-
Posts
535 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Wave9_Lee
-
On-Premise firewall alternative
Wave9_Lee replied to discoveranother's topic in Internet Related/Filtering/Firewall
Hi, appreciate you are looking for community responses rather than 'supplier', but I will offer Sophos as an alternative. We have many happy customers using this as a firewall and web-filtering appliance on-prem. Happy to provide more info or a demo anytime cheers, Lee -
Multisite routing with 2 circuits
Wave9_Lee replied to CrootUK's topic in Internet Related/Filtering/Firewall
+1 for Sophos with included SDWAN as an option on the base licence. The Standard Protect licence includes full fat next gen enterprise firewall and web-filtering, plus synchs with Sophos CIXA (endpoint). You can configure failover within the SDWAN links between dual internet connections and both links can be active, giving you additional capacity. Conditional routing for Trusted/untrusted will improve performance and capacity too - a very flexible platform. And as a co-managed service, you don't need to RTFM if you don't want to. Happy to chat through or quote/demo anytime, cheers, Lee -
Cisco ASA not working after reboot
Wave9_Lee replied to Sheridan's topic in Internet Related/Filtering/Firewall
In my (probably biased) view Sophos is a good option for both firewall and web-filter, but also as a separate firewall. The Central combined management of CIXA, MDR, firewall etc are a good timesaver and give a lot of visibility/felxibility across your estate - cost effective too... I think a continuing/increasing focus on security standards for schools from DFE is inevitable, and an enterprise NG Firewall is a foundational step in that ecosystem. -
Central filtering console?
Wave9_Lee replied to TheHyperTechie's topic in Internet Related/Filtering/Firewall
Hi, we can do this with Sophos Central. Manage multiple sites though a single dashboard, this works for firewall rules as well as filtering, and also includes CIXA (endpoint AV). All Sophos products basically. You can have one click to push out new rules/polices and also apply local specific rules. SDWAN is included and it's an Enterprise Class Next Gen firewall. Our view is that going this route gives you much more flexibility on the WAN side but also total control down to local level, including visibility of managed/unmanaged devices/users. We offer a co-managed service, where we make all and any changes, but you can also make your own changes. Happy to provide indicative pricing within 24 hours. Cheers Lee -
Yes, yes we are! Drop me a PM if you'd like a quote, thanks, Lee
-
Connect the Classroom scheme extra funding
Wave9_Lee replied to JazzFlute's topic in Wireless Networks
Any one can input into the consulation here: https://consult.education.gov.uk/reliable-and-safe-technology/narrowing-the-digital-divide-in-schools/supporting_documents/Narrowing_the_digital_divide_in_schools_and_colleges_government_consultation.pdf -
Simulated phishing emails/knowbe4 alternative
Wave9_Lee replied to njreynolds's topic in Internet Related/Filtering/Firewall
Happy to quote for Sophos and provide info to anyone who’s interested, It’s especially useful if you already have endpoint and Sophos Central as all users are part of the same ecosystem.. Cheers Lee -
Broadband provider recommendations
Wave9_Lee replied to JonesPJones's topic in Internet Related/Filtering/Firewall
Haha - some miracles are beyond even us! -
Broadband provider recommendations
Wave9_Lee replied to JonesPJones's topic in Internet Related/Filtering/Firewall
If you'd like some pricing/info, please let me know, regards Lee -
What's the purpose may I ask?
-
You could add: Sophos Fortinet Surfprotect (EXA) SafteyNet (RM) Protex OPendium Palo Alto not sure you will get a fully representative example with your list CoConnect are a provider, not a 'product' in the sense of the list you have. Not criticising! cheers
-
I'd be happy to quote Sophos CIXA if it's of interest, drop me a PM if so! regards Lee
-
Think the replies to this show that there is no silver bullet, a lot of product switching going on. Ref Sophos, it's not a monitoring product in this context, it provides advanced security and WAN/routing features as well as web filtering. DFE/KCSIE guidelines make reference to filtering and monitoring separately, which I think, is correct. My personal preference would be to split the monitoring and filtering function to two different products - this way any gaps, faults etc won't be replicated across your estate and you'll get more resilient/low risk coverage. Wave 9 offer Sophos and Lightspeed to cover all filtering and monitoring requirements - we have reasons why we prefer these to other products, but of course won't suit every customer scenario or preference. Happy to discuss pros and cons of these and other solutions any time. There are some great developments on the Sophos roadmap which I can share in the NewYear. As I've said several times on here, I think that many/most products across all functions (not limited to filtering/safeguarding) 'do a job' and usually represent ok value - the key thing for me is the organisation you deal with, how easy to work with they are, what the level of support they offer you. This makes a big difference and can usually help bridge many functionality gaps.
-
Fortigate for Filtering - Suitable?
