Saint Ignatius College Australia Oceania
Set-and–forget network security for Saint Ignatius College
About Saint Ignatius College, Education
Saint Ignatius College, the only Catholic Co-educational Secondary College in Geelong is proud of the unique position it has in the region. It is an extraordinary School, made so by a tradition of educational excellence.
Named after the Founder of the Jesuit Order, Saint Ignatius of Loyola, the College delivers challenging and innovative programs delivered by enthusiastic and dedicated teachers. This empowers each student to have the confidence to pursue excellence in all academic and social facets of their development.
As a Jesuit school, providing students with meticulous care in the development of their imaginative, affective and creative dimensions and assist each child to mature gradually in all these areas is their main objective. Key necessity is the establishment of a positive learning environment which propels students to learn, keep themselves abreast of the modern world changes and play an active role in society, yet preserve their innocence.
Thus, Internet research has come to be recognized as an essential study tool in all higher education courses in developed countries.
“We were looking for a solution that would control unproductive and harmful surfing.”
Mr. Paul James
Saint Ignatius College
Crystallizing about the main Internet security requirement of the college, Mr. Paul James, Network Manager (Systems) of Saint Ignatius College informed, “We were looking for a solution that would control unproductive and harmful surfing.”
The Saint Ignatius College was looking for a distinct solution that would offer:
Access Control and Intrusion Prevention
As an educational organization, the colleges & authorities strives to facilitate the open exchange of information. Students, instructors, and librarians all need access to the Internet. However, at the same time, the authorities have a responsibility to protect users from network threats, and keep the network up and running. A top security priority was to establish a private network to keep confidential information safe from unauthorized users, hackers, and other threats.
The organization therefore, needed a firewall and an intrusion prevention solution. The combination of both the solutions was needed to protect the network against intentional and unintentional intrusion attempts, and Denial of Service attacks.
Web URL Filter & Choked Bandwidth
Colleges and universities are faced with a constant battle to police large, distributed, networks where it is impossible to have a teacher or responsible person overseeing all pupil activity online. Colleges have a duty of care to provide a safe Internet experience for all their pupils and staff and need to demonstrate reasonable and effective measures to control access to the Internet. Content filtering was one of the foremost factors when deciding on a security solution, which was required to protect the college’s students from accessing unproductive or dangerous websites.
In case of blended threats, Mr. James was looking for a solution that could block all unauthorized download over the Internet. All Phishing, Pharming and malicious Websites need to be plugged. The college faced additional challenges with non-academic surfing, gaming, shopping, instant messaging and e-mails. There was no system in place to monitor or restrict surfing, which choked bandwidth and ruined college resources. Authorities needed a strong and flexible solution that would cater to the colleges need for content filtering, and manage bandwidth and provide them with total visibility of all network events.
Continuous Network Uptime
College is connected to the Internet by multiple ISPs to satiate the demand for high bandwidth necessitated by around thousands of Internet connected computers. “The college has 3 ISP links but we were unable to utilize the all of them effectively”, said Mr. James. Continuous Internet connectivity with no breakdown or downtime was the most important requirement for Saint Ignatius College as student had to do extensive research for their projects, view the e-library etc. "Saint Ignatius College requires load balancing and reliable performance while providing sufficient bandwidth for teachers and students to access web-based resources safely and securely," says Mr. James.
Mitigating from Malware Attacks
With the rise of P2P, and file sharing college campuses have become a virtual Petri dish for viruses and spyware. By their nature, college networks are fairly open and accessible. A virus or worm on one student's desktop can quickly propagate through a dorm and the whole network.
A perimeter level anti-virus solution was required that would protect the network, scan and clean any malware or spyware over the network to ensure the contents’ sanctity.
The Cyberoam Solution
E&S Communications implemented and maintained the Network Infrastructure, including the wireless and switching, for Saint Ignatius College. On the recommendation of Carlo Carabella, IT Manager of E & S Communications in association with Cyberoam’s distributor in Australia - MPA Systems, the institute decided to deploy one (1) Cyberoam 500ia unit in gateway mode. Saint Ignatius College has a firewall at the gateway. In the face of blended threats the college was looking for a comprehensive security solution that could blend seamlessly into their existing network. Saint Ignatius College uses Cyberoam’s integrated solution for Firewall, intrusion prevention system, content filtering protection, bandwidth management, and virus attacks. One more factor that helped Saint Ignatius College was Cyberoam’s multiple link load balancing and gateway failover which helped them make optimal use of their ISP links. A single CR appliance has the power to scale their complete Internet requirement.
Saint Ignatius College had taken demonstrations of Peplink and Draytek too, but found that they were not able to hold all their requirements. They also found Cyberoam cost- effective compared to other products. So they felt that Cyberoam was the apparent choice.
- Firewall & Intrusion Prevention
“They have student records that contain a great deal of private information related to student loans, scholarships, and other data. We also have to safeguard our own business assets, administrative records, and financial information.” says Mr. James.
Cyberoam firewall is ICSA and Checkmark certified - provides granular access controls over Internet traffic and the network resources. Coupled with Intrusion Prevention module, Cyberoam UTM can counter any Denial of Service attack. Mr. James now felt the network is secure.
- Safe Browsing & Judicious Bandwidth Management
Being an educational institute, they needed the ability to instantly block web sites, enforce acceptable usage policies on their users and have access to audit trails for entire user activity. Cyberoam addresses all these issues and more, by providing a flexible content filtering solution that puts the network administrator firmly in control.
Cyberoam has a content filtering database of more than 44 million Websites, categorized cleanly in 82+ categories, providing extensive control over Internet usage. All unauthorized downloads, P2P applications, pirated audio and video streaming and other harmful content is now safely blocked.
Any phishing or pharming Website is disallowed to ensure that no personal information accidentally falls into the hands of criminals. The content filtering categories allow the school to create policies to block access to sites associated with spyware, phishing, key-logging, malicious mobile code and malware. All content access over HTTP, HTTPS and FTP over HTTP is controlled, scanned and made malware free.
As part of their filtering policy, Saint Ignatius School uses Cyberoam's time-based quota feature. With the time-based quota option, organizations can set up policies for different users or groups to visit specific categories of sites for pre-set amounts of time.
- Continuous Data Availability
Driven by academic need of college connectivity over Internet, Saint Ignatius College has three (3) ISP links. Cyberoam’s Multi-Link Manager intelligently load balances the traffic and manages link failover between the three (3) broadband links. These links terminate on Cyberoam. The Multi-Link Manager constantly monitors the performance of the links. In case of a link failure, the load is automatically transferred to the working link, seamlessly, which leads to 100% Internet uptime, and round the clock availability of requisite bandwidth. In case of a link failure, Cyberoam automatically switches the traffic to the working link. So the organization gets a transparent multilink management with no human interference.
- Malware and Spam Free Internet
Cyberoam’s gateway anti virus pickets all the web and mail traffic – SMTP, IMAP, POP3, HTTP, HTTPS and FTP-o-HTTP protocols and makes sure that no malware or spyware creeps through the boundary and the network is fully safe and sound against malware including rootkits, viruses, worms, Trojans, spyware, backdoors, keyloggers and more.
Furthermore, the anti-virus rakes over more than 40 formats of compressed files and even freezes attachments for specified file types such as executables, media files, PDF, zipped files etc. before these blended threats can deteriorate the network.
This saves a lot of bandwidth & protects students from viruses, phishing, and spyware threats.
- To Wrap it Up
Summarizing his Cyberoam know-how, Mr. James said, “Cyberoam is termed as a first-rate product that delivers superbly high performance and I would strongly back it as - trustworthy security.”