Jump to content

Recommended Posts

Posted

Hi all,

 

At the school where I work we currently have two separate networks for admin and curriculum. Curriculum is CC3 and admin is Vanilla XP.

 

Just wondering what the situation is elsewhere as long term I am hoping to firstly move away from RM and have vanilla curriculum and eventually perhaps merge the two together.

 

Would really appreciate any feedback as how things are done elswhere and if anyone else has done anything similar - be great to hear how it went, any problems etc etc.

 

Thanks,

Posted

We currently have seperate Admin, Curriculum and Finance.

 

First week of the holidays will see it be merged to Curriculum/Admin as one and Finance off on it's own (only 4 computers and a server).

 

I couldn't tell you much more as it's being set up by our outside contractor.

Posted

We used to have a CC3 network + vanilla admin. We merged them around two years ago and now have an integrated SIMS.net and CC3 network, with SIMS on it's own member server bought from RM.

 

We haven't had any problems at all - all users on one network, same username format, all managed from the RM MC :)

Posted

Wow 3 replies in the same second.

RM sucks major ass and i would love to get rid of it, despite the facta 5 year old could operate it i think its slow and just horrible.

CC3 should die a horrible death IMO

matt

Posted

Wow - thanks for the rapid responses!!

 

Anyone come up against any resistance from their LEAs when merging admin/curriculum networks? Ours isn't too pleased with the suggestion of a one way trust relationship between the two let alone a complete merge!!!

 

The school do have the final say but it is convincing them that the LEA is over cautious - any similar experiences??

Posted

When I started here we had a single domain running from 2 vanilla 2K3 DC's on separate IP subnets (PDC sat on both with dual NIC's, BDC only on admin). In the summer we'll be moving all admin machines over to the curriculum subnet and using the admin subnet as a DMZ for the web and mail servers.

Having a DC which 3/4 of all clients can't see was a PITA.

 

Regarding convincing the LEA, easy, I havn't told them ^^

Posted
At the minimum there should be a trust in my opinion. One domain is the better solution. How are staff suppost to communicate and share easy if they are seperated. I would have staff unable to put documents in the Admin shared area, and other staff unable to put documents in the curriculum staff area. The LEA still want 2 domains so a 2 way trust is in place, so i just joined the admin machines to the curriculum network and now people care share easy.
Posted

Our LEA completely backed it as that is the way they wanted to go. I don't think it is a one way trust thing either... the SIMS is just a member server in the domain and it "just works".

 

The "admin" staff are in the teaching group on one of the DCs, but only these members have access to the S: (SIMS) drive.

Posted

We're one of the last in our LEA to have gotten away with seperate networks for a long time.

 

I'd rather have seperate ones, Staff are the most irresponsible people when it comes to security, and I think it's a major security risk for data and personal information.

 

But at the end of the day, what do my opinions matter?

Posted
I'd rather have seperate ones, Staff are the most irresponsible people when it comes to security, and I think it's a major security risk for data and personal information.

 

Then leave the ball in their court. They leave workstation open - their problem if data gets leaked.

Posted
I'd rather have seperate ones, Staff are the most irresponsible people when it comes to security, and I think it's a major security risk for data and personal information.

 

Then leave the ball in their court. They leave workstation open - their problem if data gets leaked.

 

That's pretty much my attitude tbh, though I'm just worried that it might be my personal data that gets looked at by an kid with a grudge...or crush 8O lol

Posted

We have 2 seperate networks essentially and thats the way it will stay, they are joined via a V-LAN which allows Admin to access curr. but not the other way. The LEA can kick or scream all they want they wont be joined into one domain.

 

I'd rather have seperate ones, Staff are the most irresponsible people when it comes to security, and I think it's a major security risk for data and personal information.

 

Then leave the ball in their court. They leave workstation open - their problem if data gets leaked.

 

 

Careful with that way of thinking as you may find that you are the one who takes the can for breaches of Data Protection. They would not get done it would be down to whomever is in charge of data protection and seeing as you run the servers you may find its you.

