Jump to content

Recommended Posts

Posted
We have 3 remote sites. At present, each has a DC, separate domain, separate internet, separate pretty much everything.We need to 'connect' these three sites, referred to as A,B and C. The plan is to have DC's at Site A, one domain, with a VPN working between all three sites.Sites A, B & C will all have their own SIMS servers.Is this how you would do it?My idea would be to have a DC at each of the sites, with a VPN connecting all three. The reasoning being that if Site A goes offline, the other two sites can carry on. If we have everything DC related at Site A only, and Site A goes offline, B & C are both going to experience issues.Thoughts please.
Posted

I would have one domain and a DC at each site. As you say, you dont want to end up with one site being the weak link that takes all three out.

 

Our trust has 2 data centers, physical servers at each site and sims is hosted centrally.

  • Thanks 1
Posted

Last time I did this I had 4 sites, 4 DCs, 1 AD, site to site VPNs.

 

Of course these days there's the cloud option, if you have reliable internet.

 

Make a lot of use of DFS and replication too.

 

I tended to split the computer OUs by physical location, but the user OUs by type so site1>laptops, but pupils>site1

  • Thanks 1
Posted

I would set up AD Sites & Services

 

Create new 'SITES' with your IP range for each site

 

Then when you create new DC's put them in the site of that specific school

 

Your LAN traffic then points to that site so when you ping domain.local it will ping it's local DC always as it knows it belongs to that IP range

 

Each site replicates between each other using a token - every 15/30/60 minutes

  • Thanks 1
Posted (edited)

A couple of writable DCs at your main site and the RODC in the satellite sites that take care of those subsets of users/ computers. Do not see the need to have full blown DCs at satellite sites unless you are going to identify one of those as a DR site then that may change your strategy some what. If site loss is a risk you are going to actively mitigate against then you will have a star configuration for your links If not write the risk up and get your SLT to sign it off.

 

It's swings and roundabouts as either way comes with a host of positives and negatives. Risk assessment is key to the decision making then the cost of mitigating those risks.

Edited by HPlum78
Posted
Id have no DC at any site and go AAD / O365 for ddata and services. you mention that if you lose a site you lose service, but what actual service do you have without internet connectivity anyway? reducing server spend would mean you can have a backup line/ 4G etc
  • Thanks 1
Posted
We have an OU for each school. With Workstations, Users and Groups under each one.

 

mavhc, what benefits were there from having school OUs as a child of Pupil?

 

I apply the same GPOs to the same type of users no matter which site they're at.

 

And then site specific GPOs to the Sites section for the very few things that require that.

Posted
We have an MPLS setup to one site. Works a dream.

 

All on one domain. One webfilter, one firewall.

Sounds good, are you able to expand on what you have setup?
Posted
Filtering is the major issue, so I went with Exa and they filter it. Filter's pretty good for the price, but classification and log reports aren't great, and my feature request (timed policies) hasn't been added in the past 3 years. Still, £100/site/year, can't complain too much.
Posted

I would setup a good redundant WAN and have servers in 1 central location.

 

We have 19 sites are the moment and there are no local servers at all.

 

The is no need at all to have local.

Posted
Sounds good, are you able to expand on what you have setup?

 

We have all our servers (2) at the main secondary school site. We have 1gbps leased line, 7 primaries have 100mbps leased line with backup fttc. All traffic is directed to the secondary school.

 

What else would you like to know? it's obviously a risk if there are issues at the secondary school but i did tell the SLT them, and they were happy with the risk as the amount of money is saved is worth it.

  • Thanks 1
Posted
Worth approaching your ISP to see if they will do a dark fibre lease to create yourself a highspeed private wan and bypass all the above technicalities.
  • 4 weeks later...
Posted
We have all our servers (2) at the main secondary school site. We have 1gbps leased line, 7 primaries have 100mbps leased line with backup fttc. All traffic is directed to the secondary school.

 

What else would you like to know? it's obviously a risk if there are issues at the secondary school but i did tell the SLT them, and they were happy with the risk as the amount of money is saved is worth it.

 

Sounds good thanks for the extra info

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...