Jump to content

Recommended Posts

Posted

Morning,

This is something that's only an 'in my head' plan at the moment, but it definitely needs doing.

I've taken over a secondary school as NM since September and can see the network is well overdue starting again. Just too much that is all over the place.

 

How would you go about it?

Rebuild every server or just redomain some?

Can I use the same domain name when starting from fresh?

Would you start the two networks alongside each other and then migrate everything when ready?

 

Could do with as much help as you can give. If you've done it yourself, what sort of plans/time-scales/contingency did you have in place?

 

 

Need to present it well to the HT and get it happening. I imagine a lot of it will be classed as 'a summer job'

 

Thanks! :-)

Posted

We moved from an RM CC4 network to vanilla at the secondary that I used to work at. During the term we set up a 'model classroom' with 2 PCs and Server 2012 (vanilla) which enabled us to test group policy restrictions etc on a couple of students before we migrated the whole school over.

 

Once we were happy with that, we migrated the VMs from the server that we'd used for the model classroom to the servers that were going to be used for the whole school. We then re-imaged all machines. Of course, right up until the last second we kept an 'undo button' active in the form of snapshots of our virtualised CC4 servers, so that we could go back to them if anything big went wrong over the summer that we did the work.

 

Along side this we did a backbone upgrade, installing fibre runs to all satellite buildings during half terms etc.

 

Properly managed, it's certainly achievable. If you lose track for a second you will find yourself in trouble. We did our migration along side a local IT Services provider (as the school had decided to outsource tech support anyway) so had plenty of people's attentions and perspectives at all times.

  • Thanks 2
Posted (edited)

It's one of those things I would have liked to do but after 9 years I have pretty much hammered my domain back into a very reasonable shape and I'd be worried about making it worse now.

 

I would rebuild every server (probably as VMs) in their own new domain with a trust linking it to the old one.

Domain name would be new - I'd purchase on the the .school domains and set the domain up as a (maybe subdomain) as that so you can have a unified cloud/local naming convention. So if your school was cumbria school you would own cumbria.school and your domain might be sch.cumbria.school for example. emails and logins for things like O365 would be [email protected].

Once group policies were done and tested I'd shift al the users to the new domain (probably with the ADMT) and then begin migrating the roles of servers into their new counterparts. If you aren't moving to O365 then exchange would be the first one i'd do. If you are then I'd move to it as soon as the users had been moved. If you alredy have you just need to resync with the new domain name I think - probably some powershell to change the primary login over). Your MIS would probably be next

 

I think you would want to get the main starting parts done at Easter. The four day weekend would be handy if you need to take anything down then you can plan summer doing 2 servers/services a week knowing that the main things (mis, email,logins) have been sorted and won't surprise you come the first week of september

Edited by Sagima
Posted

Do it!

 

I took over a secondary about a year ago and rebuilt our two domains (which were on a flat network anyway) into one. Haven't looked back. The first two weeks back after the summer are manic anyway, so it didn't make that much of a difference, and it's made a big difference to our workload.

 

Firstly, document everything. I used a OneNote notebook but it's up to you.

 

As others have said, get yourself a test bed with the new domain up as soon as possible to give yourself plenty of time to get it configured and practice moving users+shares across. Get the GPOs sorted early on as this eats a bit of time and can be done with only a few test VMs and dummy users. Create a trust with your current domain to make migrating easier. TAKE ALL THE BACKUPS!

 

We had two physical servers and around 200 workstations which all got rebuilt to the new domain, and it took me most of the summer with four days help from my techie. Spent the first two weeks migrating user data and servers over to the new domain, and the rest of the time imaging.

 

Having done it once now on this scale (my previous rebuild had all been primaries) I could probably do it all again in three weeks. There's probably no need to rebuild everything but it needed doing here as some of the workstation images were ancient and it's nice when everything's uniform. Staff laptops were the biggest pain because we have a mix of hardware and most staff wanted to use them over the summer, but this would vary from site to site.

 

We had some help from our LA moving SIMS to the new domain but there's plenty of documentation online, and to be honest it didn't look that complicated.

 

I think you pretty much have to use a different domain name - wouldn't like to risk using the same one. Think about workstation, user and server naming conventions before you jump. I got a big whiteboard installed in the office to make sure everyone knew what was happening.

