Jump to content

Recommended Posts

Posted

Morning,

 

Long time lurker, first time poster!

 

Starting a new job in the new year and will be effectively replacing a schools servers this coming Summer.

 

I believe the trust domain was created at the main school last summer, just curious on how people have gone about developing networks in MATs.

 

My thoughts are to move towards a single domain connected through MPLS however not an area I've ever worked in and would be interested in seeing how people have done it!

 

Sorry if this comes across as a "I'm new here tell me how to do my new job please" post, genuinely interested and intend on contributing more in future!

Posted

I can't give a great technical answer here but just from my experiences, First MAT I worked for had 4 primaries and 1 large secondary all running off the same domain using an MPLS network (LGfL). The current MAT I work for is made up of 2 secondary schools and they have separate domains and systems with no plans to consolidate as of yet.

 

The first MAT had lots of central staff moving between schools (HR, Finance etc etc) and then the primaries may have teachers that work at 2 of them for example, so the single domain / single network was fantastic for this as they didn't have to remember different logins and emails.

 

The current place i'm at only has a small handful of central staff who work across both schools and at the moment they have to remember different logins. It's important to think about future proofing as well for when potentially more schools are added to the MAT later on.

 

TL;DR - Single domain works great for MAT's who want staff to be able to work freely at any school location

  • Thanks 1
Posted

We have a single domain, with central servers (no servers on any school sites).

 

We do not use MLPS - it is an unnecessary technology really. We went with point to point leased lines. We found them cheaper. Basically, each school has a leased line that goes to the exchange and the exchanges link to each other. We pay less than £3k for 1Gbit from site to site for most of our schools.

 

We then have a leased line breaking out to the internet at our central site.

  • Thanks 2
Posted
On this road also with my MAT, doing leased lines with a hosted FortiGate to do site to site links. Will be moving to a single domain with a Microsoft Storage Spaces Direct server farm next year.
Posted
Basically, each school has a leased line that goes to the exchange and the exchanges link to each other. We pay less than £3k for 1Gbit from site to site for most of our schools.

We then have a leased line breaking out to the internet at our central site.

 

Do you have more details on your point to point provider? That seems a really good price that I would be happy to pay here to upgrade my link to my LEA which is currently 100Mbit.

Posted

Many MAT's are going down the MPLS route with central domains and several with central phone systems but as a starter get the network in place, allow schools viability of say central office network even if its just network routing, sort DNS so it resolves back and then at least staff can work in schools with access to what they need as a starter whilst you migrate things. Then you could look at domain trusts if you need to share files with a view to moving to one system.

 

I have done similar in the past and I've been left the last place 7 years and they are still mid transition to one domain and no chance of it been completed soon so plan well and put some time scales to migrations.

  • Thanks 1
Posted

I suppose my one other question (there's millions but I won't push my luck!!) is where do the FSMO roles lie with your central site and edge sites? Do you bung in a DC1 and DC2 on site and have a central DC1 and DC2 or just put the two centrally and one on the edge?

 

Thanks all as well, greatly appreciated

Posted
If they're leased/point to point lines do you bother encrypting the traffic?

Why? Its a bare wire between 2 points effectively, a private circuit. A risk assessment would have it being an incredibly low risk issue.

Posted
I suppose my one other question (there's millions but I won't push my luck!!) is where do the FSMO roles lie with your central site and edge sites? Do you bung in a DC1 and DC2 on site and have a central DC1 and DC2 or just put the two centrally and one on the edge?

Thanks all as well, greatly appreciated

We have 2 DCs - both in the central site, on a redundant cluster. No DC's on sites at all, no servers in fact. Means we can use the money we'd spend replacing servers across 5 schools for other things, like better connectivity and moving to 1:1 Chromebook schemes.

  • Thanks 1
Posted
We have 2 DCs - both in the central site, on a redundant cluster. No DC's on sites at all, no servers in fact. Means we can use the money we'd spend replacing servers across 5 schools for other things, like better connectivity and moving to 1:1 Chromebook schemes.

You mind me asking if that covers primary schools and/or secondaries?

Posted
Our trust has a single forest with a domain per school, as most schools still have local tech teams who are domain admins over their own domain, central IT staff are then in enterprise admins which gives them admin rights over every school.
Posted
Our trust has a single forest with a domain per school, as most schools still have local tech teams who are domain admins over their own domain, central IT staff are then in enterprise admins which gives them admin rights over every school.

 

What does each team do? How does the split work?

Posted
I'm about to connect our second site back to to the same leased line provider as main site. Once that has been done i'll have ACL's lifted on the provider's firewalls so i have ip site-to-site access. Initially i'll be creating a forest trust and a shared network drive for sharing resources across the trust, but will allow for all sorts of internal communications without traversing the internet.
Posted (edited)
What does each team do? How does the split work?

Academies that are close together form a cluster with local support, independents and academies out on their own have their own local support. Local support looks after each school network as if it wasn't part of a MAT, central team look after the core WAN and central services such as Azure hosted MIS, finance etc and look after the MAT offices.

 

The network used to be MPLS from each site back to a data centre where it broke out to the Internet, now each school has its own connection and we just link together via Fortigate boxes VPN into Azure.

Edited by Katy
Posted
Academies that are close together form a cluster with local support, independents and academies out on their own have their own local support. Local support looks after each school network as if it wasn't part of a MAT, central team look after the core WAN and central services such as Azure hosted MIS, finance etc and look after the MAT offices.

 

The network used to be MPLS from each site back to a data centre where it broke out to the Internet, now each school has its own connection and we just link together via Fortigate boxes VPN into Azure.

 

Thanks, so you get economies of scale for deployment of OS and software? Security patching/monitoring? Training?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...