rom1984 Posted May 9, 2017 Posted May 9, 2017 Hi, I'm part of a trust of 3 primary schools and over the summer we are going to create one trust domain rather than each school having their own. 1 school is approx 500 pupils and the other two are 400 pupils each. I've planned that each school has a DC on site that is replicated over an IPSEC VPN. My question is, do you think it would be better to have a DHCP/DNS server installed at each site or would it be better to have the DNS/DHCP Server at one central school? I've got in my head that it will be better to have it installed at each school but I'm second guessing my self thinking having 3 DHCP/DNS servers would be overkill? One of the main caveats that the governors and SLT team have said is that an internet failure at the main school would not prevent another school from authenticating/accessing resources. Hope that makes sense!
jaminben Posted May 9, 2017 Posted May 9, 2017 (edited) We installed an RODC at each of our sites... each with their own DHCP and DNS roles (using different subnets). Using this method we can disconnect one site (lose network connection) and they can still login and access all their local data etc... they just can't use the internet until the connection is restored. Edited May 9, 2017 by jaminben 1
rom1984 Posted May 9, 2017 Author Posted May 9, 2017 Cheers Jaminben - so do you have the DNS server that is "on-site" set as the primary and then for the secondary do you just use another schools DNS? Was there any deciding factor that made you go for a read only DC?
jaminben Posted May 9, 2017 Posted May 9, 2017 so do you have the DNS server that is "on-site" set as the primary and then for the secondary do you just use another schools DNS? Yes, we set the primary to the local and the secondary to the main high school. Was there any deciding factor that made you go for a read only DC? Security was the only real consideration.
localzuk Posted May 9, 2017 Posted May 9, 2017 This is how we're implementing it in our 6 school trust. The diagram isn't complete but it is a start. Each site has direct internet access, with a VPN to the core sites for core services. So, each site will be able to run should internet go down at the individual school or at the central school. All files will be stored on our central servers, and DFSR'd over to any site where a member of staff works (gotta figure that one out yet but shouldn't be too hard). 1
MatthewL Posted May 9, 2017 Posted May 9, 2017 DC, DNS and DHCP on each site then if connection does go down you can still work. A MPLS cloud is ideal for this, connectivity between each site but internet connection if one of the links fails between sites. 1
GroovyNerd Posted May 9, 2017 Posted May 9, 2017 We installed an RODC at each of our sites... each with their own DHCP and DNS roles (using different subnets). Using this method we can disconnect one site (lose network connection) and they can still login and access all their local data etc... they just can't use the internet until the connection is restored. This is how I do it. Managing 30+ schools 1
snagrat Posted May 9, 2017 Posted May 9, 2017 We are doing exact same thing for a number of MATs but using a server in Azure to act as a DC This doesn't easily allow document sharing but Office 365 is used for that. This method allows for any school on any connection join up to the single domain without additional hardware costs 1
rom1984 Posted May 10, 2017 Author Posted May 10, 2017 Thanks for all the input people - DC, DNS & DHCP per school it is then!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now