Jump to content

Recommended Posts

Posted

> Network admins were asking for more and more from it.

 

The problem with that is that the more you add the less simple it gets. Ultimately, why would you spend extra money buying something that essentially substitutes one pile of complexity with another?

 

[A tangential issue is that the vanilla admin tools have inevitably been less buggy than anyone else's]

 

> So third parties like RM with CC4 still have a very relevant product.

 

Non-BSF CC4 progress in the world, especially CC4 whenever it gets around to running on 2K8 will be interesting. FWIW if a couple of the changes I've heard about turn out to be true I'll retire from challenging the Can't Do X-ers because they'll be right, although not necessarily for their reasons.

Guest monkeyx
Posted
No it isn't, that means nothing. CC3 is an exclusively education product and its no surprise you hadn't heard of it if you didn't work in education.

 

Can you please enlighten me, as to how the education sector is so uniue that third party tools like CC3 and Ranger would be necessary. I can see how they once made sense with NT4 and people being promoted into the job within a school, where they did not have an IT background though.

Posted
Can you please enlighten me, as to how the education sector is so uniue that third party tools like CC3 and Ranger would be necessary. I can see how they once made sense with NT4 and people being promoted into the job within a school, where they did not have an IT background though.

 

it makes it secure without having to do anything so that poxy kids can't do anything they shouldn't be!

 

One difference between education and not education.... the childrens.

Guest monkeyx
Posted
it makes it secure without having to do anything so that poxy kids can't do anything they shouldn't be!

 

One difference between education and not education.... the childrens.

 

Hmm so let me see. The average age of the customer is lower :p

 

Desktop security is very good through GPO?

Posted

yeah... lower which means more intent on destroying things.

 

Thing with gpo is that it can be very easy to miss something off... and one little hole left can mean big things later on.... if you haven't worked in education then you won't know what the kids are like!

  • Thanks 1
Posted
> Network admins were asking for more and more from it.

 

The problem with that is that the more you add the less simple it gets. Ultimately, why would you spend extra money buying something that essentially substitutes one pile of complexity with another?

 

[A tangential issue is that the vanilla admin tools have inevitably been less buggy than anyone else's]

 

> So third parties like RM with CC4 still have a very relevant product.

 

Non-BSF CC4 progress in the world, especially CC4 whenever it gets around to running on 2K8 will be interesting. FWIW if a couple of the changes I've heard about turn out to be true I'll retire from challenging the Can't Do X-ers because they'll be right, although not necessarily for their reasons.

 

 

Ok I will bite what you heard about cc4 and for what reasons see if can confirm do deny stuff for you...

 

As for advancement of cc4 big think to remember like lot of upgrades nt to 2k, 2k to 2k3 some people will and so won't.

 

So CC3 networks will stay with c33 and then move to cc5 (of what ever product will be) as Part of the jump to 2k8 (is that we are calling it now??)

 

Again some cc3 networks due to renewal of network servers and other projects will move to cc4.

 

That is fact of product cycle life.

 

Russell

Guest monkeyx
Posted
if you haven't worked in education then you won't know what the kids are like!

 

I have now worked in education for 3.5 years. The workload is FAR higher than I imagined, but at least I no longer work weekends for free and travel a silly amount of miles for silly meetings. LOL

 

One big difference I can see is that you can't sack the the little darlings for trying to hack the system :)

Guest kerrymoralee9280
Posted
I like RM for its simplicity and ease of use.

 

I hate RM because I am never challenged!

 

Don't those kinda go against each other? That's like saying I hate feeling lazy but love doing nothing!

Posted

pretty much :p hahah.

 

What I mean is I wish I could delve into the active directory (and sometimes I do... we have some very special users for testing) but I don't apply GPO's to machines etc. I have a test network but I don't spend much time on it :(

Posted
I like RM for its simplicity and ease of use.

 

I hate RM because I am never challenged!

 

That's kinda the point i was trying to make....you're not being challenged perhaps in the same way as you would with a vanilla network, but i'm assuming the overlay by reducing the admin burden when managing the windows environment should allow you to concentrate on other things and be challenged in other areas, through it's simplicity as you put it.

 

Other things could be development of the school website or VLE, setting up linux servers, doing a voip project, and a whole host of other things.

 

Now vanilla adminstrators do make the time to do all those other things i've mentioned alongside firefighting vanilla. But they need to do the work to get they're vanilla networks to that stage....so that's assembling the tools that RM provides in a single pane of glass and the learning curve.

 

RM as an out of the box solution to a problem is a good idea, and while it's a education specific solution limiting it's usefulness on a cv for jobs within schools or at RM hq....it's also the case a lot of admins don't want to do the desktop support or the Active Directory mgmt in future roles, maybe they want to work with open source or become a DBA or a VLE developer in future roles. In which case vanilla or CC3 experience is slightly less relevant.

 

We all know windows support isn't the most lucratvie of areas, education or industry.

