Jump to content

Recommended Posts

Posted

Ok, the killer question:

 

SHOULD WE KEEP OUR ADMIN AND CURRICULUM NETWORKS SEPERATE?

 

This seems to have been a policy kept in place at most schools I've come across. But we have a new assistant head who is talking about merging the whole lot. We're not talking just about joining the physical network here. We're talking about putting Admin and curriculum servers all on the same domain. The only thing then seperating the two is the security and GP settings for staff and pupils.

 

I have heard all sorts of rumours that lots of other schools are merging their networks together. I've even heard that some LEAs are insisting on it. I can see where their argument is, that in the end schools are needing to have access to both networks from every room. ie. they need to have access to admin to register lessons, and they need to have access to curriculum for subject based work etc etc.

 

To run two seperate netorks to every room doubles the time, energy and cost involved because let's face it, not many schools are organized enough to pull the cables all at the same time.

 

So I am asking for your thoughts on this. Have you merged your networks? Do you feel safe to do so? Can you trust staff to be security conscious in the classroom?

 

Thanks

Posted
The govt eventually wants you to have a single integrated network, as they have a big thing for information availablity. The only problem I think you will encounter will be getting the staff to become more security concious whn it comes to leaving computers logged on etc.
Posted

what we do mainly because how embc run the vlan switch is that we have an isa box sitting between two networks and that solves secuirty problems..

 

Russ

Posted
The only problem I think you will encounter will be getting the staff to become more security concious when it comes to leaving computers logged on etc.

 

:D A tough one for sure

Posted

Well, the way I see it the only reason to keep the two networks separate is if the Network Manager is an idiot (and if you're on this site, I'm guessing that you're not!). As long as you have the technical skill and sense to ensure that everything is secured correctly then there is no reason why you should separate the networks.

 

Aside from that is the logistical nightmare of running two networks - two sets of equipment & infrastructure to maintain, two AD structures, two sets of updates to be done...

 

So unless there is some defining business reason for it, I would run one network for all.

 

(And apologies if this post sounds a little angry. Its just too damn hot here!)

Posted

For some schools keeping seperate domains for admin and curriculum is down to damage limitation ...

 

Part of me almost wished that we had stuck with seperate domains ... the amount of grief from some admin staff is unbelievable ... whereas others are fantastic ...

 

Damn ... they really are becoming like teachers!

Posted
Depressingly I usually find its the other way round. :(

Have to agree but then the kids side is locked more tightly than admin.

 

We have the two domains connected - staff and kids can log on to the same machine, with a few dedicated sims workstations, that kids can also log on to.

 

I have a problem with staff letting kids use thier passwords alright. This year i'm getting really heavy handed with the AUP etc.

Posted

Not true chris

 

I have found ways around that, despite what our sims folk tell us hehe

 

NTFS permissions on:

 

C:\Program Files\SIMS .net\

 

to Full Controll for everybody / Anonymous Logon

(havent tried just Modify rights - but that might do)

 

Make sure that it replicates throughout the directory i.e. so that all files and folders within that folder have those NTFS permissions and job done :)

 

You may think that dangerous, but if you have hidden & disallowed access to C drive for your users, they wont see it to change it anyhow ;)

 

Enjoy

Nath.

Posted

Yes- it would be *nice* if the two were merged into one network for sure. When I started at Kingswood the big thing was keeping them separate no matter what, but then I'm told this year by county that eventually *common sense* will prevail and the two will become one.

 

The other side of me says though that the person who has made this decision "higher up" may not understand the true ramifications of that decision. Perhaps in the long term it will be better- heck I have two separate networks with different IP configurations, different hardware and server platforms and such to support; it would be nice to unify this mess. But in the short term it would be a nightmare for us of almost epic proportions!

 

How many of us know staff members who allow sixth-formers to log on the SIMS equipped machines on the LAN using the teacher's credentials to download stuff from the internet or play games etc? I was appalled to find that this had been going on on our network, but apparently it's par for the course.

 

I think that preparation would be the key to success here- getting staff members to realise that security is holistic and not reactionist. If they understand that and can be made to see the danger in breeches of security where the admin and curriculum LANs are concerned, then integration of the two would be so much easier!!

 

Paul

Posted

Whoops - forgot to comment on the thread lol

 

Seperate is best for security.

 

Our staff have absolutely ZERO concept of it. I grow tired of continually explaining it to them to NOT LEAVE YOURSELVES LOGGED IN!

 

*ahem* excuse the ranting lol

 

teachers do it.... SMT do it (inc the ICT Co-ordinator)....

