Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Wave9_Lee

Sponsor
  • Posts

    535
  • Joined

Everything posted by Wave9_Lee

  1. Hi Cragos1984, sorry - shameless plug here! - if you want the maximum flexibility in terms of per-user/per-device/per-group/per-IP policies for web-filtering and application control then I would look at on-premise appliance such as Sophos XG. It would give you a huge range of options and visibility as well as extensive detailed reporting and all the other UTM features besides. If you would like a demo of more info, let me know. cheers
  2. Hi gybe78 One way you could do this is with a small sophos xg appliance with network licence only - in line. Xg can do 2fa ssl/IPSec thru a free app or google authenticate etc. Not the ideal solution to add an extra device but effective and not expensive. Cheers Lee
  3. Hi Chris, yes no problem - PM sent
  4. Hi Andy, no worries, thanks for the info. Just fyi in future, when we provide our managed service with Sophos there are no/little upfront charges. regards
  5. Thanks Andy - did you give up on Sophos because of price or other issues? Don't take this the wrong way, but including your time and effort as well as the fact you're re-using old kit and opensource software, wouldn't it possibly better value to go for a new platform? For that amount of users, you could get a fully featured new UTM including all your reporting requirements for between £800-1,200 / annum including unlimited helpdesk, advance replacement warranty etc. As I said, don't take it the wrong way, I appreciate 'free' is good value, I'm just curious at the thinking behind the routes that are sometimes taken? cheers Lee
  6. Wave 9 will be at Bett108 this year. Our stand is E350. Please feel free to visit us for info about any of our services or just for a catch-up. We'll have Sophos with us, and will be offering special offers & freebies on a range of products. Hope to see some of you there.
      • 3
      • Thanks
  7. Hi Andy, out of curiosity, how many users/devices do you have?
  8. /puts head above parapet
  9. Hi Mark, subject to deal details, exchange rate (blah blah) it would be about 2.5 x that price with a 10 year licence/warranty/upgrades. Apart from feature set, the advantages (for me) is that you don't need to buy spares as you have NBD advance replacement. You get proper support 24/7. Urgent patches are tested and released quickly (bug fixes, security patches). Single Pane of Glass management from any web device across an entire estate(s) and product type. Visibility is key for troubleshooting inc cable testing, packet captures, virtual stacking, topology mapping etc. I'm sure Unifi 'does thejob', but if the budget stretches then I believe Meraki still offers comparable value over the term. If, in 9 years and 10 months the switch goes down, you get a brand new replacement of whatever the current equivalent model is at that time - (probably solar powered hover-switch!) I'm not a Cisco fanboy (quite the opposite) but I genuinely think that when combined with the warranty, support, troubleshooting and ease of use, Meraki can save money over most other platforms. We can spread the cost of the platform over a number of years to suit budget if needed. Anyway, my twopenneth : )
  10. I know we've agreed to disagree : ) but 10 years with all maintenance, support, management dashboard, updates etc - I think when you take into account the time and effort it saves, the visibility you get - over 10 years it's really good value (IMO) @markwilfan - no, it won't beat that, but I'm a strong believer in a total cost of ownership. I mean, you can buy second hand kit in the market for next to nothing and spare up, but if you take all things into account, is it the best value? No offence, I don't expect to change people's minds about how to view the comparative 'value' of one solution over another, just pointing out what the current pricing and benefits cisco meraki offer, as I think many people are unaware that they've introduced some cost effective 'infill' models and pricing/licence can be better than expected.
  11. Think you might be surprised at Meraki switch pricing these days, especially the new MS-120 range. 10 year licence for the price of 5 too.
  12. In terms of 'zero outage', this comes down to the redundancy you pay for, plus logical design. Also you need to understand the context of your applications - mail for instance, you would probably never know there was an outage. In addition, many outages have occurred in Azure in the last day or two as forced patches are undertaken (resulting in VMs being taken down) as a result of the Intel chip vulnerability discovered this week. Hosted platforms are great, but you lose some element of control and they're not always as cheap as anticipated. Quite often the benefits come down to reduced costs elsewhere (IT tech/more uptime/better performance/freedom to do other things) and predictable spend.
  13. Hi FN-GM, how do the chromebooks authenticate to the Wifi currently?
