Jump to content

Recommended Posts

Posted

Hi All,

 

On our network we have our main LA provided internet connection and a secondary BT Infinity connection coming into the phone line in our office.

 

The secondary internet connection isn't really network. It has a 192.x.x.x IP address and we have a laptop plugged directly into it.

 

The rest of our network is on the 10.x.x.x IP range and is split into three VLANs - one for our static server infrastructure, one for our physical client DHCP and one for our wireless client DHCP.

 

Before we segmented our network into VLANs, we had the router on the 10.x.x.x range (e.g. our main router was 10.x.x.1 and the BT router was 10.x.x.2). If we ever wanted to change to the BT connection, we simply changed our default gateway address. However, we can no longer do this because the default gateway needs to be the correct IP for the correct VLAN on our L3 switch.

 

How easy would it be to get our secondary BT router onto our main 10.x.x.x network somehow? Would it involve creating a fourth VLAN? What options do I have?

 

Thanks

Nick

Posted
Add another NIC into your PC (and any other PCs). Change your main NIC to have a 192.168.x.x address with a gateway of 192.168.0.1 (BT Router). Connect them all with a mini-switch. Then on the second NIC, put your 10.x.x.x IP address with NO gateway. Add a persistent static route for the 10.x.x.x.x range to go through the 10.x.x.x.YOUR_PC_IP. Add the 10.x.x.x.x entries to your local HOSTS file
Posted

Just select staff Meldrew. I'm thinking that there must be a more streamlined way to integrate our secondary internet connection with out network so that, should a member of staff find a need for it (I dunno, lets say for example that our main internet goes down and the head would quite like access to it without having to sit in our office on the laptop) then we have the option available. I'm quite happy with the filtering side of things... it's more the actual integrating it with our existing VLANs that I'm struggling with.

 

Thanks for the suggestion Darren. Do you think that this is the best way? I'm quite happy to do that for my computer, but I quite like the idea of having a 'on the fly' switch over to this internet connection from any point at any time. Am I asking too much?

Posted

hi nick3young,

 

you could use mikrotik router this way whatever and where ever the data comes from you can send down the BT line. You can use whatever is in the headers.

 

 

  • if data from headteacher PC only send down BT
  • if from vlan 1 or 3 send down BT
  • if vlan2 only use MAIN
  • etc etc

 

why not also add in fail over (part of mikrotik default kit also) if main line fail switch to BT

 

you can pretty much do what u want - its down to your needs and imagination.

 

if you can`t add in / replace new kit (Mikrotik £59+) then perhaps a seperate VLAN with a greater default route metric for the BT. If main line fails it falls over to BT (which is then the lowest metric).

 

Perhaps eliminate the BT lines router and just use the modem (unless its an all in one on an ADSL?) and have as a secondary default route? no need for VLAN - just bridge to the modems IP but ensure security implemented appropriately.

 

You haven`t mentioned make/model of your L3 switch which hinders answers.

 

Perhaps more details on your network would also be beneficial. Do you have a detailed diagram?

 

Anyway hope the above helps.

 

Regards

 

Aidan Venn

Posted

The auto failover solutions aren't a good idea in my opinion. Ofsted still want to see a managed internet connection, even if there has been a hardware fault. The micotik router option looks a bit safer, but remember your filter is also in place to safeguard your staff from making mistakes which could cost them their job.

 

Have you checked with your main service provider that they allow a failover to another provider? Our previous LEA provider outlawed this.

Posted (edited)

I agree that Ofsted do not routinely check anything to do with the network. Where they will stick their beaks in is when they sense that something is amiss... and then they can go to town. Having experienced this a couple of weeks ago, not with the network, but with something else, they are more than capable of going through everything word by word and date by date piecing together evidence. Luckily, we were OK, but it was pretty scary.

 

Now to the subject of unfiltered access. The minute you have unmonitored access, there is an opportunity for somebody to do something they shouldn't and cover their tracks. Even "carefully selected staff" can turn out not to be what was thought and you immediately have no evidence trail to explain how certain information entered, or left, your network. It's no good saying that it couldn't happen because it could and it does happen.

 

This needs to be a decision made by the Head... and the Head needs to have the risks spelled out to him/her.

Edited by elsiegee40
Posted
Well you do bt and and la they are bothed managed plus in all the years Ive not known ofsted to poke their noses around the network

 

This is a professional forum - I'd argue it would be unprofessional of us to not highlight the potential pitfalls the original poster may, or may not, have already identified and risk assessed.

 

Ofsted have outlined in their inspection framework that all inspections should include an inspection on eSafety. I am aware that all HMI's have been trained in the eSafety requirement. Many will do no more than ask the pupils about feeling safe and have they seen anything on the web they didn't like. However there is equally a committed bunch of inspectors who will ask to see the eSafety coordinator, IT coordinator and possibly the network manager.

 

Given all the relevant information, I'd expect the original poster to make the right decision for their school, and their users, taking all the information into account and informing the head and governing body, so they can make the final call.

Posted
ok maybe I did give the wrong impression, and like everyone else we all have esafety policies in place and certain agreements. The original question was really related to what would happen of our main connection when down and nothing about safe guarding. However it would be unwise to place any network onto a fail over connection with out the right safety net I.e internet filtering as this would be totally unacceptable and yea ofsted would be all over that like a bad rash. And in my defence im just saying that I haven't had ofsted ask me for documents thats not to say they are not ready on my shelf at any given moment. I was trying to provide the person in question an answer to his problem and if this is unprofessional then im sorry
  • Thanks 1
Posted (edited)
I was trying to provide the person in question an answer to his problem and if this is unprofessional then im sorry

 

The unprofessional point wasn't really aimed at you, but I can see why my post suggested that - sorry about that. A forum is exactly that, an open discussion with the opportunity for all to make a point. There is a technical answer to the question, then there's the moral, legal, regulatory aspect. Covering all avenues makes our discussion more forum more professional and ultimately more beneficial to the original poster, and those that find this post later down the line.

