Jump to content

Recommended Posts

Posted

Hi all,

 

just wondered what the general thoughts were on combining administration network with curriculum network hence creating a 'flat network' across a school.

 

We kept two network so that SQL or Port 80 on admin servers are kept isoated from the curriculum PCs. What specifically bothers me is the fact that we even have adult evening classes in IT and I am rather concerned who may get access to the whole network.

 

What prompted this that the head wants teachers accessing admin servers from class rooms for attendance registration. But I think there is a serious data security risks here with sensitive pupils information becoming vulnerable and hence certainly infringing Data Protection Act etc...

 

I presume I am in a minority for keeping isolated networks, but I wondered whether there were any other schools in a similar situation.

Posted

A single or integrated domain structure is increasingly common in schools.

 

This could be for a variety of reasons. A simpler structure to support, more flexibility of resources, greater benefit to T&L or to administration of the school.

 

Security reasons not to do it? Actually ... very few now. DPA is not an issue really as most teachers will keep some information on students on their home areas (mark sheets, SEN info) and so if they walk away from a logged in machine it makes no difference whether you are on a single domain or on separate admin / curriculum.

 

There are many ways to skin this cat though ... here are a few ideas.

 

Firstly ... a single domain in a single forest is one thing ... but you can now form trusts between domains and forests with ease (ok ... maybe not with ease but it is not the arcane art is has previously been ... no goats or chickens will lose their life).

 

Secondly ... you can look at alternative methods of accessing the MIS to perform tasks such as register marking, report writing ... web-based plug-ins to learning platforms ... remote access to the admin systems (MS Terminal Servers coupled with Sun's Secure Global Desktop is a nice one).

 

Thirdly ... the use of virtual machines on staff laptops could be an option. A W2K Pro install on Virtual PC or VMWare that is hooked to the admin domain (the desktop / laptop is on the curriculum domain) could be handy and save on machines.

 

Just a few ideas.

Posted

I agree with Zak - as long as you secure it properly it's fine.

 

We have too much crossover between curriculum and admin staff and data to keep it seperate. We've had a single network for 7 years and (touch wood) haven't had any issues.

Posted

@ teddy - u can edit ur own posts in this forum mate.. top right of ur post button saying edit ;)

 

and i agree as long as its secured you shouldn't have any problems :)

 

Regards

James

 

p.s. i like that ''teachers know in no uncertain terms they will loose several fingers if they leave a SIMS PC unlocked'' :D

Posted

Not sure if this is exaclty related as it seems you are using a Microsoft network?

 

We have student Machines on a different LAN to Teachers PCs, which is different again for Admin, Wireless, etc.....

 

We use around 16 different LANS. It makes security alot easier.

Posted
oopps sorry i take that back now you can't... **goes all red with embarracement** lol ;) i thought you could

You did used to be able to edit them...

 

Anyhoo - as others have said, a well-secured single network is not a security risk. A poorly-secured one is, but then so is a poorly-secured two network system since, as Tony points out, teachers have all sorts of stuff in their home areas anyway.

 

As with all network security, the biggest hole is your users - the ones who share passwords, write passwords in their planners, leave computers logged in over break/lunch because logging back on afterwards "takes too long". You can put every security measure you want in place to protect your data, but what MI5 don't leave in a taxi, the Government will lose in the post.

Posted
Not sure if this is exaclty related as it seems you are using a Microsoft network?

 

We have student Machines on a different LAN to Teachers PCs, which is different again for Admin, Wireless, etc.....

 

We use around 16 different LANS. It makes security alot easier.

 

Do you mean VLANS?

 

VLANS are a good idea if you are worried abouth security.

Posted

I must admit I am rather surprised with some of the responses.

 

Nick Jones: "Anyhoo - as others have said, a well-secured single network is not a security risk. A poorly-secured one is, but then so is a poorly-secured two network system since, as Tony points out, teachers have all sorts of stuff in their home areas anyway."

 

'Single network' & 'secure' are two that go only very limited way if applications on admin server require SQL or port 80 to be open to curriculum network. A hacker in a remote classroom will have a field day listening to the network traffic in a 'man middle attack'.

 

 

Nick Jones:"As with all network security, the biggest hole is your users - the ones who share passwords, write passwords in their planners, leave computers logged in over break/lunch ..."

 

This is precisely the point of keeping two networks isloated and 'not' to rely on teachers across the school keeping PC's logged in to SIMS or their password sahred/written in their planners.

