Jump to content

Recommended Posts

Posted

We are a private apprenticeship provider based in the UK with 41 academies including head office. Each academy range from 1 – 3 classrooms – with the exception of 2x 4 classroom academies. Classrooms have an average of 25 desktops in each. Our HO has around 40 staff.

 

The board have asked us to look into moving all existing infrastructure to the cloud. As a result of this, we have been looking at combining Windows 10 with Office 365, Intune (EMS) and Azure Active Directory. The plan will also include some application deployments in Azure (Incl. our business-critical LMS/Portfolio application Maytas/E-Track).

 

At the moment, each academy has its own isolated network with an on-site DC which runs DNS and DHCP.

 

 

  • There is no site-to-site link at all.
  • The DC runs active directory for the classroom PC’s on that site ONLY – we have no central active directory.
  • ALL staff laptops/desktops across all academies + head office are either on a workgroup, or connected to Azure AD – head office is a mess as we have no control (i.e. AD DS)

 

An MPLS solution has been at the top of the plan for months now, but after countless hours of reading, it appears SD-WAN is the way to go…especially as most of our infrastructure will be delivered as-a-service (Azure). However, we are still confused as to why we wouldn’t just simply set up a site-to-site VPN (Using Cisco Meraki or equivalent) instead of the SD-WAN solution?

 

Please also bear in mind that we already have Office 365 E3 licenses which all staff currently use for email, sharepoint and Skype for Business. We are also looking to deploy Skype for Business as our PBX solution in the near future.

 

What comms+WAN solution do you guys think best fits our design?

Posted

No matter how you look at it, having everything in the cloud is going to require huge bandwidth at each site. A 1Gb lease line is still pretty expensive - it's still currently more cost effective to have servers in-house, be it a single forest, separate domains or even a single forest single domain configuration.

 

Personally I still think MPLS is the way to go; it's your private network so you can do as you please, whereas SD-WAN is somewhat more complicated, especially from a security point of view, site to site VPN or other is recommended.

 

You could debate that implementing a 100Mb PTP configuration would centralise the Trust's requirements with servers at each site. In time as prices come down, on site servers are then replaced with 1Gb PTP with everything centralised. That's not to say you can't have 'some' functionality in the cloud, but everything in the cloud just isn't viable in practice in my experience.

 

Schools are pretty unique in the sense of a group of pupils will all logon or all access a resource at once, whereas in a Business environment, everyone generally works independently. You'll see less traffic surges and it's something that's difficult to avoid in an Educational environment.

Posted

Hi Jayswarve

 

Without knowing more about your specific requirements, particularly around real-time coms, it's difficult to say, but for your main Microsoft application suite and device count my initial thoughts lean towards an Internet Facing service and a Site to Site VPN architecture. We can provide MPLS, Azure Express Route or filtered secure Internet with a meshed VPN solution, and have done for many schools and MATs. Happy to provide advice and info around federating your MS environment too.

 

If you would like a discussion or some outline budgetary solution/pricing, please feel free to contact me,

 

regards

Lee

Posted
MPLS is much more efficient on bandwith as there is no encryption or compression overheads. also a doddle to setup. I used Timico for there PWAN service with about 30 sites and had some servers in there data center
Posted

Very high level we'd recommend an MPLS WAN utilising with hosted firewalls (shared or dedicated) in a providers data centre. From there as you're so reliant on Microsoft Azure and Office 365 based services then you may also wish to purchase a Microsoft Express Route port which gives you guaranteed 1:1 bandwidth into Microsoft and allows you to do QOS all the way to them rather than over general ISP peering links.

 

We've already quoted large MAT's on this solution and I expect some of them to take us up on our offer soon.

 

Point to point links may be a good idea if you have any sites close to one another. I'd also recommend checking what your actual bandwidth utilisation is at the moment on all of your links too.

 

Don't use normal FTTC whatever you do as there's no proper quality of service of bandwidth guarantees on that service. Look at EoFTTC or leased lines.

 

Prices for Ethernet leased lines have come down a lot of late and will do again, particularly in 2018 with the release of the BT Dark Fibre product.

 

Using VPN encryption puts a slight packet overhead on communications but none you'd probably notice, particularly when on a decent speed leased line.

 

We've a number of clients with 40+ sites (our largest being about 85) utilising their own MPLS WAN doing exactly what you're after so feel free to get in touch if you'd like some advice or an introductory meeting.

 

Thanks

 

Dave

Posted

I suspect a few. Ironically the large ones I spoke about haven't had any issues and we've actually been praised by their technical team of late for providing a rock solid service and good support.

 

More people always say bad things than good things. I can say that as we have so many customers then 5% of 2,000 is a lot more than 5% of 100 so more will be vocal.....

 

Still we must always do better. Thank you for those that have been continually supporting us.