Edited by IrritableTech
  • Thanks 1
Posted

Hi All,

 

A good forum post to read, looking at the tech level and then the external impact of the tech decision - regs etc. Love it.

 

Based on some discussion points i`ve had quick play with visio and attached some possible ideas. However without knowing more about current setup its a bit tricky.

 

It seems to me that the regs need sorting first before the tech otherwise possible hot water. This is tricky as engineers minds tend to play, tinker and fix first!

 

Regards

 

Aidan

Untitled.png

Posted (edited)

What are the LA's T&C's about connecting to another network? I know our LA viewed this sort of thing as a security risk to their entire WAN so took a very dim view of any school connecting up a non-approved ADSL (or similar) connection in this way.

 

EDIT: From a technical standpoint it's very easy to do by introducing a new 3xNIC router between your private LAN and the two external connections.

Edited by tmcd35
Posted

---edit - initial post came out a little scrambled for some reason!---

 

Thanks you Kevin and Avenn for your responses.... this is the kind of information I'm after. Also, thanks to all others who have highlighted the filtering/safeguarding issues. I had already considered this - I wouldn't be daft enough to pipe any of our student connections (or staff for that matter) out over an unfiltered connection. I should have made this clear in the first post I guess to save the debate... but definitely worth mentioning since I didn't.

 

For anyone who uses Capita's OpenHive on the EMBC/EMPSN network, you will understand why I would be considering a backup connection for staff. Take Thursday for example when our connection was down (as is becoming increasingly more common), our office has important physical mail to send out and our franking machine relies on an internet connection. We had to lug it down to our office and plug it into our BT router. Now, that is just one small, recent example... and moving the actual machine might remain the best solution. But as IT professionals, I feel it is part of our job to make life more convenient for our users. The internet being down is incredibly inconvenient these days!

 

I agree with you IrratableTech... I think an 'auto failover' could be quite dangerous. I would like to make the decision WHO gets the backup connection and WHEN. I feel that the responses from Avenn and Kevin are definitely getting towards something which might allow me to achieve this.... I'll send some more detailed information about our network in a follow up post......

Posted

Thanks for the response @nick3young.

 

This thread begs another question none of us have touched on... if the primary connection is not robust enough for day to day running of a school it's not fit for purpose. Rather than look at failover or a backup, surely another more robust provider is required?

Posted

Ha! I knew that comment was coming too. :D You're quite right though. We use Kingston for our connectivity and they are fine. Capita on the otherhand, who provide our servives (webfiltering etc) always seem to be breaking the proxy.... I don't know what they are playing at. They host our website too which was also unavailable over the weekend. I am looking into replacing them, as I'm sure are most of the other network managers in the area.

 

But, having said that, even when our main connection is more stable... we are always going to have a secondary one - we wouldn't be without it. Especially when you consider it is such a small cost in the grand scheme of things. So if we have this second connection, I would like to know if there is a way that we can SECURELY, offer it out when/if needed without having to physically bring a device into the office to be plugged in. It doesn't seem very slick. Take another quick example, a member of staff is taking part in a web meeting tomorrow evening. It doesn't work very reliably (or at all) through our LA proxy. It would be nice to offer her the secondary connection for the meeting for a couple of hours. I might be opening a can of worms and I appreciate the concerns.... but I'm trying to get to the bottom of whether or not this is possible from a technical viewpoint. Our main connection is 100mbps and our second connection is 60mbps.... it seems crazy having that sitting there doing nothing when staff are crying out to use it in certain situations.

Posted

network.png

 

Our main switch is a Netgear L3 GSM7328S. Above is how we have our VLAN routing configured. I believe the IP address in the configured route section is for our LA proxy. The IPs in the 'learned routes' table are our 4 VLANS (one for DHCP, one for wireless, one for static infrastructure and the other is our internet transit VLAN).

 

I have a feeling if we create another VLAN for our secondary internet connection, this is still going to be quite tricky to switch over to? Would it involve re-tagging ports etc for the relevant devices? Or could it be done just by simply changing your gateway/proxy?

 

Thanks

 

P.S. I've blanked out portions of the IP address information. I don't know if it would put us at risk if I posted all of the information. In fact, I don't know if the information I've posted is a security risk - please somebody let me know if it is! Thanks!

Posted

Hi,

 

I'm a little confused as to why people think auto failover is unsafe. We have 3 routes into our building here. 1 x fibre and 2 x ADSL but all are behind our firewall / UTM so apart from being a lot slower on the ADSL failover route(s) there's no difference in filtering. Am I missing something?

 

HBJB

Posted

Heebeejeebee: We pay for offsite LA provided services so I believe only our LA provided link can be routed via those services. Also, it's those services which is causing our connection to the internet to break (!) so currently, I wouldn't want the secondary link to flow our via it.

 

We are considering a Smoothwall box so when/if that is put in, perhaps we could route both our connections out via it. But we can't currently.

Posted
Hi,

 

I'm a little confused as to why people think auto failover is unsafe. We have 3 routes into our building here. 1 x fibre and 2 x ADSL but all are behind our firewall / UTM so apart from being a lot slower on the ADSL failover route(s) there's no difference in filtering. Am I missing something?

 

HBJB

 

The question was around a failover connection where the filtering was hosted by the service provider of the main connection. Main connection filtered, backup connection not filtered. Those running local filtering wouldn't have this issue.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...