Posted

> Ok I will bite what you heard about cc4 and for what reasons see if can

> confirm do deny stuff for you...

 

I wasn't fishing, honest. I've got the means to throw my concerns at RM too, so I'll save it until I find out if it's true, and if so whether it's something on their to-fix-later list or set in stone.

 

> remember like lot of upgrades nt to 2k, 2k to 2k3 some people will

> and so won't.

 

Sure but neither of those is quite so straightforward in RMsville: It was the NT svr + 9x -> 2K[3] svr + XP which was a significant jump with significant benefits all round. Motives for the svr 2K to 2K3 are things like the 2K box is past it, and upgrading it to 2K3 is a relatively small part/cost of moving the contents over to a shiny new server... and/or things like Capita dropping support for SIMS on 2K.

 

CC3->CC4 upgrade obviously gets you some new some new management tools, but means rebuilding all your desktops (and paying a significant upgrade cost for each one) to typically end up where you are right now, except with more stress on the server and potential teething troubles for a year or two.

 

That's very hard sell or it should be to anyone spending public money. I certainly wouldn't upgrade to CC4 until it came on 2K8, and I probably still wouldn't do it until the raison d'etre, the applications an organisation wants to run on the system, begin to stop working on XP, or 2014... whichever comes first.

 

Again it will be interesting to see what people actually do and why.

Posted

we've got the money to upgrade to cc4 this year... this amounts to more than the annual budget given to my fella for the entire running costs of his network!! Poor poor school, where the kids do well, so they don't get any money!

 

Oh and of course they have to pay all of their 'management' extortinate wages....

Guest kerrymoralee9280
Posted
Who does CC3 installs on networks? In Durham I think it's the LEA (being ITSS). If a commission needs doing they have to do it (as far as I'm aware). This costs money and still takes a few days - I reckon you could set your vanilla servers up in a couple of days (Obviously with the right amount of preparation).
Posted
Who does CC3 installs on networks? In Durham I think it's the LEA (being ITSS). If a commission needs doing they have to do it (as far as I'm aware).

 

We don't 'have' to do it, schools can do it themselves, but since I don't do the commissioning and don't know what it involves I can't comment on how much work is involved.

 

:)

Posted

> Who does CC3 installs on networks?

 

Uh? If a system support buck stops with me then I'm going to do my best to ensure that system is put together in a consistent way by someone with a clue.

Posted
We don't 'have' to do it, schools can do it themselves, but since I don't do the commissioning and don't know what it involves I can't comment on how much work is involved.

 

:)

 

You could go to rm direct if wanted (well I guessing you can)...

 

Russ

  • 7 months later...
Posted
good move, we are in the process of chucking this overpriced spyware out.

 

We are in a very advanced stage, we have moved 70% of desktops and laptops onto vanilla clients. In order to do this just create a OU outside of the cc3 establishent bit in AD.

 

Block inheritence on the newly created OU, this will stop most of the cc3 gpos from applying.

 

Create machine gpos for the desktops computers

create user gpos by using loopback processing

 

Use WDS to deploy your desktop images.

 

There are several different ways to export/move users after that use ntfsfix to reset permissions on user areas.

 

The hardest thing you will have to do is get every department to give you a detailed list of all software that they need and it which room.

The technical side is easy but the communication of getting all information from different departments is hard.

 

I am also looking to do a similar thing as you. I am also looking to upgrade 3 of my servers with standard vanilla servers and have ad replicate to them, gradually phasing the rm servers out.

Jose-is this the method you are applying and if so have you had many issues?

Posted (edited)

No, its easier to migrate all servers at once, you have to think carefully about how your going to do things before you start. This is how we did ours,

 

its a girls grammer school in Wallington, 1200+ pupils, 400+ curriculum laptops, only around 150 curriculum desktops, 100 staff laptops, 2 dc servers, 2 member servers and 2 admin servers, one bromcom server.

 

We started off by moving certain ict rooms over to vanilla clients, this was usefull because it enabled us to setup and test tools such as Italc and steadystate. It also enabled us to make deployment images in advance for these rooms.

 

We had a 2008 server installed and configured with Windows deployment services running on it.

 

Before the holiday period/upgrade time we took one pc/laptop of each type and ensured we had either a working wds image or a ghost image for each one.

 

Backup everything from all domain controllers, as these are the servers that have to be completely wiped and reinstalled from scratch. backup to usb drives as well as tape its quicker.

 

Make sure you have printer driver disks ready, note ip address of servers and printers down, have pre configured scripts ready for printers.

 

We copied our user accounts to a tempory domain controller (temp domain) using the free migration tool from microsoft. We then wiped both DC servers and installed 2003 server on these systems, then copied the accounts across using the free tool from microsoft.

 

Problems and issues,

 

staff users had a folder redirection issue, fixed with a update to client machines something to do with IE7 causing problems.

 

Certain desktops would not work with wds due to the motherboard not supporting vista, solved by using a bartpe disk and imageX instead.

