ajbritton Posted September 15, 2005 Posted September 15, 2005 My two cents... Single physical network (natch) Single/multiple subnets (as required) but not designated to either admin or curric VLAN (as required) to control traffic flow, but not particularly for security Single AD forest, admin domain is forest root, curric domain as additional domain in the same forest. Having both domains in the same forest means you can get away with a single Exchange server. Also, the trust relationship is implicit so cross domain permissions can easily be set up. Having seperate domains means you can think clearly about what links are required between admin and curriculum, then set them up specifically, rather than worrying about what security you need to put in place to prevent inappropriate access to admin work. Workstations are generally in the admin domain for office staff/smt and the rest are on the curric domain. Users can log into either domain from any workstation because of the implicit trust relationship however. SIMS.NET and FMS will both happily run from curric workstations, and the SQL server takes care of security Single AV & WSUS server can service the entire site
MkII Posted September 15, 2005 Posted September 15, 2005 You still have the concern of Staff attitude or lack of it towards security ajb.
Mango_RW Posted September 16, 2005 Posted September 16, 2005 In reference to staff leaving themselves logged in, why not put a screensaver which times out after x minutes (for us 5) and locks the workstation, into the staff gpo? Works for us!
woody Posted September 16, 2005 Author Posted September 16, 2005 Thanks for all of your inputs. I can't see what the advantage of having two domains running in the same forest over just the single domain. (Taking into account I've never done this.) If a trust is setup between the two domains, then either is accessible anyway. Why not just have the one?
woody Posted September 16, 2005 Author Posted September 16, 2005 Ah, so you can allow teachers on Admin to see shares or other things on curriculum, but stop curriculum from seeing anything on admin. Got it.
Dos_Box Posted September 16, 2005 Posted September 16, 2005 Thanks for all of your inputs. I can't see what the advantage of having two domains running in the same forest over just the single domain. (Taking into account I've never done this.) If a trust is setup between the two domains, then either is accessible anyway. Why not just have the one? Because some school had totally seperate admin and curric networks inc naming structure. It is a victory in itself to bring both into the same namespace. The seperate networks were done under the name of security (fair point) and also under the name of 'paying lots for a support contract which was hardly used' from a third party. It is much better with a single LAN which is configured whichever way suites your purposes.
ConTheITGuy Posted September 16, 2005 Posted September 16, 2005 On applying a policy to screensaver after x minutes... do other folk have these same machines in use for the IWBs? Andy.
woody Posted September 20, 2005 Author Posted September 20, 2005 Ok, so if both of my servers are domain controllers on seperate physical networks and I want to keep the two domains but have admin as forest root domain, and curriculum as second domain with a trust relationship, what is the step by step process? Can anyone point me to some documentation to do this or even record the steps here for me? Thanks in advance!
ChrisH Posted September 20, 2005 Posted September 20, 2005 You would have to migrate your Curriculum domain into the admin domains forest. 2003 supports some kind of inter forest trusts as well I think.... but problably best having both domains in the same forest.
MkII Posted September 20, 2005 Posted September 20, 2005 Ok, so if both of my servers are domain controllers on seperate physical networks and I want to keep the two domains but have admin as forest root domain, and curriculum as second domain with a trust relationship. Ours is set up like that, well, curriculum is forest root and admin a sub domain. It WAS our intention to have the trusts set up as discussed here. There's some linking going on between the root domain and the sub domain - so the consultant that set it up couldn't break the trust between them. Bit pointless really. I think there was an old teacher group left on the DC that was still active on a policy. Must try and get that fixed!
tosca925 Posted September 20, 2005 Posted September 20, 2005 We used to have our seperate but we have everthing on one domain now. As long as the securty is set up correctly you should have no problems.
woody Posted September 21, 2005 Author Posted September 21, 2005 That is what I mean, have both domains in the same forest. Where can I find documentation to do this?
tosca925 Posted September 21, 2005 Posted September 21, 2005 @mark_wood If your reply was to me i think you misunderstood me. We only have one domain, the Sims box is just a server in a multiple server domain. We set up a security group called SIMS USERS and if the staff who use Sims are not a member of this group then they have no access to the server at all.
