Jump to content

Recommended Posts

Posted

Hi,

We have recently got a new Principal at our school who wants me to write a report on the pros and cons of seperating our domain into admin and curriculum, and or having sperate subnets.

We are a small independent school with around 350 students and around 200 machinesand the network was all set up when I got here.

 

Have read a few posts on this site on schools merging their networks but not the other way round. It is something I know very little about, I was wondering if anyone could give me a few ideas or point me in the direction of some useful info so that I can write something that will give the impression I know what I'm talking about.

Thanks

 

Judy

Posted
The official advice from MS is not to maintain split domains with trusts any more, but to amalgamate them and use granular permissions within the forest to control rights. Splitting them does add a lot of complexity if there are resources crossing the boundaries.
  • Thanks 1
Posted
So long as you're running Windows 2000/2003 Server or later and Windows 2000/XP on your workstations then you're safe to have one single domain. Active Directory allows you to create security groups which you then allocate to the relevant shares. This gives you control who has access to what resources.
Posted

We are in the process of merging our networks from the same kind of setup that you are looking at going to. When I started at the school they had 2 physically seperate networks, 2 domains, 2 seperate ADs, 2 seperate usernames/password etc.... It doubles my work load having to maintain 2 seperate networks - so there is a con for you.

 

Like powdarrmonkey says splitting them does cause complexity there are resources crossing the boundaries. One example we have is E-Mail. Our Exchange server sits on the curriculum network. All works fine until their password expires and they can't logon to it - but they do know this has happened because they don't get the "you password is about to expire" dialog.

 

The reason it is why it is here was becuase of security concerns, but with proper use of permissions there is no real reason for seperation.

 

BTW - are you in Croydon, South London?

  • Thanks 1
Posted

One issue with 2 subnets is all traffic must go via a layer 3 device to be routed to the other network.

 

Advantage is you have control via ACLs of exactly what crosses the boundry.

 

Disadvantage is it is a potential bottleneck as all traffic must pass through the single point.

Posted

Having entirely seperate networks is much more secure but its overkill for schools. As long as the permissions/security groups and group policys are in place you won't have any issues with students gaining access to areas they shouldn't.

 

File permissions wise I usually ensure that any staff only areas have deny acl's for students even though they don't really need them - at least then even if a student is a member of one of the groups allowed access they'll be denied because they are part of the student group.

Posted
Of course - the other problem is that the separation between "Admin" and "curriculum" is blurry at best - I have found that pretty much, people want to sit at a PC and be able to work, be it in the MIS system, office stuff or educational programs - not a problem for Admin staff who usually have an office - but often a problem for middle & senior management on the teaching side.
Posted
A search on the site for 'flat network' should bring up the previously discussed threads which include links to British Standards for security on networks that can apply as well as possible alternatives.
Posted

We're looking to merge Domains early next year. Taking up a lot of administration time have seperate Domains, when they all shared the same physical network anyway.

 

With SIMS now being used for Electronic Registration I've set up a trust between the Domains for the time being, and am starting to plan merging the Domains. Makes SIMS pointless being seperate now and with Learning Gateways, etc, etc in the offering I just want to keep things simple.

 

Get your AD structure right and permissions correct and security should never be an issue.

 

Pete

Posted
One issue with 2 subnets is all traffic must go via a layer 3 device to be routed to the other network.

 

Advantage is you have control via ACLs of exactly what crosses the boundry.

 

Disadvantage is it is a potential bottleneck as all traffic must pass through the single point.

 

Unless you use layer 3 switches. TBH, you really don't need two entirely seperate networks, permissions on folder shares...etc will be plenty good enough I would imagine? :confused:

 

There are very few advantages with having more than one domain. The only one coming to mind at the moment is that it's less easy to accidentally give everyone permissions to do something, for example. WHATEVER\domain users...etc.

 

As from 2008, Vista...etc, everything is more geared up towards a single domain. I don't see any reason at all why you would want to go from a single domain to multiple domains, you're just creating a lot of needless work for yourself and you will ultimately end up with two networks to administer instead of one!

Posted
We are merging too finally a week on wednesday. For all sorts of reasons including E-registration etc. It is a pain to mange 2 physically seperate networks as you end up doing most things twice. Also I dont have to keep explaining to the staff that X is only available on admin or curric etc.
Posted
It is a pain to mange 2 physically seperate networks as you end up doing most things twice. Also I dont have to keep explaining to the staff that X is only available on admin or curric etc.

 

Exactly or why X password has expired and now they're not both the same...etc. :mad:

 

Imagine having a single domain where everything you used integrated with LDAP. Imagine changing your password once. :drunken_smilie:

Posted
Unless you use layer 3 switches.

 

Well yes but i did hint at that fact by not specifying "router". I didnt mention layer 3 switches as replacing your core network would be costly.

Posted

On the issue of separate subnets, I'm aware of a couple of local schools that have multiple subnets although I can't see the benefit myself. Historically I believe subnets were used to reduce the amount of broadcast traffic seen by each PC (because the subnet is effectively a boundary to broadcast traffic - a broadcast domain) and to increase security by restricting traffic flow (because your routers/layer 3 switches act as passport control between subnets).

 

Especially with a school as small as yours the amount of broadcast traffic will typically be negligible. We have a lot more kit on a single subnet and the broadcast traffic is almost nothing. Even if we had a split site with a poxy 10mb link it wouldn't be significant.

 

As far as increasing security - others have said it - there are plenty of tools at your disposal in a standard Windows network to restrict access to the things schools typically worry about. Any gain you might get in security could easily be turned into a loss by the increased administrative burden you are put under, meaning you have little or no time to monitor, maintain and update your security measures.

 

Think of the numerous scenarios where staff might want to access the same resource from both networks. Think of the hassle of them having to pick the right PC to perform a particular job (in general that is what we are trying to move away from - surely it should be the person's identity that determines their access rather than their location)

 

I have taken part in network merges at two large schools and I believe staff at both would say the merge led to a much smoother ICT experience.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...