CavTech Posted September 17, 2021 Posted September 17, 2021 We have 3 remote sites. At present, each has a DC, separate domain, separate internet, separate pretty much everything.We need to 'connect' these three sites, referred to as A,B and C. The plan is to have DC's at Site A, one domain, with a VPN working between all three sites.Sites A, B & C will all have their own SIMS servers.Is this how you would do it?My idea would be to have a DC at each of the sites, with a VPN connecting all three. The reasoning being that if Site A goes offline, the other two sites can carry on. If we have everything DC related at Site A only, and Site A goes offline, B & C are both going to experience issues.Thoughts please.
DaveTheTech Posted September 17, 2021 Posted September 17, 2021 I would have one domain and a DC at each site. As you say, you dont want to end up with one site being the weak link that takes all three out. Our trust has 2 data centers, physical servers at each site and sims is hosted centrally. 1
mavhc Posted September 17, 2021 Posted September 17, 2021 Last time I did this I had 4 sites, 4 DCs, 1 AD, site to site VPNs. Of course these days there's the cloud option, if you have reliable internet. Make a lot of use of DFS and replication too. I tended to split the computer OUs by physical location, but the user OUs by type so site1>laptops, but pupils>site1 1
DaveTheTech Posted September 17, 2021 Posted September 17, 2021 We have an OU for each school. With Workstations, Users and Groups under each one. mavhc, what benefits were there from having school OUs as a child of Pupil?
IAMCloud_Curt Posted September 17, 2021 Posted September 17, 2021 I would set up AD Sites & Services Create new 'SITES' with your IP range for each site Then when you create new DC's put them in the site of that specific school Your LAN traffic then points to that site so when you ping domain.local it will ping it's local DC always as it knows it belongs to that IP range Each site replicates between each other using a token - every 15/30/60 minutes 1
HPlum78 Posted September 17, 2021 Posted September 17, 2021 (edited) A couple of writable DCs at your main site and the RODC in the satellite sites that take care of those subsets of users/ computers. Do not see the need to have full blown DCs at satellite sites unless you are going to identify one of those as a DR site then that may change your strategy some what. If site loss is a risk you are going to actively mitigate against then you will have a star configuration for your links If not write the risk up and get your SLT to sign it off. It's swings and roundabouts as either way comes with a host of positives and negatives. Risk assessment is key to the decision making then the cost of mitigating those risks. Edited September 17, 2021 by HPlum78
chaplic Posted September 17, 2021 Posted September 17, 2021 Id have no DC at any site and go AAD / O365 for ddata and services. you mention that if you lose a site you lose service, but what actual service do you have without internet connectivity anyway? reducing server spend would mean you can have a backup line/ 4G etc 1
mavhc Posted September 17, 2021 Posted September 17, 2021 We have an OU for each school. With Workstations, Users and Groups under each one. mavhc, what benefits were there from having school OUs as a child of Pupil? I apply the same GPOs to the same type of users no matter which site they're at. And then site specific GPOs to the Sites section for the very few things that require that.
HPlum78 Posted September 17, 2021 Posted September 17, 2021 Tbh @chaplic is bang on, if you do indeed use cloudy based services. If not maybe now is the time....
sippo Posted September 17, 2021 Posted September 17, 2021 We have an MPLS setup to one site. Works a dream. All on one domain. One webfilter, one firewall.
lmgtfy Posted September 17, 2021 Posted September 17, 2021 We have an MPLS setup to one site. Works a dream. All on one domain. One webfilter, one firewall.Sounds good, are you able to expand on what you have setup?
mavhc Posted September 17, 2021 Posted September 17, 2021 Filtering is the major issue, so I went with Exa and they filter it. Filter's pretty good for the price, but classification and log reports aren't great, and my feature request (timed policies) hasn't been added in the past 3 years. Still, £100/site/year, can't complain too much.
FN-GM Posted September 18, 2021 Posted September 18, 2021 I would setup a good redundant WAN and have servers in 1 central location. We have 19 sites are the moment and there are no local servers at all. The is no need at all to have local.
sippo Posted September 20, 2021 Posted September 20, 2021 Sounds good, are you able to expand on what you have setup? We have all our servers (2) at the main secondary school site. We have 1gbps leased line, 7 primaries have 100mbps leased line with backup fttc. All traffic is directed to the secondary school. What else would you like to know? it's obviously a risk if there are issues at the secondary school but i did tell the SLT them, and they were happy with the risk as the amount of money is saved is worth it. 1
Oaktech Posted September 20, 2021 Posted September 20, 2021 Worth approaching your ISP to see if they will do a dark fibre lease to create yourself a highspeed private wan and bypass all the above technicalities.
lmgtfy Posted October 15, 2021 Posted October 15, 2021 We have all our servers (2) at the main secondary school site. We have 1gbps leased line, 7 primaries have 100mbps leased line with backup fttc. All traffic is directed to the secondary school. What else would you like to know? it's obviously a risk if there are issues at the secondary school but i did tell the SLT them, and they were happy with the risk as the amount of money is saved is worth it. Sounds good thanks for the extra info
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now