Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Wave9_Lee

Sponsor
  • Posts

    535
  • Joined

Everything posted by Wave9_Lee

  1. Agreed, that's why I say the most common scenario would be fttc/fttp backup. Which can still be used in full, not just during an outage. You have to also look at your useage during an outage - if a secondary school with a Gbps line has an ADSL or v low fttc backup, it feels pointless in some ways, but it does mean you can still use voip, have critical admin systems online, and with the right traffic shaping policies, allow a cut down curriculum use. Having said that, many large schools will take a 100Mbps leased line backup for a Gbps main link. cheers
  2. The key thing is to try and get some separation where possible. Yes, 2 leased lines using Openreach might use the same duct and exchange, but you can pay to guarantee separacy (quite pricey and can involve civils work). It's sometimes possible to specify two different fibre providers, aiming to ensure different duct etc (i.e. Openreach + VMB or Cityfibre etc). I think that the most common scenario would be a leased line, with an fttp backup or fttc backup. FttP and FttC will use different routes back to an exchange generally, (and the exchanges are generator protected), so from the school/provider end, you can ensure that the logical routes are different too - i.e we specify different ISPs for backup services so that in the unlikely event of a routing or other config failure, your second link is unaffected. And for the Yorkshiremen, as standard we configure both links as active/active so you can use what you're buying, load balanced, weighted etc. It also means you could have a scenario where your voip on your backup link in normal use, and have it failover to your main link in the event of a fault, and vise versa for data. And don't forget that you should ideally use failover hardware and UPS - we will be specifying this as a standard option going forward.
  3. Having designed and buit a lot of Local Authority private WAN in the past (when it made sense), my opinion is that it's time for most LAs to get out of the network build business - many already have. Leave telcoing to Telcos - they have the most scale, lowest marginal costs, expertise. Trying to scale and build a WAN for a fixed number of sunscribers, where the demands increase every year, but the subsciber numbers reduce every year is a bad business model. You end up asking a dwindling number of subscribers to pay more and more to support the core infrastructure, staff and licences etc. How many on here have been told by an LA something like; 'We can't tell you what your charges are for next year because we don't know how many schools will sign up' or 'Next year's charges will be higher because we have fewer schools' And what usually happens is that the large schools with the biggest spend, subsidise the smaller schools, so when they large schools find a better deal in the open market (maybe cheaper/more flexible/more reliable/more secure) then it leaves the small (usually rural) schools holding the bag. Notwithstanding the above, it's likely that Openreach will have fttp in to most schools in the next 2-4 years, which can currently run at 1Gbps for a very good price. Even taking into account demand growth within schools, this will be more than enough for many primary schools, and if not sufficient (perhaps around upload speeds) then you can buy two links from 2 different ISPs and load-balance. This will continue to have a downward effect on leased line connection pricing for those that continue to need/want them (better upstream speeds, no contention, better SLA). There is an ironic set of consequences of an LA announcing their own private network build project; 1. If they are planning to use BT/Openreach, that will delay the roll out of natural 'wholesale' fttp services to that region (Why would BT spend their own money to upgrade a region, when the government will pay them to do it 2. If they are planning to use an Alt-net (VMB, CityFibre etc) then Openreach will bring their own plans forward for that area to disrupt the alt-nets business model. it's all a game. Finally, there is, and will continue to be grant funding for local authorities to pay Openreach to provide fttp infrastructure to schools AT NO COST TO THE SCHOOL (see recent DFE announcements).