  14. Hi, not sure Barracuda will meet all the requirements either. Most choices on these things are a compromise between features and budget and your priorities. Sophos XG will filter chromebook, but SSO is not 100% slick yet, but future releases should resolve this. Smoothwall requires a client to be installed I believe. As i say, don't think there's a perfect answer to everything, and no doubt, as soon as there is, the requirements will change!
  15. This might be of interest - although has to be read in the context of an education environment. https://www.gartner.com/doc/reprints?id=1-43OJRBD&ct=170620&st=sb
  16. As expected +1 for Sophos UTM. If you need a demo or more info I'd be happy to help. ref Barracuda, not much first hand experience. We used to see quite a lot in data centre load-balancing, but not much in the way of filtering/gateway. They've just been acquired by a private equity company, so expect some changes (good or bad - could be either)
  17. Hi Scorpio, Do you have any other details such as user count, use of cloud, what current usage is, any changes planned such as a ton of devices being added? We tend to advocate a direct internet connection with Sophos UTM, if you'd like a quote and some options let me know, regards Lee
  18. Hi Dan, some of this is down to what your future plans are, where your key resources are going to be hosted, what applications and service you are running, so I don't think there's a perfect solution without knowing those things. Your service architecture should define your network topology. You can then look at risk appetite and cost. In simple terms, a link between the two sites is relatively low cost, but creates a dependency on your main site - if your internet or router goes down, you take out both sites. If each site has their own internet, then one of the sites can continue to operate. An outage at you main site will have greater impact as you bring on more sites. I would generally advocate an internet facing P2P VPN (or P2MP) design as this gives you the most flexibility. You don't need to do this at ISP level, you can do it with equipment at each site so that it's network agnostic. This way you are not tide to a single ISP or technology. For instance, if you have a school on a separate ISP, you can connect them to your core services pretty quickly even though they might be in contract for a year or two more than is ideal. Multiple schools will have staggered contract dates and often different technologies available, so flexibility is key. regards Lee
  19. Hi there, I don't know if this has been achieved, but as others have mentioned, it's possible to get an alternative FttC/ADSL supply in very quickly with expedited delivery. In some areas even 4G would be suitable if schools feel they've not had chance to review the market. Along with others we're offering both temporary and long-term package options for affected schools with deferred payment. If I hear of any interim arrangements I will post here.
  20. Dual FttC is a good solution, and probably sensible to get them from different ISP - although you won't be able to protect against the digger scenario, or key exchange/cabinet failure. Depending on your location 4G is becoming a viable backup technology. It's independent of your primary connection, so no digger. exchange or ISP issues and data rates are pretty cost effective these days.
  21. Appreciate this is early days but with ref to any offer to continue to supply the current service, it's likely to include a commitment for the school to sign up for future years. This is fair enough because it will no doubt cost the 'interim' provider to run the service to March, even though no monies may be received for that period. There should be some caution exercised that the school isn't caught in a long-term contract that is poor value.
  22. Hi Norphy, my personal view is that having updates and patches as well as hardware support for 10 years is worth serious consideration despite your reservations. Many issues we find in schools are caused (or contributed to) by poorly maintained and configured network infrastructure, so mitigating this for 10 years has a significant value in terms of resources and uptime. Additionally it's common for schools to not take any maintenance support at all (either wilfully or by budget constraints) so hardware replacements, even cheap ones, hit budgets unexpectedly. This will come off your available spend for whichever year it occurs in. I appreciate your viewpoint, but i think when budgets are really tight, securing a predictable cost and guaranteeing availability is really important. We can spread the upfront costs too, which further improve the picture. Just my view : )
  23. Just a quick note ref Meraki - In most cases we are currently able to offer the 10 year licence for the price of 5, which, considering this includes replacement warranty and support is pretty good value and pushes the 'brick' concern well into the long grass. regards Lee
  24. Hi there, There are plans to improve chromebook authentication in a future release of XG, but in the meantime using a splash page to login will do the job. regards Lee
  25. Hi FN-GM Sophos is worth a look. XG v17 is out shortly, and 17.5 next year with some really interesting features. When are you looking to change? If you'd like a chat or demo, let me know, kind regards Lee
×
×
  • Create New...