Jump to content

Recommended Posts

Posted

Hi,

I'm part of a trust of 3 primary schools and over the summer we are going to create one trust domain rather than each school having their own. 1 school is approx 500 pupils and the other two are 400 pupils each.

 

I've planned that each school has a DC on site that is replicated over an IPSEC VPN. My question is, do you think it would be better to have a DHCP/DNS server installed at each site or would it be better to have the DNS/DHCP Server at one central school?

 

I've got in my head that it will be better to have it installed at each school but I'm second guessing my self thinking having 3 DHCP/DNS servers would be overkill?

 

One of the main caveats that the governors and SLT team have said is that an internet failure at the main school would not prevent another school from authenticating/accessing resources.

 

Hope that makes sense!

Posted (edited)
We installed an RODC at each of our sites... each with their own DHCP and DNS roles (using different subnets). Using this method we can disconnect one site (lose network connection) and they can still login and access all their local data etc... they just can't use the internet until the connection is restored. Edited by jaminben
  • Thanks 1
Posted
Cheers Jaminben - so do you have the DNS server that is "on-site" set as the primary and then for the secondary do you just use another schools DNS? Was there any deciding factor that made you go for a read only DC?
Posted
so do you have the DNS server that is "on-site" set as the primary and then for the secondary do you just use another schools DNS?
Yes, we set the primary to the local and the secondary to the main high school.

Was there any deciding factor that made you go for a read only DC?
Security was the only real consideration.
Posted

This is how we're implementing it in our 6 school trust. The diagram isn't complete but it is a start. Each site has direct internet access, with a VPN to the core sites for core services. So, each site will be able to run should internet go down at the individual school or at the central school.

 

All files will be stored on our central servers, and DFSR'd over to any site where a member of staff works (gotta figure that one out yet but shouldn't be too hard).

 

Plan.png

  • Thanks 1
Posted
DC, DNS and DHCP on each site then if connection does go down you can still work. A MPLS cloud is ideal for this, connectivity between each site but internet connection if one of the links fails between sites.
  • Thanks 1
Posted
We installed an RODC at each of our sites... each with their own DHCP and DNS roles (using different subnets). Using this method we can disconnect one site (lose network connection) and they can still login and access all their local data etc... they just can't use the internet until the connection is restored.

This is how I do it. Managing 30+ schools

  • Thanks 1
Posted

We are doing exact same thing for a number of MATs but using a server in Azure to act as a DC

 

This doesn't easily allow document sharing but Office 365 is used for that.

 

This method allows for any school on any connection join up to the single domain without additional hardware costs

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...