 

Dave

Posted

We are. Nothing is more important than to fix things when they go wrong and its all our engineers are doing at the moment to get this issue resolved. We've quite a few of them camped in Telecity over the weekend.

 

New customers aren't on this affected hardware and as much as I like and respect our sales department I really wouldn't want them fixing core Fortigate firewalls anyway :)

 

Dave

Posted

Of course it's not. The hardware issues with one of the Fortigates have only occurred this week. Good news is that the replacement unit has been installed yesterday evening so as per my other post we'll be monitoring closely over the next week.

 

Dave.

  • 1 year later...
Posted
Hi, this was a long time ago, so perhaps things have changed? Our MAT has only two schools, but a third is on the horizon. We are looking to move to a single IT service provider, and all sites will use SIMS. The schools each have up to 500 students. I have been asked to look into general approaches for linking the sites, which are a few miles apart (if this makes any difference!). The only decision that has been made is that we do not wish to use cloud services for applications or data storage. We of course want as much simplicity as possible, with reduced costs. Like the OP, most articles on the internet point towards SD-WAN, which is clearly not the preference of you guys for some reason! Any thoughts would be appreciated.
Posted

In my opinion for best speeds and value for money you want to put a big leased line in one connection and then BT Ethernet access direct (EAD) point to point links atn100mbit or 1gbit. They are very affordable and allow you to share internet bandwidth from the main site and also transfer files intersite very quickly.

 

We've done dozens of these in the same situation you describe. You can even terminate them on your own switches rather than our routers if you like.

 

Happy to help look at your requirements and help design something for you. I'll send you a pm.

 

Dave

  • Thanks 1
Posted
Hi, this was a long time ago, so perhaps things have changed? Our MAT has only two schools, but a third is on the horizon. We are looking to move to a single IT service provider, and all sites will use SIMS. The schools each have up to 500 students. I have been asked to look into general approaches for linking the sites, which are a few miles apart (if this makes any difference!). The only decision that has been made is that we do not wish to use cloud services for applications or data storage. We of course want as much simplicity as possible, with reduced costs. Like the OP, most articles on the internet point towards SD-WAN, which is clearly not the preference of you guys for some reason! Any thoughts would be appreciated.

 

Hi John,

 

I don't believe SDWAN is appropriate for most UK customers, never mind schools. The development of SDWAN technology (hardware) is great for multi-nationals, and particularly in countries where the difference in price between Direct Internet Access and MPLS is large. The reality is (in the UK at least) is that the telcos and resellers pricing model has changed to such a large extent that MPLS is the same price as Direct Internet Access here, so your network provider can generally accomplish most of what SDWAN can, for a fraction of the cost. As Dave (SB) says, you can use P2P links if schools are close together, or a mix of VPN, Cloud or whatever. I think the key thing is to choose a solution that supports your current and future (or at least 3-5 yrs worth) requirements and is resilient.

 

Despite the underlying monopoly of (mostly) Openreach and Virginmedia, competition has forced carriers and resellers to innovate and discount.

Posted
What is SD-WAN anyway? People seem to have 100 meanings for it

 

I mean it to be SD-WAN hardware, which dynamically monitors and manages the state of your connection(s) and routes applications/traffic accordingly. Some ISPs are starting to deploy 'SD-WAN' on their own network, which on that context usually means more visibility/management/flexibility for resellers/customers. This is a slightly different prospect.

 

I'm sure there are other definitions out there : )

Posted

SD WAN can be useful for sites where connectivity is expensive. I think its more of a nice to have than everyone needs it. We are starting to see some schools request this in quotes. But there's a premium to pay which is mostly in the customer premise equipment to do it properly which with schools budgets as they are I suspect most will not want to pay.

 

The one thing I do like about SD WAN is the ability to use two or more links at the same time which is useful. A secondary school could buy say a 200Mbit leased line but have a secondary 330Mbit G.Fast connection. Put all critical apps and latency sensitive apps down the leased line and other apps and general browsing down the G.Fast connection. We can then also put each circuit using different carriers too for extra resiliency.

 

Again though, will people pay for it or not?!

 

Dave

Posted
The Fortigate 60E we got for £370 seems to have that option, 2 internet links, share between them, can set a ratio, and failover I guess
Posted
The Fortigate 60E we got for £370 seems to have that option, 2 internet links, share between them, can set a ratio, and failover I guess

 

We regularly deploy that with our service (using Sophos UTM). I think one of the key differences is that SD-WAN appliance is able to monitor link status and manage traffic routing based on the requirements of the application. So for instance, if both links we able to support QOS for voice and one link became degraded to an extent (i.e. not enough to 'fail'), SD-WAN would route traffic up the 'better' link. Firewall load-balancing is a bit more rudimentary.

 

Again, one of those things that, of it were available cheaply, would be nice to have - but not worth the current cost (IMO)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...