 

Make yourself a list of all the hardware that references your current domain for DNS/IP settings and any currently assigned static IPs

 

We were office 365 anyway so no exchange to migrate (yey).

 

Keep SLT, your Data manager and especially your ICT-Co-ord in the loop with timescales etc, and make sure you have a full list of software that teaching staff need for lessons before you flatten everything.

 

Test as much as you can before the summer and make it clear to staff who want to work on site over the first few weeks that there won't be any ICT provision for them!

 

Good luck!

  • Thanks 1
Posted
Anyone like a nice trip up to the lakes to help out? You all seem like you know exactly how to do this! It'll be a big task for me and a newly appointed apprentice (starting in January)!
Posted

Did this last summer.

 

Started in the previous Nov/Dec, took time to try and understand the network and tried to resolved a number of issues. Decided end of Feb to start again from scratch. - Left the cabling/switches alone as this worked - plus I figured I could look at this after the network went live. (in hindsight I wish I had taken time to look at first - some niggling little issue appearing)

 

Started planning on paper what needed to be done (Information gathering exercise such as IP Details of any connected device - Looked at New internal domain name, IP Scheme, Server Names, naming convention etc..) and in what order things had to be done. Had regular meetings with Head of IT so I could keep him up to date with progress and any ideas I have. Also good way of getting feedback and finding out of what works best for staff etc.

 

At the beginning of May I started creating a small test network with a server (HyperV) and a number of different workstations/laptops - I imported some GPOs I wanted to keep and created some new ones from scratch. - Tested, Tested and then Tested some more! Also documented everything in a notebook which went everywhere with me.

 

Asked staff to come and try new settings and feedback so I could make changes etc.

 

Once happy with GPO, station builds etc.... I looked at data Migration.

 

Exported current network VMs and ran on test network so I could run various tests on migrating of data for both exchange user data without fear of breaking my live network.

 

D-Day - shutdown current VMs and exported them for safe keeping (incase of emergency etc)

 

Imported new VMs, tested connectivity added some workstations to make sure all working - then migrated data. - this took couple of days. Once happy with migration, then started reimaging workstations with new image.

 

The one thing I didn't test as I couldn't was Hyper-V Cluster and teamed nics.

 

Also reinstalled Smoothwall from scratch with new settings/IP Address.

 

Everything worked fine until the start of term where I had an issue with the teamed nics - Thankfully managed to get it resolved fairly quickly.

 

 

Currently have an issue with Wifi and cabling/switching infrastructure - I had intended to look at this after the new network was up and running.

 

Changed Wifi from using a shared key to X802 authentication so It works nicely with smoothwall - works will if you don't move around - I am investigating this at the moment.

 

Some areas of the school are slow - this is partly down to old switches (100mb) and due to the fact some switches are daisy chained!

 

 

So...... definitely doable - just make sure you test, document and keep staff informed.

  • Thanks 1
Posted
Anyone like a nice trip up to the lakes to help out? You all seem like you know exactly how to do this! It'll be a big task for me and a newly appointed apprentice (starting in January)!

 

Next summer I am actually booking a holiday! Probably not to the Lake District though - thanks for the offer.

 

It is a big task, but it's definitely worth doing. A lot of it can be set up in advance (KMS, Print servers, images, DCs) so that the minute the staff and kids walk out the door on the last friday of term you can start unplugging things.

Posted

Did it a few years ago migrating away from a domain riddled with Viglen Classlink

 

Same as others have said, I purchased a new VM host in the spring and spent any spare time up until the summer creating the barebones - 2 DCs, Exchange, GPOs, User accounts etc, pretty much everything setup except for data.

At the start of summer shut the network down completely, and migrated all the data over. Can't remember specifics of how I did it but presumably scripts for all the user data, and exported all Exchange mailboxes to PSTs then reimported to the new server.

Everything was up and running within a week - the rest of the summer was spent reimaging every client.

 

Only thing I regret was using a .local domain, with the chance to start from scratch I should have used our actual domain name.

Posted

Definatly on VM's

 

Personaly as a starting point I would use VMware free edition or "Essentials Plus"

 

Gone through all sorts of scenarios of network rebuilds in the last 7 years..

 

TT

Posted (edited)

I'm currently deciding on the same thing at the moment.

