rusty155 Posted July 10, 2006 Posted July 10, 2006 Hi all, At the school where I work we currently have two separate networks for admin and curriculum. Curriculum is CC3 and admin is Vanilla XP. Just wondering what the situation is elsewhere as long term I am hoping to firstly move away from RM and have vanilla curriculum and eventually perhaps merge the two together. Would really appreciate any feedback as how things are done elswhere and if anyone else has done anything similar - be great to hear how it went, any problems etc etc. Thanks,
intrigue Posted July 10, 2006 Posted July 10, 2006 We have that samesetup as you and have just merged the two but still with CC3 we will eb going Vanilla fairly soon hopefully matt
mrforgetful Posted July 10, 2006 Posted July 10, 2006 We currently have seperate Admin, Curriculum and Finance. First week of the holidays will see it be merged to Curriculum/Admin as one and Finance off on it's own (only 4 computers and a server). I couldn't tell you much more as it's being set up by our outside contractor.
webman Posted July 10, 2006 Posted July 10, 2006 We used to have a CC3 network + vanilla admin. We merged them around two years ago and now have an integrated SIMS.net and CC3 network, with SIMS on it's own member server bought from RM. We haven't had any problems at all - all users on one network, same username format, all managed from the RM MC
intrigue Posted July 10, 2006 Posted July 10, 2006 Wow 3 replies in the same second. RM sucks major ass and i would love to get rid of it, despite the facta 5 year old could operate it i think its slow and just horrible. CC3 should die a horrible death IMO matt
rusty155 Posted July 10, 2006 Author Posted July 10, 2006 Wow - thanks for the rapid responses!! Anyone come up against any resistance from their LEAs when merging admin/curriculum networks? Ours isn't too pleased with the suggestion of a one way trust relationship between the two let alone a complete merge!!! The school do have the final say but it is convincing them that the LEA is over cautious - any similar experiences??
Irazmus Posted July 10, 2006 Posted July 10, 2006 When I started here we had a single domain running from 2 vanilla 2K3 DC's on separate IP subnets (PDC sat on both with dual NIC's, BDC only on admin). In the summer we'll be moving all admin machines over to the curriculum subnet and using the admin subnet as a DMZ for the web and mail servers. Having a DC which 3/4 of all clients can't see was a PITA. Regarding convincing the LEA, easy, I havn't told them ^^
Quackers Posted July 10, 2006 Posted July 10, 2006 At the minimum there should be a trust in my opinion. One domain is the better solution. How are staff suppost to communicate and share easy if they are seperated. I would have staff unable to put documents in the Admin shared area, and other staff unable to put documents in the curriculum staff area. The LEA still want 2 domains so a 2 way trust is in place, so i just joined the admin machines to the curriculum network and now people care share easy.
webman Posted July 10, 2006 Posted July 10, 2006 Our LEA completely backed it as that is the way they wanted to go. I don't think it is a one way trust thing either... the SIMS is just a member server in the domain and it "just works". The "admin" staff are in the teaching group on one of the DCs, but only these members have access to the S: (SIMS) drive.
beast_gts Posted July 10, 2006 Posted July 10, 2006 My LEA suggested it as they wanted to use my 'net connection (100mb LES).
mrforgetful Posted July 10, 2006 Posted July 10, 2006 We're one of the last in our LEA to have gotten away with seperate networks for a long time. I'd rather have seperate ones, Staff are the most irresponsible people when it comes to security, and I think it's a major security risk for data and personal information. But at the end of the day, what do my opinions matter?
webman Posted July 10, 2006 Posted July 10, 2006 I'd rather have seperate ones, Staff are the most irresponsible people when it comes to security, and I think it's a major security risk for data and personal information. Then leave the ball in their court. They leave workstation open - their problem if data gets leaked.
mrforgetful Posted July 10, 2006 Posted July 10, 2006 I'd rather have seperate ones, Staff are the most irresponsible people when it comes to security, and I think it's a major security risk for data and personal information. Then leave the ball in their court. They leave workstation open - their problem if data gets leaked. That's pretty much my attitude tbh, though I'm just worried that it might be my personal data that gets looked at by an kid with a grudge...or crush 8O lol
Disease Posted July 10, 2006 Posted July 10, 2006 We have 2 seperate networks essentially and thats the way it will stay, they are joined via a V-LAN which allows Admin to access curr. but not the other way. The LEA can kick or scream all they want they wont be joined into one domain. I'd rather have seperate ones, Staff are the most irresponsible people when it comes to security, and I think it's a major security risk for data and personal information. Then leave the ball in their court. They leave workstation open - their problem if data gets leaked. Careful with that way of thinking as you may find that you are the one who takes the can for breaches of Data Protection. They would not get done it would be down to whomever is in charge of data protection and seeing as you run the servers you may find its you.
