Jump to content

Recommended Posts

Posted

Firstly, School Broadband have already passed on their thoughts on this but wanted to see what others think.

 

We have 12 schools connected as a single domain. All schools will be on a VPLS and we have a VPN from each school to Azure where a DC resides.

 

For those that don’t know, SB/Netsweeper require an authentication portal to be installed on a server in the domain. Most schools will have this on their DC as a very lightweight program. A DNS entry is then created for authportal to point to the IP the portal is configured on. The portal is used to authenticate windows machines into Netsweeper.

 

As we are one domain we can’t have a authportal in each school and configure DNS to point to each server. So I have be looking at the solution:

 

Option 1 - setup a server for authportal and put in one of the schools. No school acts as a datacenter per say, but some have better internet connections than others

 

Option 2 - Put it on the server in Azure.

 

The only cons of each are that it the authportal is not reachable the machines will not authenticate to the Internet. That is why the Azure solution seems better.

 

However, how much traffic is generated by the authentication process as we will be paying for data out of Azure.

 

I would welcome peoples opions

Posted
Could you not use a read only dc

 

I can, it doesn’t even have to be a DC.

 

But the point is where is the best to put it for performance and reliability

Posted

To increase reliability into Azure we could install a Microsoft Expressroute for your trust as this gives an sla and guaranteed bandwidth into Microsoft too from our network over and above peering and ipsec vpns. Also as it's a Trust are all the schools not in the same virtualised Fortigate firewall? That would make ipsec vpn set up and expressroute setup much more simple.

 

Dave

Posted
To increase reliability into Azure we could install a Microsoft Expressroute for your trust as this gives an sla and guaranteed bandwidth into Microsoft too from our network over and above peering and ipsec vpns. Also as it's a Trust are all the schools not in the same virtualised Fortigate firewall? That would make ipsec vpn set up and expressroute setup much more simple.

 

Dave

 

ExpressRoute - not unless you are giving for free!! It’s mighty expensive.

 

Yes all schools will be on the same VDOM so will only be one IPSEC VPN to Azure once the migrations are completed.

 

Out of interest what speed would a VPN from the fortinet to Azure be running at?

Posted
Just stumbled on this thread - I use fortigate Wi-fi. Controllers for my schools and I see you mention a fortigate firewall service. Is this a standard for schools broadband delivery?
Posted

Hi @johnpd. Fortigate firewalls are available as standard on 95% of our product range. You can use Fortigate Wi-Fi access points on our hosted firewalls if you want to. Best check the model and firmware versions with our technical consultants first but we already have hundreds of APs attached to our hosted firewalls already.

 

Dave

Posted
Or, you could create a new DNS zone for the full server address (blah.domain.com) in each site and have it not be AD integrated. Then a non-named A record will allow you to have a different response in each site.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...