 

I look after one school which after working, nudging and prodding over a few years now works pretty well. There's a couple of little things that I don't particularly like still, but to be honest they are mainly cosmetic and only bug me because I know they are there. Everything else works bob on.

 

I'm now working at another school and the network works fine, but there are a few things that I am thinking would be far easier to rebuild the domain then spending a lot of time unpicking and doing again. The snag with this one is I don't have the funds to virtualise.

 

What I have in my head is if I'm going to do this, I'll build a new server up as the domain controller for the new domain. Create a trust between the current and new domain, migrate all the files across and then spend the time to setup the structure and GPO's how I want. In the next major holiday (probably Easter) build a room across to the new domain for testing (not worked out the user side of this yet, that needs more planning as I haven't investigated it). Monitor that until May half term and then gradually move things across to the new domain as time allows, leaving the summer to complete what needs to be done.

 

I'm probably going to decide exactly what to do after Christmas as I'm just too run down at the moment to think it through clearly. A domain rename and reverting the default GPO's might just do what I want but if I'm going to attempt a domain rename I go back to leaning more towards rebuilding from scratch.

 

The best thing I learnt from nudging and prodding the first network was it all worked and so I could spend the time nudging and prodding. It's effectively been rebuilt now without doing the full domain rebuild but I could spend the time to do that and learn all the little quirks it has and iron them out. You have a great platform in that being virtualised (and hopefully with Veeam) you can do a hell of a lot and revert back fairly easily if something does go drastically wrong.

Edited by Cache
Posted

In my last job we had to join a Netware 6.5/OES based network with a AD network maintaing all the good bits whislt avoiding unseteling a politicaly charged apple cart.

 

That was then moved to a new AD domain after 2.5 years over the space of 2-3 weeks with a new domain with user account anems having been changed (political) causing lots of re-mapping work to be done.

 

Then we added a second site to the domain from a third school again with the same name changes.

 

The 1st stage worked realy well, 2nd and 3rd caused a number of permisson issues.

 

 

If you think the domain is a mess then take the plunge, but build along side the existing and plan for a summer cut over. I no longer have the luxury of "SUMMER"

 

but over this summer we did do a seeamless migration of our systems from

 

old "NetAPP Filer" , "ESX 5.0 on Dell R810" "HP5406 Switch"

 

to

 

new "Netapp Filer" , "ESX 5.5 on Dell R730", "HP Comware 5700FF 10G" Switch.

 

Everything was migrated live with no downtime at all.

 

 

 

And VEEAM is cracking!!

 

TT

Posted

P.S.

 

If going virtual make sure you have 1 Physical DC, it's recomended that this is the FSMO roll holder.

 

As a guide we are presently being quoted...

 

Dual CPU 18 Core Dell R730, 256GB ram , 10Gb lan, (disks we dont care much about due to SAN) 5 year Warranty 24/7/365/4hr at about £11K that will easily run 40-50 VM's ... So scale that down a bit ;) (12core was about 4k cheaper) .

 

I forget what I used to pay years ago but we probably had 10 Physical servers that cost 2-3K each. And doing a hardware upgrade was a nightmare ( not with Virtual! )

 

TT

Posted (edited)

I had a project 3 summers ago and only 6 weeks to do the following as things had to remain as was until the holidays:

 

Merge 2 independent schools networks together - our backbone was 10gig fibre , theirs was 1gig copper so their half was upgraded. Set up a new domain for the 2 single domains to be migrated to 1 new one. Do layer 3 routing to migrate data/users over to the new network domain as both schools next to each other so 10gig link was installed between the 2 original server rooms for easy data migration.

 

 

Install and configure a new VOIP system on VLAN.

 

re-image 1000 pc's and join to the new domain.

 

Install Cat5e cabling for a new 30 PC IT suite.

 

All good fun! Wasn't a dull moment for those 6 weeks as well as taking 2 weeks annual leave so that left 4 weeks to do the above!

Edited by ITGURU
Posted

I've also done this in the past, its actually surprisingly quick to do these days with Hyper-V compared to how it used to be.

 

Definitely look at creating a test network with say 1 computer room. As for passwords, just reset everyone's and make them change it on start of term.

 

You can spend hours playing around with group policies, but there are tried and tested ways of locking down school computers. Just do a search around these forums for some nice threads.

