← All Case Studies
Education — SEND

LAN Reconfiguration to DfE Standards

SEND Secondary School — Tameside
By Jack Healy · Senior Network Engineer

A SEND (Special Educational Needs and Disabilities) secondary school in Tameside asked Foresight to reconfigure its internal LAN to meet the Department for Education’s digital and technology standards for network switching and cyber security. Like many schools, its network had grown organically over years of piecemeal additions. The result was a flat, largely unsegmented network carrying several overlapping security appliances — difficult to manage, difficult to document, and difficult to secure. For a SEND setting in particular, where the network underpins safeguarding, filtering and the handling of highly sensitive pupil information such as EHCPs and medical data, that position carried real risk.

The site was running a SonicWall firewall alongside a Smoothwall filtering appliance whose functions overlapped and, in places, actively conflicted — creating routing ambiguity, duplicated policy and blind spots that are hard to reason about during an incident. A third device, a FortiGate UTM, was already present on the network but was only being used as a wireless controller — a capable security appliance doing a fraction of its job. Meanwhile the flat network meant that staff, pupils, guests, servers and unmanaged devices all shared the same broadcast domain, so a single compromised device could reach almost anything.

The brief was clear: rationalise the estate down to one documented gateway, bring firewall functions, network traffic policies and web and content filtering under that single device, retire the redundant appliances, and segment the network properly — all aligned to the DfE standards.

The DfE’s “Meeting digital and technology standards in schools and colleges” framework sets out the minimum technology every school should reach, with six core standards to be met by 2030: broadband internet, wireless network, network switching, cyber security, filtering and monitoring, and digital leadership and governance. Three bore directly on this project:

  • Network switching — switches should be centrally managed and secure, support features such as VLANs, and provide the performance and resilience the school needs.
  • Cyber security — among other requirements, the DfE expects a properly configured, managed firewall and, crucially, network segmentation, so that a compromise in one area (for example guest Wi-Fi) cannot spread to critical systems and sensitive data.
  • Filtering and monitoring — schools must block harmful and inappropriate content in line with Keeping Children Safe in Education, with clearly owned provision that is reviewed at least annually.

Importantly, the standards are outcome-based. They do not prescribe a fixed number of VLANs or a particular vendor; they require that a school’s network is segmented, firewalled and filtered to protect pupils and data. A well-designed VLAN structure behind a single managed firewall is simply the most practical, maintainable way to satisfy those outcomes — which is exactly the approach we took.

Because the school depends on its network every minute of the teaching day — and because safeguarding and filtering cannot lapse even briefly — the change could not be improvised on site. The intensive planning phase was the real work of the project. Jack Healy audited the live environment end to end: every firewall rule, NAT and routing policy, every DHCP scope, the existing filtering categories, the wireless SSIDs and the devices hanging off each part of the network. From that, he produced a documented target-state design — an addressing plan, a VLAN scheme and a consolidated policy set mapped to the DfE network switching and cyber security standards — and a cut-over runbook so that the on-site work could be executed quickly and safely, with a clear rollback position at each step.

With the design agreed, the on-site work was delivered in a focused three-day window. Foresight elevated the existing FortiGate UTM to become the primary perimeter gateway and migrated all firewall functions and network traffic policies onto it, rebuilt to DfE standards. Content and web filtering were consolidated into the FortiGate, so that a single device now performs firewalling, traffic policy and filtering — allowing the redundant SonicWall and the conflicting Smoothwall to be decommissioned entirely.

The flat LAN was then re-architected into 15 individual VLANs, separating traffic such as staff and admin, curriculum and teaching, pupil devices, guest and BYOD, wireless, servers, network management, printers and MFDs, CCTV, VoIP, and building-management / IoT systems. Inter-VLAN traffic is now governed by explicit firewall policies on the FortiGate rather than flowing freely, so each zone can only talk to what it genuinely needs. Finally, the FortiSwitch and FortiAP estate was brought under the FortiGate as a single, centrally managed FortiLink LAN — one console for switching, wireless and security, fully documented for the school and any future support.

Segmentation is not box-ticking. SEND settings hold some of the most sensitive personal data in the education system — care plans, medical needs, safeguarding records — and rely on assistive technology and third-party and IoT devices that are not always easy to patch. By placing those devices, guest access and pupil networks in their own VLANs, a compromise on, say, an unmanaged device or the guest Wi-Fi is contained rather than free to move laterally toward servers and sensitive data. That containment is precisely the outcome the DfE cyber security standard is asking schools to achieve, and it materially strengthens the school’s overall security posture.

1
Gateway (from 3 appliances)
15
VLANs segmenting the network
3 days
On-site delivery
DfE
Standards met & documented
FortiGate UTMFortiSwitchFortiAPFortiLinkVLAN SegmentationWeb & Content FilteringDfE Digital & Technology Standards

The school now runs on a single, fully documented FortiGate, FortiSwitch and FortiAP LAN, segmented into 15 VLANs to the DfE’s standards. Consolidating three appliances into one gateway removed the conflicts, simplified management and gave the school a far stronger, more defensible security posture.

Jack Healy, Senior Network Engineer, Foresight IT Services
Discuss a Similar Project Back to Case Studies