 

Staff laptops taking ages to startup due to steadystate, this is due to the harddrive controller on the motherboard, still no fix, so have disabled steadystate on staff laptops if they moan.

 

No major issues really due to planning and hard work and backing our own ability rather than having a cheesy salesman selling us junk.

 

good luck

Edited by Jose
errors
  • Thanks 4
  • 3 weeks later...
Posted

Jose, I think your method reflects a healthy degree of both skill and realism.

 

CC3 and ClassLink are, as far as I'm concerned, fine for people that want very limited flexibility or perhaps (read disclaimer that follows before flaming me!) have limited technical expertise. Disclaimer: I know some CC3 network managers that are highly skilled, but I also know some that might struggle using a pocket calculator - I'm not judging YOU and it is for YOU to decide where YOU slot in!

 

Personally I cannot stand these products as they don't quite deliver what they claim to. Ross, you will find I'm NOT starting a flame war as I'm criticsing both!

 

All such products operate mostly the same, although under the bonnet things'd obviously be very different. Still, they all tend to "extend" existing AD and Microsoft technology. Honestly, group policies are easy to set up from scratch and running as others refer to it a "vanilla" network is a doddle.

 

There should be no reason why a "vanilla" network isn't at very least as stable, while I believe it should also end up being more secure.

 

Your TCO comments made me smile, given that no CC3 or ClassLink advocate actually came up with the goods, but instead simply threw in a few references to TCO to scare people into submission. Do the maths and then come talk to me so we can compare my cheap apples with your over-priced ones.

 

On the networks I support we don't use any of those products (we removed CC3 and ClassLink from a few). Staff members on thses networks are locked down to the point that they cannot simply install software of their choice, unless it is software approved for usage on the network. In that case all staff members can install/re-install any software title relevant to them (within licensing limitations) within moments.

 

We repackage all software titles as part of our evaluation process.

 

Our teachers mostly use SynchonEyes as classroom management software, although on a few sites they use Italc. IT Support uses Ultr@VNC. (You will notice I refer to IT Support, because there is a huge chasm between ICT and IT as far as I'm concerned, with IT being real-world IMHO).

 

We exclusively use VBScripts because it is a simple and straightforward language to get to grips with. Using nothing but GPO's, we limit what drives are visible to students and we can even remove the ability to access USB mass storage devices using nothing but GPO's.

 

By the way, if you're looking for a rather excellent collection of scripts, go visit Win32 Scripting.... Everything you need to get up and running - why re-invent the wheel?

 

To my experience, CC3 and similar products try to obtain stability by removing flexibility and tries to implement a one-size-fits-all solution. Any decision to remove such products is one I will applaud.

 

Having said that, I will also caution you to test, test and test again before going live with any implementation. In fact, you ought to have a lab network in place permanently so you can test everything there first, even well after a migration.

 

Document everything to an infinate level and ensure your change management processes are able to cope with what you will be doing. This is vital if you are planning on having a graceful escape route in place. Also, it'd be foolish NOT to plan an escape route!

 

Decide on naming conventions that clearly incorporate version control. StaffSecurityGPO_v1 at a glance tells you who the policy should apply to, what it's intended purpose is and what the version number is.

Backup GPO's religiously before making any changes using Microsoft's Group Policy Management Tool and ALWAYS increment the version numbers following a change. That's your escape route should you have made any mistakes.

 

And once you've documented and tested everything, you'll also have excellent references to refer to when running your new stable network.

 

I'll finish off this post with 2 more pieces of advice:

NEVER make any changes to ANYTHING after lunchtime on a Friday and if it aint broke, don't fix it.

  • Thanks 3
Posted

Great posts Jose and tamarside, Very helpful.

 

I will be purchasing a "clean" server sometime soon and will use this to start building the secondary domain without the rm nasties on it and will look at migrating all existing users, folder and apps over the next two years starting in the summer.

 

Jose: when you built your secondary domain to rid yourself of cc3 did you have MS Exchange installed on your network and if so how did you get this to function on a secondary domain?

Posted
Great posts Jose and tamarside, Very helpful.

 

I will be purchasing a "clean" server sometime soon and will use this to start building the secondary domain without the rm nasties on it and will look at migrating all existing users, folder and apps over the next two years starting in the summer.

 

Jose: when you built your secondary domain to rid yourself of cc3 did you have MS Exchange installed on your network and if so how did you get this to function on a secondary domain?

 

We don't use Exchange here, but I have just had a quick google search and the free tool from MS will migrate Exchange but is very basic compared to third party utilities that also do Exchange Migrations.

Posted

The utility to which Jose refers to is ExMerge, which is actually brilliantly simple!. It works in either a one step or two step mode, but I suggest you use the two step method.

Essentially it'll export all your Exchange mailboxes to .PST's then you can have it import those .PST's to Exchange on the new domain.

 

Of course it doesn't work with Exchange 2007, so be warned!

 

Good luck.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...