Posted
P.S.

 

If going virtual make sure you have 1 Physical DC, it's recomended that this is the FSMO roll holder.

 

As a guide we are presently being quoted...

 

Dual CPU 18 Core Dell R730, 256GB ram , 10Gb lan, (disks we dont care much about due to SAN) 5 year Warranty 24/7/365/4hr at about £11K that will easily run 40-50 VM's ... So scale that down a bit ;) (12core was about 4k cheaper) .

 

I forget what I used to pay years ago but we probably had 10 Physical servers that cost 2-3K each. And doing a hardware upgrade was a nightmare ( not with Virtual! )

 

TT

 

A physical DC is no longer required if you go to server 2012 or higher. It's well worth it to do that anyway as AD is much more robust on those and don't have the time issues etc.

Posted

I have 2 prime reasons.

 

1) Time sync is crap on a virtual DC and causes all sorts of problems. Time problems extended to our NETAPP filers and other systems that referenced the Virtual DC.

 

We now run 2 Physical Linux Time Servres(on at Prime and one at DR site) and the Physical PDC-E gets time from them.

 

2) in the event of a catastrophic failure of the Hypervisor Cluster, I still want to be able to log into my PC easily to begin trouble shooting.

 

TT

Posted
Weird, never had a problem on our VMWare virtual servers with time synch. If we lost our main Virtual hosts we have a live DC on our DR side, much easier than having a hardware failure on a physical DC.
Posted

Internet is littered with time issues on Vmware. It may have improved on 5.5 which we moved to in the summer.

 

Our XenServer farm was also getting well out of sync.

 

I found these after I started with the company in Feb2014 and after attempting a number of fixes the combination of the Linux NTP servers and Physical DC have fixed all time issues with the exception of the Phone systems that is always ~15s behind!

 

TT

Posted
I have 2 prime reasons.

 

1) Time sync is crap on a virtual DC and causes all sorts of problems. Time problems extended to our NETAPP filers and other systems that referenced the Virtual DC.

 

We now run 2 Physical Linux Time Servres(on at Prime and one at DR site) and the Physical PDC-E gets time from them.

 

2) in the event of a catastrophic failure of the Hypervisor Cluster, I still want to be able to log into my PC easily to begin trouble shooting.

 

TT

 

Didn't have a problem with time sync on virtual DCs once I had turned off sync time with host in the virtual machine options

  • 3 months later...
Posted

I know this is adding to an old thread, but this is something I've been tasked to do. At the moment we have a shared domain for staff and students using NTFS permissions and VLAN's with Access Control Lists locking down student access to certain areas.

 

Today, I have been asked by the principal to look at a wholly separate domain for students which I think will be a management nightmare given the number of applications we use which traverse domains. I was wondering are any other schools doing this and can you see any benefits as it is something I cannot really see being any use to us however we moved from a rather rubbish external IT provider who keep sticking their oar into the school as we still licence a few applications from them. Using NTFS permissions, VLANs and Group Policies we shouldn't need to do this but wondering what others think.

 

Any advice is greatly appreciated.

Posted
I know this is adding to an old thread, but this is something I've been tasked to do. At the moment we have a shared domain for staff and students using NTFS permissions and VLAN's with Access Control Lists locking down student access to certain areas.

 

Today, I have been asked by the principal to look at a wholly separate domain for students which I think will be a management nightmare given the number of applications we use which traverse domains. I was wondering are any other schools doing this and can you see any benefits as it is something I cannot really see being any use to us however we moved from a rather rubbish external IT provider who keep sticking their oar into the school as we still licence a few applications from them. Using NTFS permissions, VLANs and Group Policies we shouldn't need to do this but wondering what others think.

 

Any advice is greatly appreciated.

 

Has the principle said why they want this? It's an odd request from someone in that position. I'd be asking them what exactly it is that they're trying to achieve and find a better way of doing it, if it needs doing at all.

Posted
Has the principle said why they want this? It's an odd request from someone in that position. I'd be asking them what exactly it is that they're trying to achieve and find a better way of doing it, if it needs doing at all.

 

Morning,

 

The company we moved away from IT Support (before I started) does this in other schools and believes anything else is a security risk. With the correct management in place on our current setup I cannot see this improving things at all.

 

Thanks,

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...