 

If even Inland Revenue can not rely on well trained staff with data security what chance shcools have?

 

A visiting Australian network manager in a school from Melbourne kindly pointed out to me a document by Victoria Education Department which clearly states that schools must keep networks isolated. Data security/data protection act and civil liberties appear to be a high profile issue across Australia.

 

Pls drop me PM for a copy of the document.

Posted
'Single network' & 'secure' are two that go only very limited way if applications on admin server require SQL or port 80 to be open to curriculum network. A hacker in a remote classroom will have a field day listening to the network traffic in a 'man middle attack'.

 

How exactly would they manage that? For example, SIMS.net uses SQL as its backend. A user on a random machine on our (well, how it used to be) network could not sniff those packets. The only way of doing that would be spoofing addresses and complex techniques - most of which can be handled by having your switches set up right.

 

This is precisely the point of keeping two networks isloated and 'not' to rely on teachers across the school keeping PC's logged in to SIMS or their password sahred/written in their planners.

 

yes, but those admin machines will still be classrooms, else how will the staff use sims? It doesn't matter what network it is on if the user is a muppet.

 

A visiting Australian network manager in a school from Melbourne kindly pointed out to me a document by Victoria Education Department which clearly states that schools must keep networks isolated. Data security/data protection act and civil liberties appear to be a high profile issue across Australia.

 

Whereas here, I am pretty sure that either the DfES (or whatever it is called) or Becta has called on schools to consolidate into single network infrastructures - this being one of the reasons Somerset has changed most of its schools to single domain networks.

Posted

It is a fact that current direction of BECTA and DCSF policy is encouraging the use of Flat network design, which is in direct opposition to "popular expert opinion". We have recently enountered the same antipodean amazement that Tiger experienced, when we recently had some comms with an Australian VLE manufacturer. There reaction to the UK school situation of even having seperate networks "connected" across any means, let only a truly flat netowrk, was simple disbelief..

anyway...

This is the precise reason why we have endeavoured to develop non-standard/secure comms methods.

Where we do use standard network Comms we now advocate the addition of hardware based route blocking on the server to prevent unexpected attacks on common ports.

Attendance registration pretty much functions on the basis that your collection occurs in the Curriculum environment but your reporting occurs on the admin side, they need "A" link to be truly effective.

Our clients therefore run on a variety of comms - 802.11, Radio signal, even the browser based registration has a software solution in place to prevent direct connection to notorious SQL ports.. But we avoid anything running on the usual port suspects.

Very soon a Java version of the attendance interface is beingt released to run on any Linux PCs/Laptops or iMACs. Much more secure as far as netowrks are concerned.

On tht last point contact me if you want to know more (not the right forum to disucss that :) )

Posted

Ok ... are we looking for the ultimate design in security for MIS information or sensitive data on a network?

 

Firstly, too much is of what is being discussed is based on the MIS being the only store of sensitive data in a school. Too much is based around a single DB storing *all* information. I am afraid it does not work like that and the costs involved in changing that are generally prohibitive in schools (in software, in hardware and in retraining of support staff ... and this is before we even get to training the staff!)

 

Secondly, the move to hosting data in a central location is now having another hole opened to it, web access. More MIS are going to have some form of two-way conversation with a web front-end. Whether that is via web-parts into Sharepoint or the company's own web interface. These *have* to be over HTTPS to the browser before we even go into the other problems.

 

Finally ... this talk about creating a separate network for admin machines because we can't trust staff not to leave machines logged in ... what makes you think they will not just write done the password for the second domain? What makes you think that they won't just let a student onto their laptop because they are a machine short in their classroom? IT is sustainable in schools as it is ... as much as I want to make systems as secure as possible I don't want to make it so expensive that it becomes unusable.

 

Remember ... whatever we do in a school has to show that there is a demonstrable impact on the school, either across T&L or Leadership & Management.

 

@JohnCondon

Can you produce documentation or articles about flat networks (whether a single domain in a single forest, a single domain with child domains in a single forest or multiple domains in a single forest) that say they are against 'popular expert opinion'?

Posted

A visiting Australian network manager in a school from Melbourne kindly pointed out to me a document by Victoria Education Department which clearly states that schools must keep networks isolated. Data security/data protection act and civil liberties appear to be a high profile issue across Australia.

 

This is exactly what we have set up. Yes. I am in Australia.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...