AndyGibs Posted October 14, 2018 Posted October 14, 2018 Okay so the school is running two networks an admin office network and a education network for computer rooms and classrooms this was designed so that user account elevation wouldn’t be a security risk to the sensitive info on the admin network. Their are talks now about merging the network together again with new windows 2016 servers. Should I advise against this. Or if I move all seanative info into hidden network folders (as they should anyway) should this be okay are their extra measures that I can take to protect against this type of elevated attack?
Jaan Posted October 14, 2018 Posted October 14, 2018 We did this year's ago. We have a single network with the relevant NTFS permissions, hidden shares, and user specific mapped drives. We also use a feature where if a user doesn't have read access, they can't see the folders in explorer. Can't remember it's funky name. Also running 2016. We've never had a problem. But we also introduced staff only machines where students are unable to log into them.
6Foot2 Posted October 14, 2018 Posted October 14, 2018 ...We also use a feature where if a user doesn't have read access, they can't see the folders in explorer. Can't remember it's funky name... Access Based Enumeration. https://www.youtube.com/watch?v=Tzjm4V-Of-k
mavhc Posted October 14, 2018 Posted October 14, 2018 Administrating 2 networks takes longer. Plus teachers end up on both networks. There are ways to half split them, use different subnets, so they can be on 2 different ethernet networks but still on the same domain. Put rules so only office staff can log into office computers, etc
Jamman960 Posted October 14, 2018 Posted October 14, 2018 (edited) In my experience many schools had separate reworks originally and often had them managed by different suppliers, usually whoever the school wanted for the curriculum network and the la for the admin one. It made sense to some extent but now there’s much more crossover between admin and curriculum so it became pointless separating them, support providers now tend to support the whole lot now also. As above with the correct permissions setup a single network is just as secure as separate ones and has the benefit of costing less in tech time and hardware . Edited October 14, 2018 by Jamman960
3s-gtech Posted October 14, 2018 Posted October 14, 2018 We had two, many years ago. They were eventually moved onto the same range, merged and integrated so that they're a forest and child domain. It works very well so I've never bothered to change it - all services like Azure AD etc just work from the forest level down so it's no more work. It does require more DCs, that's about it. If building from scratch, I'd never recommend it though - you can achieve everything you need using ACLs and GP.
witch Posted October 15, 2018 Posted October 15, 2018 We merged ours several years ago, and have just one network now. Permissions are set so that nobody can see the admin stuff except admin, and me. Works fine
Michael Posted October 15, 2018 Posted October 15, 2018 I believe it was all to do with security and needs back then. MIS systems were reserved for office personnel only, with every else done on paper. These days it's completely different, with the MIS branching out to all the network/school. I believe the other reason was permissions - the likes of Windows 95 and 98 didn't support NTFS, but only FAT, but could read NTFS permissions over a network. Having two subnets was considered more secure (and I suppose it is), unless you create a VLAN between the two, so then bringing everything natively onto one subnet made sense!
FishCustard Posted October 15, 2018 Posted October 15, 2018 Get rid of Admin and Curric networks with all haste. Nuke 'em from orbit. It made sense in the 1990s because the security options available in Windows weren't as robust as they are now. These days they make less than zero sense - they make everything harder. 1
mavhc Posted October 15, 2018 Posted October 15, 2018 Also the office maybe had dialup to the council, whereas the school had something else. Our office share has a folder for wordperfect files
witch Posted October 15, 2018 Posted October 15, 2018 Historically, both my schools had two networks - the admin side was supported by the LEA and they did SIMS support and whatever else was needed. Both schools went over to one network. In one, they chose the LEA to support it - which is why I am not there anymore - and in the other, they chose ME
AndyGibs Posted October 24, 2018 Author Posted October 24, 2018 Thanks for the info everyone. I am definitely going to move to just the one network now once I bring the new server in. I had a feeling way more could be done to protect.
MatthewL Posted October 24, 2018 Posted October 24, 2018 Merge it into one, just more admin and hassle. Things have developed since the days of Windows 95/98.
FragglePete Posted October 25, 2018 Posted October 25, 2018 Ditto what everyone says - was the same at my place. Two networks, two lots of credentials for a range of staff (not all). Ended creating a trust between the two domains initially so we could start doing Lesson Monitor in SIMS for all classroom teachers and then eventually nuked the Admin network when SIMS was migrated to a new server on the Curriculum network. Never looked back. Pete
Rob_D Posted October 25, 2018 Posted October 25, 2018 Just to offer a contrasting point of view: The first school I worked in had a split network. County managed the admin network I managed the curriculum one. Sometimes I ended up troubleshooting the printers and such on the admin side, but it was no more hassle than fixing it on the curriculum network. So.. Are you being asked to manage (or are currently managing) both networks? Is there something wrong with the Admin network? If the answer to these is "no", then I'd leave it as is. If the answer is yes, then fair enough, go for it.
djm968 Posted October 25, 2018 Posted October 25, 2018 First school I worked for back in 1994 had separate admin and curriculum networks. The first major project I completed was to merge the two networks. The old admin network was also running on 10BASE2 Ethernet!
Patrick Posted October 26, 2018 Posted October 26, 2018 Most of my schools have a split network, we have a domain trust where needed. The admin network is maintained by county and i'm happy to leave it alone and let me them manage the network/sims. It comes as part of a package so until the say otherwise i'll leave it be, if it aint broke an all that.
mavhc Posted October 28, 2018 Posted October 28, 2018 Yeah, but it's managed by people who don't care about your school, they won't have bothered to get SRP/AppLocker working etc
nathan3388 Posted October 28, 2018 Posted October 28, 2018 Cannot believe people still separate the networks. It becomes a pain to manage and people want to use different computers and access there files just becomes a nightmare. So I would merge them into one
Rob_D Posted October 28, 2018 Posted October 28, 2018 Cannot believe people still separate the networks. It becomes a pain to manage and people want to use different computers and access there files just becomes a nightmare. So I would merge them into one I think it depends on the size and structure of the school. The last school I was at with a split network was fairly small (single form entry primary) with 2 office staff. Domain trust allowed them to access the curriculum shares and none of the teaching staff needed access to anything on the admin network. There was practically no management from my point of view. So if the choice is between keeping on with something that works fine and that I never need to touch and having to adopt the SIMS server, I know what I'm leaning toward. (Hint, it's me not having to touch SIMS) Where as, the 1500 pupil secondary I'm at now would be a nightmare to run with a split domain.
Patrick Posted October 29, 2018 Posted October 29, 2018 I would never build a new network like it, but as i said, the LEA completely looks after the admin network. SIMS A/V windows updates etc. It's easier to leave it up to them to manage. Also, we are talking small primaries with about 3 admin PC's.
jimmy_2k Posted October 30, 2018 Posted October 30, 2018 When I was at school we had 3 separate networks in different buildings. These were using different topologies. 10BaseT in one, Econet in the other and 25 Pin serial. 2 were Acorn Risc OS the other Microsoft
mavhc Posted October 30, 2018 Posted October 30, 2018 I would never build a new network like it, but as i said, the LEA completely looks after the admin network. SIMS A/V windows updates etc. It's easier to leave it up to them to manage. Also, we are talking small primaries with about 3 admin PC's. Except they can read and write your shared files, so ransomware is still a problem
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now