Jump to content

Recommended Posts

Posted
Okay so the school is running two networks an admin office network and a education network for computer rooms and classrooms this was designed so that user account elevation wouldn’t be a security risk to the sensitive info on the admin network. Their are talks now about merging the network together again with new windows 2016 servers. Should I advise against this. Or if I move all seanative info into hidden network folders (as they should anyway) should this be okay are their extra measures that I can take to protect against this type of elevated attack?
Posted
We did this year's ago. We have a single network with the relevant NTFS permissions, hidden shares, and user specific mapped drives. We also use a feature where if a user doesn't have read access, they can't see the folders in explorer. Can't remember it's funky name. Also running 2016. We've never had a problem. But we also introduced staff only machines where students are unable to log into them.
Posted

Administrating 2 networks takes longer. Plus teachers end up on both networks.

 

There are ways to half split them, use different subnets, so they can be on 2 different ethernet networks but still on the same domain. Put rules so only office staff can log into office computers, etc

Posted (edited)

In my experience many schools had separate reworks originally and often had them managed by different suppliers, usually whoever the school wanted for the curriculum network and the la for the admin one. It made sense to some extent but now there’s much more crossover between admin and curriculum so it became pointless separating them, support providers now tend to support the whole lot now also.

 

As above with the correct permissions setup a single network is just as secure as separate ones and has the benefit of costing less in tech time and hardware .

Edited by Jamman960
Posted

We had two, many years ago. They were eventually moved onto the same range, merged and integrated so that they're a forest and child domain. It works very well so I've never bothered to change it - all services like Azure AD etc just work from the forest level down so it's no more work. It does require more DCs, that's about it.

 

If building from scratch, I'd never recommend it though - you can achieve everything you need using ACLs and GP.

Posted
We merged ours several years ago, and have just one network now. Permissions are set so that nobody can see the admin stuff except admin, and me. Works fine
Posted

I believe it was all to do with security and needs back then.

 

MIS systems were reserved for office personnel only, with every else done on paper. These days it's completely different, with the MIS branching out to all the network/school.

 

I believe the other reason was permissions - the likes of Windows 95 and 98 didn't support NTFS, but only FAT, but could read NTFS permissions over a network.

 

Having two subnets was considered more secure (and I suppose it is), unless you create a VLAN between the two, so then bringing everything natively onto one subnet made sense!

Posted
Get rid of Admin and Curric networks with all haste. Nuke 'em from orbit. It made sense in the 1990s because the security options available in Windows weren't as robust as they are now. These days they make less than zero sense - they make everything harder.
  • Thanks 1
Posted

Also the office maybe had dialup to the council, whereas the school had something else.

 

Our office share has a folder for wordperfect files

Posted

Historically, both my schools had two networks - the admin side was supported by the LEA and they did SIMS support and whatever else was needed.

Both schools went over to one network. In one, they chose the LEA to support it - which is why I am not there anymore - and in the other, they chose ME :)

  • 2 weeks later...
Posted
Thanks for the info everyone. I am definitely going to move to just the one network now once I bring the new server in. I had a feeling way more could be done to protect.
Posted

Ditto what everyone says - was the same at my place. Two networks, two lots of credentials for a range of staff (not all). Ended creating a trust between the two domains initially so we could start doing Lesson Monitor in SIMS for all classroom teachers and then eventually nuked the Admin network when SIMS was migrated to a new server on the Curriculum network. Never looked back.

 

Pete

Posted

Just to offer a contrasting point of view:

The first school I worked in had a split network. County managed the admin network I managed the curriculum one. Sometimes I ended up troubleshooting the printers and such on the admin side, but it was no more hassle than fixing it on the curriculum network.

So..

Are you being asked to manage (or are currently managing) both networks?

Is there something wrong with the Admin network?

If the answer to these is "no", then I'd leave it as is. If the answer is yes, then fair enough, go for it.

Posted
First school I worked for back in 1994 had separate admin and curriculum networks. The first major project I completed was to merge the two networks. The old admin network was also running on 10BASE2 Ethernet!
Posted
Most of my schools have a split network, we have a domain trust where needed. The admin network is maintained by county and i'm happy to leave it alone and let me them manage the network/sims. It comes as part of a package so until the say otherwise i'll leave it be, if it aint broke an all that.
Posted
Cannot believe people still separate the networks. It becomes a pain to manage and people want to use different computers and access there files just becomes a nightmare. So I would merge them into one :)
Posted
Cannot believe people still separate the networks. It becomes a pain to manage and people want to use different computers and access there files just becomes a nightmare. So I would merge them into one :)

 

I think it depends on the size and structure of the school. The last school I was at with a split network was fairly small (single form entry primary) with 2 office staff. Domain trust allowed them to access the curriculum shares and none of the teaching staff needed access to anything on the admin network. There was practically no management from my point of view. So if the choice is between keeping on with something that works fine and that I never need to touch and having to adopt the SIMS server, I know what I'm leaning toward. (Hint, it's me not having to touch SIMS)

 

Where as, the 1500 pupil secondary I'm at now would be a nightmare to run with a split domain.

Posted
I would never build a new network like it, but as i said, the LEA completely looks after the admin network. SIMS A/V windows updates etc. It's easier to leave it up to them to manage. Also, we are talking small primaries with about 3 admin PC's.
Posted
When I was at school we had 3 separate networks in different buildings. These were using different topologies. 10BaseT in one, Econet in the other and 25 Pin serial. 2 were Acorn Risc OS the other Microsoft
Posted
I would never build a new network like it, but as i said, the LEA completely looks after the admin network. SIMS A/V windows updates etc. It's easier to leave it up to them to manage. Also, we are talking small primaries with about 3 admin PC's.

 

Except they can read and write your shared files, so ransomware is still a problem

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...