ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Suggestions for new APs and Firewall

    IT Discussion
    8
    70
    4.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @dafyre
      last edited by

      @dafyre said in Suggestions for new APs and Firewall:

      @scottalanmiller said in Suggestions for new APs and Firewall:

      @dafyre said in Suggestions for new APs and Firewall:

      This is for a school, not an SMB. With out some form of traffic shaping somewhere, their bandwidth would be overrun with torrents.

      @Markferron can correct me if I'm wrong, but right now, I think the Meraki APs are where the bandwidth shaping is being done now.

      There is a lot more to it than that. How many schools have their phones via their public WAN, for example? They might, and then they likely need shaping, but the things that make you need shaping often go away when dealing with things like schools.

      @scottalanmiller, I have worked at this place. They need shaping to prevent 3 computers with bit torrent from overrunning every ounce of bandwidth they have. Been there, done that, turned on traffic shaping, problem solved.

      Edit: The Phone system is a different topic.

      Why not block those rather than shape?

      JaredBuschJ 1 Reply Last reply Reply Quote 0
      • JaredBuschJ
        JaredBusch @scottalanmiller
        last edited by

        @scottalanmiller said in Suggestions for new APs and Firewall:

        @dafyre said in Suggestions for new APs and Firewall:

        @scottalanmiller said in Suggestions for new APs and Firewall:

        @dafyre said in Suggestions for new APs and Firewall:

        This is for a school, not an SMB. With out some form of traffic shaping somewhere, their bandwidth would be overrun with torrents.

        @Markferron can correct me if I'm wrong, but right now, I think the Meraki APs are where the bandwidth shaping is being done now.

        There is a lot more to it than that. How many schools have their phones via their public WAN, for example? They might, and then they likely need shaping, but the things that make you need shaping often go away when dealing with things like schools.

        @scottalanmiller, I have worked at this place. They need shaping to prevent 3 computers with bit torrent from overrunning every ounce of bandwidth they have. Been there, done that, turned on traffic shaping, problem solved.

        Edit: The Phone system is a different topic.

        Why not block those rather than shape?

        In general, you cannot. Not without some packet inspection going on. and that again kill the CPU in the router.

        1 Reply Last reply Reply Quote 2
        • scottalanmillerS
          scottalanmiller
          last edited by

          If you want to do all of this at the FW, which is reasonable but not the only choice, then yeah, obviously a bigger model is needed. If you are using the router only for routing, it will handle a lot of bandwidth. Just depends how you are setting it all up.

          1 Reply Last reply Reply Quote 0
          • dafyreD
            dafyre
            last edited by

            If they wanted to block it all at the edge, I'd assume they would need to look at something such as a Palo Alto or what-not?

            ER Pro -> Palo Alto -> Internal Network?

            scottalanmillerS 1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @dafyre
              last edited by

              @dafyre said in Suggestions for new APs and Firewall:

              If they wanted to block it all at the edge, I'd assume they would need to look at something such as a Palo Alto or what-not?

              ER Pro -> Palo Alto -> Internal Network?

              That's one approach.

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                EdgeRouter have an option for blocking BitTorrent themselves. But they have to spend time looking at the traffic to do so.

                dafyreD 1 Reply Last reply Reply Quote 0
                • dafyreD
                  dafyre @scottalanmiller
                  last edited by

                  @scottalanmiller said in Suggestions for new APs and Firewall:

                  EdgeRouter have an option for blocking BitTorrent themselves. But they have to spend time looking at the traffic to do so.

                  That's better done on a separate device, isn't it?

                  DashrenderD scottalanmillerS 2 Replies Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @dafyre
                    last edited by

                    @dafyre said in Suggestions for new APs and Firewall:

                    @scottalanmiller said in Suggestions for new APs and Firewall:

                    EdgeRouter have an option for blocking BitTorrent themselves. But they have to spend time looking at the traffic to do so.

                    That's better done on a separate device, isn't it?

                    If that's the only thing you're doing - it is worth splitting?

                    dafyreD 1 Reply Last reply Reply Quote 0
                    • dafyreD
                      dafyre @Dashrender
                      last edited by

                      @dashrender said in Suggestions for new APs and Firewall:

                      @dafyre said in Suggestions for new APs and Firewall:

                      @scottalanmiller said in Suggestions for new APs and Firewall:

                      EdgeRouter have an option for blocking BitTorrent themselves. But they have to spend time looking at the traffic to do so.

                      That's better done on a separate device, isn't it?

                      If that's the only thing you're doing - it is worth splitting?

                      They would likely benefit form the Web filtering and such on the Palo Alto (currently handled by the Meraki FW).

                      DashrenderD scottalanmillerS 2 Replies Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @dafyre
                        last edited by

                        @dafyre said in Suggestions for new APs and Firewall:

                        @scottalanmiller said in Suggestions for new APs and Firewall:

                        EdgeRouter have an option for blocking BitTorrent themselves. But they have to spend time looking at the traffic to do so.

                        That's better done on a separate device, isn't it?

                        Depends. Blocking one service is a very minor thing and easily handled by the entry level enterprise non-UTM device. So likely, no, you'd not split for one little thing.