 

Seperate all the way lol

 

N.

Posted
too right! seperate all the way. You can't trust (l)users, & guess who'd get the flack when sims goes up the creek... the same one who's left to sort it out!!!! I wonder what the Sims people think about convergence???
Posted

Capita are all for it ... They want more teachers logging into and using SIMS.net.

 

They also really want people to use their VLE too ... so that might have something to do with them wanting a single network.

Posted

One way to make staff security conscious is to tell them that if they leave themselves logged on, pupils will have access to all their personal details including bank A/C numbers! Of course, I wouldn't let this happen but teachers don't have to know that! It's only when it affects them personally that they MIGHT do something about it.

 

At the end of the day, if SMT say they want it, I'll have to deliver. So here's another question:

 

If my curriculum server is a domain controller and my admin server is a domain controller and they are running differently named domains, how do I bring the admin one onto the same domain as the curriculum one?

Posted
If my curriculum server is a domain controller and my admin server is a domain controller and they are running differently named domains, how do I bring the admin one onto the same domain as the curriculum one?

 

Export your users onto the curriculum domain, demote the admin DC, join it to the curriculum network and promote it to a DC (assuming you want to use it as one). Easy as... :lol:

Posted
We run a merged network here, its been merged since the NT4 box dissapeared 4 years ago i believe, we never have any problems, ACLs are your best friend :D so far (touch wood) in the 2 1/2 years ive been here there has been no security breaches.
Posted

I agree - go for it!

 

When I came here three years ago, there were two separate networks. It was for purely historical reasons - originally (years ago) admin had a small network, and teachers and pupils had standalones. The standalones were joined to form the curriculum network.

 

I asked our LEA if they had any objections - they hadn't.

 

The way I do it is to allow admin staff access to shares that the teachers use. Only some teachers (those who need it) have access to admin shares.

 

GPO's limit the desktop, and mapped drives pointing to the relevant shares. The admin staff have a very bland GPO, giving them almost free control over their desktops. Teachers have a much stricter GPO locking down their desktop do it's similar to the pupils.

 

The shares are controlled with NTFS permissions.

 

I did it by just doing a double backup of the old admin server, before blowing it away, reinstalling and joining it to the existing curriculum domain as another DC. Then just restore all the admin data and set up shares for the admin staff.

 

It may be harder for you, but that approach was the easist for me. It took me five days in the holidays.

Posted

We had two networks.

 

When we moved from "old sims" to Facility CMIS, I decided that rather than go through an upgrade/install of a Windows 2000 domain for our admin and continue with seperate networks, that it made sense to make our new CMIS box a member server of our existing curriculum windows 2000 AD setup and migrate our admin staff user details.

 

It goes without saying that there were some people who objected. One through a complete lack of understanding of how network security works, and another because "we don't want that...". Would you be supprised to know that these two people were the head and second in the ICT department!!!

 

I went ahead with the change because of various reasons, a few of which were:

1) Staff would now be able to prep materials on the computers in their office, and have them available to use in the classroom.

2) I didn't have to manage 2 separate networks. I know that you shouldn't make a decision on the basis of what is easier for you, but the less time I have to spend admining a system then the more time I can commit to helping students and staff.

3) The one that all head teachers love, it saved money. We only had to buy one new server, for the MIS setup. If we had kept with the old way of doing things we would have needed a second new server because our existing NT4 box didn't have the specs to run server 2000.

Posted

We are on two networks. We have more and more teachers in offices which we are connecting to the curriculum network, operating SIMS through the trust. Having a network password AND a SIMS password is confusing enough without them having separate admin and curric passwords too!

 

Andy.

Posted

@ jcs808,

 

Your story sounds familiar. We have a number of teachers who also do admin work, and were always walking the corridors looking for admin then curriculum computers.

 

The head was always against it. I resorted to writing a 2 page essay on the benefits of joining them (teachers able to do their admin work on the same machine, less admin overhead for me, admin staff able to access teachers docs) and a description of how the security would work. He took one look at it and accepted it straight away, after a year of opposition.

Posted

Seperate!

For 'getting access from any room' we have sims.net and parsql (our registration system) accessible from any machine.

The Sims database runs on the admin server which has a second network card linked to cirriculum. A trust relationship has been setup between the 2 domains and the only thing accessible on the admin server is the 'shared' folder which contains on the sims/pars stuff. Ofcourse this is only accessible to users that are part of the cirricdomain\staff group.

 

As for staff leaving themselves logged in, idle time for locking + logout?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...