  4. With ref to Sophos, enhanced reporting is now available through Central and is much improved. In addition, all the firewalls can be managed through Central too, giving you a single dashboard. You can push out policy to all firewalls with a single click, or specify policies for specific sites. Happy to chat through and help out with the Central element if you drop me a PM or contact me directly cheers
  5. Feel free to contact me for info or pricing any time. If you need a demo etc, happy to help cheers
  6. Assuming you're looking at Firewall and Filtering too, there are some DFE templatey ones that do the rounds that we see regularly, happy to redact and send over if you DM me your email address. The key thing (I think) is treat any template RFQ/tender docs as just an example of how to structure your info/requirements/instructions, and then use the template specification judiciously. Relate it to your actual requirements and the reality on the ground. Sometimes there's far too much insistence on things you won't need, and indeed can't have (i.e. I want my leased line in 6 weeks time). So you can end up putting off some bidders and reducing your supplier choice. That's not to say you need to dumb it down either! But in addition to the templated 'standard' elements and compliance, consider what you might need in the future both technically and commercially; What actal resilience is really available VPNs both user based and intersite connectivity Telephony and QoS considerations Different Authentication methods Reporting and Data Management Control and Visibility Different device types/OS and impact What happens if you add schools What happens if you want to upgrade What happens if you leave or staff are absent (for changes for instance) What training is available Project Management, Technical Support, Response times References References References And think about any score weighting - 80/20 price/quality might get you a price you like but a solution/supplier you don't, and you might not have a choice by that point. And whatever time you think you need, it's probbaly not enough : ) Good luck!
  7. Lightspeed filtering is based on price/qty bands - happy to send a quote anytime if needed, just drop me a PM or call directly, cheers
  8. probably a red herring but coincidental; https://www.theregister.com/2022/01/26/lets_encrypt_certificates/ We've a lot of users on MR2 using Lets Encrypt with no issues that we can see currently.
  9. This is a key point to consider too. If you're flying solo, it's particularly important to 'outsource', consolidate and simplify where possible. I personally don't think a full outsource 'managed service' works most of the time, which is why we operate a hybrid managed service so you retain as much control as you need, but are getting good support and backup resource for a sensible budget for when things get too complex or resource issues occur.
  10. It's true and there can be some value to be had by scouring the market for competitive rates, but in my experience it makes it too easy for the 2 (or 3) providers to pass blame between themselves for issues. Straightforward internet outage, not so bad, but certain websites not loading (Filter rules/DNS/firewall policy/authentication?) applications not working, patches not downloading or slowness, etc - not so easy to track down. If you're a whizz across all the technologies then you can probably troubleshoot but prepare for your provders to play the blame game. It's not entirely unreasonble to be fair - a supplier could tie up an engineer for hours troubleshooting something that isn't their fault, so knocking it back until you prove definitively it's them is a valid process.. If you use a single provider for these services, then it's their issue to resove, whichever element is causing the problem - and it's easier to resolve because they (we) have visibility of all the data and logs. You also get a single bill, which admin types quite like. Of course, if all of your eggs are in a crap basket, then your point is very valid!
  11. No doubt you'll find a plethora of opinions, but my two pence is; You will need a firewall as well as web-filtering Web-filtering is not monitoring You can't be an expert in all the technologies No product is perfect Price does not equal value If we assume that your shortlist is comprised of products/services that are compliant with baseline DFE requirements and the companies offering them are reputable and solvent (and they're all affordable) then it's sometimes a case of making sure that any non-standard specific requirements are met (could be technical, could be process/organisational) and then making sure that the service can adapt and facilitate any changes you might encounter. Cloud adoption and Covid have shown that the ground is ever shifting and you'r expected to adapt with it. If you anticipate a large quantity of off-prem devices that need filtering, then an agent based filtering might be the way to go (we offer Lightspeed) If not, (or we think that covid measures will resolve back to in-school 90-100%)then a combined firewall and web-filter will save you money, facilitate easy management and visibility and ensure that support is simplified. You can still use agent based filtering or monitoring products alongside. If you don't have lots of technical resource or the right skillset, then how much support are you offered - conversely, how much are you allowed to change yourself. If you change your entire network architecture or take on additional sites, how is the service going to facilitate or hinder that? What resilience (truly) are you able to get for an increasingly vital resource. Increasingly security is a focus - how much visibility and control do you have over what is on your network and what is being accessed? Everyone will have an opinion based on their specific pain points, experience, their skillset and comfort zone as well as specific pressure from SMT/governors and compliance factors. If you did a feature/service comparison across 20 suppliers, there would be some 'x's in most columns, but only you will know what is a priority for you. What do you like about LS Rocket, what is missing that you really need, what are your plans for the next 3 years? Happy to organise a demo/trial anytime, cheers
  12. We have survey tools for detailed fibre and broadband availabiity, and you can of course check your own site/postcode on various public checkers, but if you haven't seen it before, this is a good public resource to check your surrounding area easily. With FttP, it's sometimes possible to get Openreach to extend service to you with no additional cost if you are close to an FttP area. https://labs2.thinkbroadband.com/local/broadband-map#6/51.414/-0.641/