                        1 Reply Last reply Reply Quote 0
                        • DashrenderD
                          Dashrender @dafyre
                          last edited by

                          @dafyre said in Suggestions for new APs and Firewall:

                          @dashrender said in Suggestions for new APs and Firewall:

                          @dafyre said in Suggestions for new APs and Firewall:

                          @scottalanmiller said in Suggestions for new APs and Firewall:

                          EdgeRouter have an option for blocking BitTorrent themselves. But they have to spend time looking at the traffic to do so.

                          That's better done on a separate device, isn't it?

                          If that's the only thing you're doing - it is worth splitting?

                          They would likely benefit form the Web filtering and such on the Palo Alto (currently handled by the Meraki FW).

                          Then you aren't doing just one thing of filtering out Torrents. 🙂

                          1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @dafyre
                            last edited by

                            @dafyre said in Suggestions for new APs and Firewall:

                            @dashrender said in Suggestions for new APs and Firewall:

                            @dafyre said in Suggestions for new APs and Firewall:

                            @scottalanmiller said in Suggestions for new APs and Firewall:

                            EdgeRouter have an option for blocking BitTorrent themselves. But they have to spend time looking at the traffic to do so.

                            That's better done on a separate device, isn't it?

                            If that's the only thing you're doing - it is worth splitting?

                            They would likely benefit form the Web filtering and such on the Palo Alto (currently handled by the Meraki FW).

                            They likely would, but that would be a different discussion.

                            dafyreD 1 Reply Last reply Reply Quote 1
                            • dafyreD
                              dafyre @scottalanmiller
                              last edited by

                              @scottalanmiller said in Suggestions for new APs and Firewall:

                              @dafyre said in Suggestions for new APs and Firewall:

                              @dashrender said in Suggestions for new APs and Firewall:

                              @dafyre said in Suggestions for new APs and Firewall:

                              @scottalanmiller said in Suggestions for new APs and Firewall:

                              EdgeRouter have an option for blocking BitTorrent themselves. But they have to spend time looking at the traffic to do so.

                              That's better done on a separate device, isn't it?

                              If that's the only thing you're doing - it is worth splitting?

                              They would likely benefit form the Web filtering and such on the Palo Alto (currently handled by the Meraki FW).

                              They likely would, but that would be a different discussion.

                              One they will run around the soccer field a few more times I'm sure, but that heads into religion / politics there.

                              scottalanmillerS 1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @dafyre
                                last edited by

                                @dafyre said in Suggestions for new APs and Firewall:

                                @scottalanmiller said in Suggestions for new APs and Firewall:

                                @dafyre said in Suggestions for new APs and Firewall:

                                @dashrender said in Suggestions for new APs and Firewall:

                                @dafyre said in Suggestions for new APs and Firewall:

                                @scottalanmiller said in Suggestions for new APs and Firewall:

                                EdgeRouter have an option for blocking BitTorrent themselves. But they have to spend time looking at the traffic to do so.

                                That's better done on a separate device, isn't it?

                                If that's the only thing you're doing - it is worth splitting?

                                They would likely benefit form the Web filtering and such on the Palo Alto (currently handled by the Meraki FW).

                                They likely would, but that would be a different discussion.

                                One they will run around the soccer field a few more times I'm sure, but that heads into religion / politics there.

                                I don't follow this phraseology.

                                dafyreD 1 Reply Last reply Reply Quote 0
                                • dafyreD
                                  dafyre @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in Suggestions for new APs and Firewall:

                                  @dafyre said in Suggestions for new APs and Firewall:

                                  @scottalanmiller said in Suggestions for new APs and Firewall:

                                  @dafyre said in Suggestions for new APs and Firewall:

                                  @dashrender said in Suggestions for new APs and Firewall:

                                  @dafyre said in Suggestions for new APs and Firewall:

                                  @scottalanmiller said in Suggestions for new APs and Firewall:

                                  EdgeRouter have an option for blocking BitTorrent themselves. But they have to spend time looking at the traffic to do so.

                                  That's better done on a separate device, isn't it?

                                  If that's the only thing you're doing - it is worth splitting?

                                  They would likely benefit form the Web filtering and such on the Palo Alto (currently handled by the Meraki FW).

                                  They likely would, but that would be a different discussion.

                                  One they will run around the soccer field a few more times I'm sure, but that heads into religion / politics there.

                                  I don't follow this phraseology.

                                  It's a discussion around whether or not web filtering should be enabled or not on campus. One that has been discussed many times. I'm sure there will be many more... but it becomes a religious / political discussion since they are a Christian College.

                                  1 Reply Last reply Reply Quote 0
                                  • M
                                    Markferron @dafyre
                                    last edited by

                                    @dafyre said in Suggestions for new APs and Firewall:

                                    This is for a school, not an SMB. With out some form of traffic shaping somewhere, their bandwidth would be overrun with torrents.

                                    @Markferron can correct me if I'm wrong, but right now, I think the Meraki APs are where the bandwidth shaping is being done now.

                                    Yup I have rules on the APs and the MX400. They should all be the same as far as bandwidth limits, just in case.

                                    1 Reply Last reply Reply Quote 1
                                    • 1
                                    • 2
                                    • 3
                                    • 4
                                    • 4 / 4
                                    • First post
                                      Last post