Posted
I am at this moment working with system strategic leader for IT my boss in other words to implement a legal binding document based on the data protection and security act 1998 and 2000. In this document it raises the awareness of the end user inveriably the memebers of staff who leave their workstations unlocked (given that they only have to hit the windows and L keys and it is locked) that secure data via the SIMS can be obtained by other members of the school if they leave their computers open. If this is the case then we through the governors will make it quite plain that the culprit no matter who is liable to legal prosecution under the said acts. We will run regular security checks to this effect for the first six months and repeat offenders will be named and shamed by enforcing a retraining on the use of IT + any data protection training. Our Staff members are usually pretty good but it is the odd one that lets us down.
Posted
1 Domain, 2 Networks - Admin & Academic. Most Servers are dual carded so seen on both LANS, but some are just one of the other so we have 2 DHCPs one for Admin and one for Academic, same with DNS and WINS. Things like SQL are just on Admin for the database etc
Posted
We have 2 seperate networks essentially and thats the way it will stay, they are joined via a V-LAN which allows Admin to access curr. but not the other way. The LEA can kick or scream all they want they wont be joined into one domain.

 

Do your admin users need to access curriculum resources then? I would have imagined it would be the other way around?

 

I realise that all schools operate differently, but I thought the days of MIS purely being the domain of the office staff was a thing of the past?

 

Just curious. :wink:

Posted
we are working to joining our two seperate domain this summer. Using AD to seperate the computers roll and restrict user access. The main difficult I can see (apart from the obvious) Is the teacher who keeps their whiteboard on showing all the school local neighbourhood kids private information. Any body got a way of shutingdown the projectors when sims is run ?
Posted
Any body got a way of shutingdown the projectors when sims is run ?

 

Following the Data Protection Act, the Teacher has the responsibility of putting the projector into "No Show" or "Blank Screen" mode.

Posted
We have 2 seperate networks essentially and thats the way it will stay, they are joined via a V-LAN which allows Admin to access curr. but not the other way. The LEA can kick or scream all they want they wont be joined into one domain.

 

Do your admin users need to access curriculum resources then? I would have imagined it would be the other way around?

 

I realise that all schools operate differently, but I thought the days of MIS purely being the domain of the office staff was a thing of the past?

 

Just curious. :wink:

 

Our teachers do not have access to Sims in the classroom, they can't be trusted to use it properly and securely. They can only access it in the staffroom on 3 admin machines but even those are set to shutdown after 15mins of inactivity.

Posted

We merged our networks last summer. One domain with the Admin server joining the others. The reason for this was that Teachers where now required to take electronic registers.

 

The way SIMS works, you have to log into SIMS (where all the sesitive stuff is although you can lock down what is available) to get to your lesson register. Teachers would do this on their laptop in the classroom. Therefore, if teachers had access to sims in the classroom, (where traditionaly it was only available in an office) then what's the point in keeping networks seperate? If a teacher leaves their laptop unlocked, kids can get to the data whether they are on an admin network or not.

 

Hence, we merged for ease of management and ease of access to both admin and curriculum materials. The emphasis now is on training teachers to lock their laptops when they are not there. You always get the regulars who forget but I just report them to SMT then it's off my hands :)

 

Plus, you can write instructions to keep sensitive data secure into the staff AUP.

Posted
The emphasis now is on training teachers to lock their laptops when they are not there. You always get the regulars who forget but I just report them to SMT then it's off my hands :)

 

Plus, you can write instructions to keep sensitive data secure into the staff AUP.

 

What would be even better, would be if the adults who are supposed to be educating the future business employees of our country , would have enough intelligence to not leave their laptops/PCs open.

 

Course , sadly this often proves a much too difficult task. Its a wonder at times they know how to close a door :)

Posted

For suitable small sites who can't afford to regularly update two servers, I'm consdering the following to maintain the admin/curriculum separation...

 

Single physical server with gobs of disk space, dual CPU and 4GB RAM

Admin DC, DHCP, DNS, SIMS etc running on the physical server

Curric DC running on a virtual server hosted on the same server

 

Am I crazy?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...