snagrat Posted February 18, 2018 Posted February 18, 2018 Firstly, School Broadband have already passed on their thoughts on this but wanted to see what others think. We have 12 schools connected as a single domain. All schools will be on a VPLS and we have a VPN from each school to Azure where a DC resides. For those that don’t know, SB/Netsweeper require an authentication portal to be installed on a server in the domain. Most schools will have this on their DC as a very lightweight program. A DNS entry is then created for authportal to point to the IP the portal is configured on. The portal is used to authenticate windows machines into Netsweeper. As we are one domain we can’t have a authportal in each school and configure DNS to point to each server. So I have be looking at the solution: Option 1 - setup a server for authportal and put in one of the schools. No school acts as a datacenter per say, but some have better internet connections than others Option 2 - Put it on the server in Azure. The only cons of each are that it the authportal is not reachable the machines will not authenticate to the Internet. That is why the Azure solution seems better. However, how much traffic is generated by the authentication process as we will be paying for data out of Azure. I would welcome peoples opions
snagrat Posted February 18, 2018 Author Posted February 18, 2018 Could you not use a read only dc I can, it doesn’t even have to be a DC. But the point is where is the best to put it for performance and reliability
SchoolsBroadband Posted February 18, 2018 Posted February 18, 2018 To increase reliability into Azure we could install a Microsoft Expressroute for your trust as this gives an sla and guaranteed bandwidth into Microsoft too from our network over and above peering and ipsec vpns. Also as it's a Trust are all the schools not in the same virtualised Fortigate firewall? That would make ipsec vpn set up and expressroute setup much more simple. Dave
snagrat Posted February 18, 2018 Author Posted February 18, 2018 To increase reliability into Azure we could install a Microsoft Expressroute for your trust as this gives an sla and guaranteed bandwidth into Microsoft too from our network over and above peering and ipsec vpns. Also as it's a Trust are all the schools not in the same virtualised Fortigate firewall? That would make ipsec vpn set up and expressroute setup much more simple. Dave ExpressRoute - not unless you are giving for free!! It’s mighty expensive. Yes all schools will be on the same VDOM so will only be one IPSEC VPN to Azure once the migrations are completed. Out of interest what speed would a VPN from the fortinet to Azure be running at?
SchoolsBroadband Posted February 18, 2018 Posted February 18, 2018 It'll go as quick as the routing allows via our peers which will be a minimum of 10gbit. The big Fortigates have excellent ipsec throughput Dave
johnpd Posted February 18, 2018 Posted February 18, 2018 Just stumbled on this thread - I use fortigate Wi-fi. Controllers for my schools and I see you mention a fortigate firewall service. Is this a standard for schools broadband delivery?
SchoolsBroadband Posted February 19, 2018 Posted February 19, 2018 Hi @johnpd. Fortigate firewalls are available as standard on 95% of our product range. You can use Fortigate Wi-Fi access points on our hosted firewalls if you want to. Best check the model and firmware versions with our technical consultants first but we already have hundreds of APs attached to our hosted firewalls already. Dave
Domino Posted February 19, 2018 Posted February 19, 2018 Or, you could create a new DNS zone for the full server address (blah.domain.com) in each site and have it not be AD integrated. Then a non-named A record will allow you to have a different response in each site.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now