  13. Hi @tmoon-mint Lightspeed can do this. I can arrange a trial that would see you over Christmas if you need?
  14. Yes, no problem - the hardware, as with most firewalls is dependent on school size/device count/internet etc. You would ideally route LAN traffic through it too so all traffic, including non-internet bound gets inspected which adds a bit of load. In terms of licencing, there's a standard bundle which covers most requirements. It's called Standard Protect funnily enough. Having endpoint is a bonus as you can link the firewall to the endpoint clients so the firewall is aware of the status of your machines and can block them from joining the network if infected, or even unpatched. Managed on the same dashboard If you PM or mail me your details I can send over some info and pricing - arrange a demo if you like. Or give me a call anytime.
  15. Thanks All - tenner's in the post!
  16. FYI - Sophos are launching LAN hardware this quarter and we'll be evaluating as part of early access. Managed from the Sophos Central with added security features and synchronisation, might be a nice addition if we can get the pricing right. In addition, advanced reporting has been launched too. They have ZTNA coming (Zero Trust Network Access) so a good portfolio of products lining up, all managed from the same dashboard.
  17. Hi Samlcfc16 I'd be happy to arrange a demo of Sophos XGS, which can do all of the above. No obligation, let me know if this is of interest
  18. Hi Jordan, I'm sure you'll be getting the community responses shortly, but I thought I'd just jump in and mention Wave 9 - We're 100% edu focussed, supplying firewall/filtering and connectivity to hundreds of UK schools. If you'd like a demo, or detailed info and some pricing for our services, I'd be happy to oblige. We don't pressure sell and quotes usually take 24 hours. Our co-managed service is based on Sophos XGS and/or Lightspeed, or a combination. We have dozens of customers in South Yorks and Derbyshire if you'd like any local references. Contact me any time using the details below or PM cheers
  19. Lightspeed offer an alternative that is very cost effective in my view - happy to arrange a demo/quote if you're interested in casting the net wider..
  20. Worth saying that some EDU ISPs will spread the costs of your ECCs over the term of the broadband contract, which helps with the pain slightly.
  21. Hi @Asmodeus I'd be happy to provide some options/info/pricing as needed. PM me or contact me directly (as per below info) if we can help. Happy to chat on the phone anytime. Quote turnaround in an hour or so, no pressure-sell. regards Lee P.S. thanks Sister_Annex!
  22. Pretty sure you can do this with Sophos XGS and they have a home SW version which is free https://www.sophos.com/en-us/products/free-tools/sophos-xg-firewall-home-edition/software
  23. For customers that want device-based filtering, we now offer Managed Sophos XG firewall and Lightspeed alongside. The costs of the XG come down because of the reduced licencing, so can often be cost-neutral. I.e. you can retain the firewall and advanced security features of the XG alongside the Lightspeed filtering. Single bill/single support desk etc Note; for your renewal, that XG is End Of Sale, and the new firewall is XGS -(more performance). cheers
  24. We can provide both on-site or client based filtering for very reasonable pricing - Contact me direct or PM me anytime and I can send some info/pricing? How low is 'Low'? There really should be sufficient budget alocated for compliant and effective web-filtering to be honest. regards Lee
  25. Yes - it's just the users. it doesn't break everything. You can always just change the extension or make a copy of it. ​ Settings are in the .ini file, live users are in the .db file
×
×
  • Create New...