bossman Posted July 10, 2006 Posted July 10, 2006 I am at this moment working with system strategic leader for IT my boss in other words to implement a legal binding document based on the data protection and security act 1998 and 2000. In this document it raises the awareness of the end user inveriably the memebers of staff who leave their workstations unlocked (given that they only have to hit the windows and L keys and it is locked) that secure data via the SIMS can be obtained by other members of the school if they leave their computers open. If this is the case then we through the governors will make it quite plain that the culprit no matter who is liable to legal prosecution under the said acts. We will run regular security checks to this effect for the first six months and repeat offenders will be named and shamed by enforcing a retraining on the use of IT + any data protection training. Our Staff members are usually pretty good but it is the odd one that lets us down.
Disease Posted July 10, 2006 Posted July 10, 2006 Sounds very good and useful, post it up for us when you are done so we can plagiarise it
john Posted July 10, 2006 Posted July 10, 2006 1 Domain, 2 Networks - Admin & Academic. Most Servers are dual carded so seen on both LANS, but some are just one of the other so we have 2 DHCPs one for Admin and one for Academic, same with DNS and WINS. Things like SQL are just on Admin for the database etc
meastaugh1 Posted July 16, 2006 Posted July 16, 2006 We have 2 seperate networks essentially and thats the way it will stay, they are joined via a V-LAN which allows Admin to access curr. but not the other way. The LEA can kick or scream all they want they wont be joined into one domain. Do your admin users need to access curriculum resources then? I would have imagined it would be the other way around? I realise that all schools operate differently, but I thought the days of MIS purely being the domain of the office staff was a thing of the past? Just curious.
Face-Man Posted July 18, 2006 Posted July 18, 2006 we are working to joining our two seperate domain this summer. Using AD to seperate the computers roll and restrict user access. The main difficult I can see (apart from the obvious) Is the teacher who keeps their whiteboard on showing all the school local neighbourhood kids private information. Any body got a way of shutingdown the projectors when sims is run ?
webman Posted July 18, 2006 Posted July 18, 2006 Any body got a way of shutingdown the projectors when sims is run ? Following the Data Protection Act, the Teacher has the responsibility of putting the projector into "No Show" or "Blank Screen" mode.
Disease Posted July 18, 2006 Posted July 18, 2006 We have 2 seperate networks essentially and thats the way it will stay, they are joined via a V-LAN which allows Admin to access curr. but not the other way. The LEA can kick or scream all they want they wont be joined into one domain. Do your admin users need to access curriculum resources then? I would have imagined it would be the other way around? I realise that all schools operate differently, but I thought the days of MIS purely being the domain of the office staff was a thing of the past? Just curious. Our teachers do not have access to Sims in the classroom, they can't be trusted to use it properly and securely. They can only access it in the staffroom on 3 admin machines but even those are set to shutdown after 15mins of inactivity.
woody Posted July 18, 2006 Posted July 18, 2006 We merged our networks last summer. One domain with the Admin server joining the others. The reason for this was that Teachers where now required to take electronic registers. The way SIMS works, you have to log into SIMS (where all the sesitive stuff is although you can lock down what is available) to get to your lesson register. Teachers would do this on their laptop in the classroom. Therefore, if teachers had access to sims in the classroom, (where traditionaly it was only available in an office) then what's the point in keeping networks seperate? If a teacher leaves their laptop unlocked, kids can get to the data whether they are on an admin network or not. Hence, we merged for ease of management and ease of access to both admin and curriculum materials. The emphasis now is on training teachers to lock their laptops when they are not there. You always get the regulars who forget but I just report them to SMT then it's off my hands Plus, you can write instructions to keep sensitive data secure into the staff AUP.
Jake Posted July 18, 2006 Posted July 18, 2006 The emphasis now is on training teachers to lock their laptops when they are not there. You always get the regulars who forget but I just report them to SMT then it's off my hands Plus, you can write instructions to keep sensitive data secure into the staff AUP. What would be even better, would be if the adults who are supposed to be educating the future business employees of our country , would have enough intelligence to not leave their laptops/PCs open. Course , sadly this often proves a much too difficult task. Its a wonder at times they know how to close a door
ajbritton Posted July 18, 2006 Posted July 18, 2006 For suitable small sites who can't afford to regularly update two servers, I'm consdering the following to maintain the admin/curriculum separation... Single physical server with gobs of disk space, dual CPU and 4GB RAM Admin DC, DHCP, DNS, SIMS etc running on the physical server Curric DC running on a virtual server hosted on the same server Am I crazy?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now