Securing School Networks: Firewall and Filtering Solutions for Enhanced Broadband Safety
This presentation by Liam Kennedy, Network Engineer at HEAnet Ltd., outlines the comprehensive measures taken to secure broadband infrastructure in nearly 4,000 schools. Funded by €18m from TIF and Departments of Education and Communication, the project includes the implementation of advanced firewalls, web filtering, and malware scanning. With a peak daily traffic exceeding 100 Mbps and 84% of schools actively utilizing their connections, this initiative ensures robust cybersecurity, enabling a safe learning environment for students while minimizing risks associated with internet use.
Securing School Networks: Firewall and Filtering Solutions for Enhanced Broadband Safety
E N D
Presentation Transcript
SecuringSchools Firewalling and Filtering on the Broadband for Schools Network. Liam Kennedy Network Engineer HEAnet Ltd.
Broadband for Schools Project • Providing free broadband to nearly 4,000 schools. • €18m - Funded by TIF and Depts. of Education and Communication. • Feb 2004: Plan announced and HEAnet chosen as ISP. • Late 2004: Connection and router tenders awarded. • Spring 2005: HEAnet build network and interconnect with selected service providers. NCTE support desk set up. • Summer 2005 Majority of schools connected and routers installed – Spring 2006: • Summer 2006: Scoilnet email service trialled and put into production.
Schools Update • 95% of schools installed • 84% of schools have used their connection • Peak daily Traffic > 100Mbps • Daily Download > 250GB • Email service now live
Cisco Firewall Services Module • Integrated firewall module (blade) for 6500 switch • 5.5 Gbps throughput • 100,000 connections per second • 1 million concurrent connections • Runs PIX OS
Fortinet • 500Mbps in-line scanning – scalable to higher bandwidths • Web Content Filtering • Virus & Malware Scanning – HTTP, SMTP, POP3 • Anti-Spam • IPS • Logging and statistics
Fortinet: Web Filtering • Database of 26 million rated Web Sites • 76 Categories • 24x7 Managed Service • White & Blacklists – override categories • Unrated sites blocked (24hr rating) • Currently 2 levels of filtering but is capable of giving each school it’s own profile
Web filtering – potential problems Not everything on the web can be neatly categorized - manual intervention will always be required.
Anti-Virus • Well-known ports blocked inbound and outbound by FWSM and 871 • HTTP, SMTP, POP3, IMAP scanned by Fortinet • Automatic reporting culled from Cymru and Spamcop reports, DNS and Fortinet logs. • Schools contacted – problem hosts can be blacklisted.
Other Issues: • Scoilnet Email Service • Virus and Spam scanned, inbound and outbound • P2P and other bandwidth-intensive apps • Can be blocked or rate-limited • Acceptable Usage
Q&A • liam.kennedy@heanet.ie • www.ncte.ie • www.fortinet.com