, makes a compelling proposition. And the filtering is improving all the time. Anyway - my two pence. There are plenty of opinions on here, I'm sure other contributions will give you a broader view. -
Filtering for MAT?
Wave9_Lee replied to Shaun_Dark_Lord's topic in Internet Related/Filtering/Firewall
Hi Shaun, Sure you will get inundated here : ) I think one of the key things when managing multiple sites is the ease of management and visibility of users/devices across the estate, plus the ability to act quickly. This is what we do - we use Sophos XG and provide integrated connectivity, all fully managed or co-managed with you, so you have full visibility and control, plus ease of management. If you'd like a demo or more info, let me know. -
PM Sent What size of school/connection are we looking at?
-
Hi Badaz, You can do this with Sophos XG Firewall. if you don't need filtering etc, then this would be at a lower cost. Let me know if you need any more info. cheers Lee
-
Leased Line - Openreach cost
Wave9_Lee replied to Simcfc73's topic in Internet Related/Filtering/Firewall
It's not clear what you're buying from your post Simcfc73 (at least to me - maybe my fault!) Openreach don't provide Internet, and generally won't quote end-sites direct, unless it's a new build. As others have said, you can run SIP over an ADSL line in some circumstances - unless you're needing dozens of channels.. -
Sophos UTM Identify and Stop VPN usage
Wave9_Lee replied to Theldron's topic in Internet Related/Filtering/Firewall
If this is UTM (not XG) First turn on "Network Visibility" under Web Protection > Application Control Then add a New Rule on the Application Control tab, just add in the application(s) you want to block. You can get away with a measure of control if HTTPS inspection isn't covering the clients. You can check on application usage under the Logging & Reporting > Network Usage > Bandwidth Usage tab and change the view to Top Applications. cheers -
If you've not written off any other vendors totally - I can recommend Meraki and you might be surprised at the price!
-
Hi Dave, taking into account the 10 year licence, plus we can spread the hardware cost, Meraki Pricing is pretty good (in my view). If you'd like some pricing, I'd be happy to oblige, cheers
-
Hi Caffrey, yes, there's been a marked reduction in fibre pricing in the last 12 months. As John says, one of the key things is to make sure you're firewall and filtering can cope (if it's on-prem). Datasheets might say throughput is OK, but of course, depends on how much processing and analysis the box is doing. Of course, if you're upgrading to 1Gbps from 1/2/300 just because it's super cheap (i.e. not coz you are maxing out) you probably won't hit the Gbps for some time. Happy to provide a price for comparison if you'd like. cheers
-
Hi just a quick notice that we are exhibiting at Bett 2019 alongside Sophos and it would be great to meet any Edugeeks who are visiting this year. Both ourselves and Sophos will have technical representation to hopefully answer any queries you have, and of course we offer much more than Sophos XG/Endpoint etc, including broadband, back-up services, telephony and network infrastructure - please drop in to Stand E350 if you have time. Cheers Lee
-
Any good ISP company recommendations?
Wave9_Lee replied to MrWu's topic in Internet Related/Filtering/Firewall
Well this has turned into a sales-fest! Take a look through the forum, there have been many requests like yours, and many responses/recommendations. We'd be happy to provide information/pricing as needed of course, drop me a PM if interested. cheers -
The Sophos migration tool isn't really fit for purpose, we (and Sophos) recommend a build from scratch, copying policies/rules you want to retain - also presents a good opportunity to review old rules to see if they're still relevant and safe.
-
Hi there are differences between the two, and much of the development will be going into XG in future - although the SG is not mothballed at this point. There are a range of new features on the next firmware update that should be of interest to the Education community, so definitely worth a look. You could extend your SG subscription by a year or two if needed, but we're switching/upgrading SG>XG every week with no issues. Yes, there's a the familiarity aspect, which is the case with any change, but most users are happy after a short period. The migration of rules is a bit manual currently, and where we provide the Sophos, we do this for the customer. If you would like a chat with someone technical at our end about the process, let me know.
-
Hi We often deploy 4G as failover, (or early/interim connectivity) and it can also be suitable for voice with Fixed IP. Ref inbound, it's fair to say that email is mostly cloud based now, and some of the inbound issues can be dealt with by dynamic DNS or MX record configuration. So there are ways to mitigate the worst effects. Depending on your location, the more usual form of failover would be Ethernet Leased Line as Prime, and say, FttC as failover (through a different carrier), so this gives you different technology resilience. BT fibre and copper will often use the same duct, and they're in the same exchange footprint, so it's not fool proof, but probably good enough (at the price). You can go to extremes with resilience, but there comes a point where the cost outweighs the benefit.
-
Request for help Guidance Please
Wave9_Lee replied to rama1712's topic in Internet Related/Filtering/Firewall
Hi Stuart, we have a template document with some guidance for purchasing the services you've mentioned as well as some previous tender docs that we can sanitise for you to use as a template. If you PM me your email address, I can send them over. cheers Lee -
MPLS vs SDWAN vs IPSEC VPN
Wave9_Lee replied to jayswarve's topic in Internet Related/Filtering/Firewall
We regularly deploy that with our service (using Sophos UTM). I think one of the key differences is that SD-WAN appliance is able to monitor link status and manage traffic routing based on the requirements of the application. So for instance, if both links we able to support QOS for voice and one link became degraded to an extent (i.e. not enough to 'fail'), SD-WAN would route traffic up the 'better' link. Firewall load-balancing is a bit more rudimentary. Again, one of those things that, of it were available cheaply, would be nice to have - but not worth the current cost (IMO) -
MPLS vs SDWAN vs IPSEC VPN
Wave9_Lee replied to jayswarve's topic in Internet Related/Filtering/Firewall
I mean it to be SD-WAN hardware, which dynamically monitors and manages the state of your connection(s) and routes applications/traffic accordingly. Some ISPs are starting to deploy 'SD-WAN' on their own network, which on that context usually means more visibility/management/flexibility for resellers/customers. This is a slightly different prospect. I'm sure there are other definitions out there : ) -
MPLS vs SDWAN vs IPSEC VPN
Wave9_Lee replied to jayswarve's topic in Internet Related/Filtering/Firewall
Hi John, I don't believe SDWAN is appropriate for most UK customers, never mind schools. The development of SDWAN technology (hardware) is great for multi-nationals, and particularly in countries where the difference in price between Direct Internet Access and MPLS is large. The reality is (in the UK at least) is that the telcos and resellers pricing model has changed to such a large extent that MPLS is the same price as Direct Internet Access here, so your network provider can generally accomplish most of what SDWAN can, for a fraction of the cost. As Dave (SB) says, you can use P2P links if schools are close together, or a mix of VPN, Cloud or whatever. I think the key thing is to choose a solution that supports your current and future (or at least 3-5 yrs worth) requirements and is resilient. Despite the underlying monopoly of (mostly) Openreach and Virginmedia, competition has forced carriers and resellers to innovate and discount.