Wave9_Lee replied to gsk's topic in Internet Related/Filtering/Firewall
I'm a big fan of on-premise firewall/web-filtering and we offer the Sophos suite of solutions. Contrary to some, I think that visibility and control of your own solution (with the correct support) is a much more flexible and responsive approach - and especially when considering the increase in cyber threats, a joined up approach is very useful - the 'filtering' on a firewall is not just that, it will include web protection as a module, scanning for threats on websites as well application control. Sophos links up with their endpoint product (CIXA) in a pretty unique way, managed via a single dashboard. Many happy customers with this approach - if you want to compare Sophos with your current shopping list, let me know. -
Recommended Firewalls
Wave9_Lee replied to CyBeRkId2002's topic in Internet Related/Filtering/Firewall
Something odd somewhere - Sophos amongst the cheapest enterprise firewalls in my view? I'm sure Unifi does a decent job, but if it was me, I'd be looking at a proper security eco-system with a proven pedigree in threat protection and mitigation. Given the number and cost of Ransomware attacks and other threats, I wouldn't be surprised to see some minimum standards enforced by DFE in due course. We have a few Trust Governors in our organisation and this is becoming a hot-topic from a governance and compliance point of view. -
Recommended Firewalls
Wave9_Lee replied to CyBeRkId2002's topic in Internet Related/Filtering/Firewall
-
Recommended Firewalls
Wave9_Lee replied to CyBeRkId2002's topic in Internet Related/Filtering/Firewall
We provide Sophos XGS for 'just' firewall duties for plenty of customers pretty cost effectively - major advantages in a lot of areas compared to many 'non-enterprise' firewalls, it's not just branding. There are a lot of features to consider, even if you're not currently using them just now - I believe that organisations need to be thinking about how to beef up their cyber protections, not deprecate it. Happy to chat through how pricing might be optimised based on your use-case anytime. -
ISP, Firewall and Filtering Costings
Wave9_Lee replied to JonnyAlpha's topic in Internet Related/Filtering/Firewall
Thanks @synaesthesia Happy to quote for firewall/filtering/monitoring anytime. Ref the free trial - agree it's hard to turn down free, but as far as I'm aware there is no SLA with Starlink, be interested to know if that's changed. So no guarantees on uptime, throughput, latency, or fixtime in the event of an issue. So agree with the Starlink as a backup scneario. Few of of our customers have used it, but speed was variable and outages frequent. Kind of flies in the face of DFE broadband standards tbh.. Also, going by those standards, backup connection would be appropriate. SOGEA (previously FTTC, should be sub 25ms and Leased Line <5ms generally). Voip would probably be noticably bad at around 100ms+ or so. SOGEA and Leased Line you would get a 'proper' SLA with these, uptime guarantees, service credits, <6hr fix time guarantee etc. Also need to consider your upstream bandwidth requirement. Not trying to put starlink down, it's good in certain use-cases, just not as the main/only link in a school (unless there is absolutely no other choice) But free is free - just consider what will happen if the service is deprecated or hard-down.. Pretty confident we could offer connectivity/firewall/filtering and monitoring for less than your current price including unlimited helpdesk support for all changes, robust SLA and service credits.. but we can't beat free : ) -
Keystroke Monitoring
Wave9_Lee replied to ITchallenged's topic in Internet Related/Filtering/Firewall
I appreciate you'll prefer community suggestions, but take a look at Lightspeed Monitor. Happy to arrange a demo or trial if needed. cheers -
do you have a ticket number?
-
Will have a look at this for you
-
Internet Filtering and Monitoring Providers
Wave9_Lee replied to JonnyAlpha's topic in Internet Related/Filtering/Firewall
Appreciate you're looking for community recomendations rather than vendors etc, but I'd be happy to provide info/options and pricing on our services anytime. As others have said before, every product/service has it's promoters and detractors, and there's no silver bullet for an increasingly complex IT architecture and governance/regulatory environment. On the basis that most products will cover the basic compliance requirement then, having found a shortlist of preferred options you perhaps want to consider How much control and visibility you'll have How easily/quickly changes can be made, How reliable it is and how quickly issues get resolved How is support delivered, how helpful, responsive etc How does the service adapt to changing needs I personally think that having several solutions with one provider is useful. It makes troubleshooting simpler, without one supplier blaming another for slow internet, DNS issues, filtering not working on failover, BYOD, authentication, VLANS and remote access etc - someone who knows a lot about your specific environment will be a useful partner. I think one of the challenges in the education sector is that particularly in this area, cost is often seen as the ultimate deciding factor, so quite often some important factors get missed. For info, some previous community discussions can be found using the search function - it's a perennial favourite topic! - some examples here; /forums/internet-related-filtering-firewall/228471-anyone-using-rm-broadband.html /forums/internet-related-filtering-firewall/227819-broadband-up-renewal-who-you-using.html /forums/internet-related-filtering-firewall/235552-isp-recommendations.html http:///forums/internet-related-filtering-firewall/239753-rmsafetynet-vs-smoothwall-vs-senso.html /forums/internet-related-filtering-firewall/239000-dnsfilter-agent-based-network-based-filtering.html there are lots more.. Be interested to understand your thinking around Starlink? The business package is not that cheap, and I wouldn't recommend the residential (no fixed IP, no priority on bandwidth, lower grade support etc). Is anyone using it with Teams/voice/video etc'? Assuming you can't currently get FttP and Ethernet Leased Line is too expensive for you (?) - then a second SOGEA (fttc) connection would help, as you could use both links, increasing available bandwidth and meet the DFE standards for resilient connectivity. Don't forget to review the DFE Standard Guidelines https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges -
Sanity check - UDP session timeout
Wave9_Lee replied to haci's topic in Internet Related/Filtering/Firewall
You could either set the timeout to 11 mins to see if that fixes the issue, or you could ask them to change their polling interval. Our voip is set to 10 seconds... 11 minute session timeout is a very long time. Think most fw vendors recommend between 120 and 300 seconds. You can sometimes set the timeout rule at application level to avoid resource impacts if globally set in large school -
No problem - drop me a PM or email with your contact details and I can send you some info. We tend to do both primary and secondary links so we can manage the failover seamlessly etc, but I'm sure we can sort something out
-
The amount of unused/unnecessary ports in new build schools is a scandal, especially when you consider they are nearly all patched through to a switch