spc-rocket Posted November 16, 2005 Posted November 16, 2005 Hello all, I think main issues are staff leaving stations logged on etc and giving password to students. Also another differance is that schools who utilise curriculum network which are on RM CC3 Networks tends to have a seperate network for admin. We thought about migrating and its a pain to have all the services that we can offer the admin staff to be migrated to the curriculum and have one big network. For people who have normal networks (without RM) congratulations!!! all the way, you can probably merge the two without many problems but for people who have RM network there are other things to consider ie. technical work required, training staff and getting them to used to the new network etc. Someone mentioned the AUP - we have that and to be honest the SMT makes mistakes as well and don't follow it either so is there any hope about the rest of the teachers following it. However i do agree to having a AUP of somekind because it takes us out of the equation and cover us if any incidents happen. We have seperate networks are present most viruses are on the curriculum network and not admin. Also stuff like WSUS and other tools like Microsoft SBA (security baseline analyser) helps keep the admin secure and patched consitently. I'm with Russ on this if you have to give some access to the other network use software like ISA 2004 (great software!) which allow you to set restrictive access to and from both networks. Ashok.
ChrisH Posted November 16, 2005 Posted November 16, 2005 No, was replying to ChrisH The microsoft tool for this is the active directory migration tool or ADMT Look up the docs for that. Most info will be on about NT 4 to 2003 but in the description is does say: restructure Windows Server Active Directory domains between forests or within a forest
Dos_Box Posted November 17, 2005 Posted November 17, 2005 RM CC3 Networks tends to have a seperate network for admin. The horror, the horror.
Declan Posted December 2, 2005 Posted December 2, 2005 I'm in the process of merging the 2 networks. I'm only allowing access from curriculum to admin via the staff laptops. I've given them all static IP addresses outside the dhcp scope and organised for the ISP (RM trading as South West Grid For Learning) to allow that range of addresses to go through the firewall. As you say, the hardest part is getting them to lock the laptops when they leave the room. How hard is it to press Ctrl Alt Del followed by Rtn for goodness sake!!!! You'd think I was asking them to teach ICT as well!!
kingswood Posted December 2, 2005 Posted December 2, 2005 Good point Declan. I can't tell you the amount of times a certain member of staff has sent me pieces of paper declaring that "the computers in [whatever room] don't work" (when all that's wrong is an errant mouse on ONE machine) but who then leave their admin system unlocked ALL DAY! Or there are the staff members who allow sixth formers to log in to the admin systems and take the register (of course letting them surf and stuff while they do it). And oh yes- last week one told me that he had forgotten his password so couldn't unlock the machine; a helpful student told him, "no problem- I'll log in with [enter staff member's name here] and you can use lesson monitor through their account"! Help! Paul :-P
DMcCoy Posted December 2, 2005 Posted December 2, 2005 I have set the policy to lock the computer when the screensaver comes on. I set it for 5 minutes at first. Oh the complaints!
RobC Posted December 2, 2005 Posted December 2, 2005 How hard is it to press Ctrl Alt Del followed by Rtn for goodness sake!!!! Even just pressing the Windows key & L is too difficult for them!
sahmeepee Posted December 2, 2005 Posted December 2, 2005 Even just pressing the Windows key & L is too difficult for them! Ordinarily I would laugh, but I've had the exact same thing. When told "you can just to windows + L" the reply came, "but I've got so much stuff to do when I'm leaving the office". Ack. It wouldn't be so bad, but there's a bug in the group policy setting in XP SP1 which sometimes causes it to fail.
browolf Posted December 2, 2005 Posted December 2, 2005 we have ours separate wth a trust between them so teachers can access sims from their laptops. A 3rd party company manages the technical side of the admin network & sims. We suffer from the problems of having long established networks. c. 12 years and network managers who dont see eye to eye on some things lol. i'm of the opinion that its fine by me. I dont need even more work for no more money. cant trust teachers to be sensibly security conscious. teachers frequently let kids use their laptops with the teacher logged in and in extreme circumstances have been known to tell kids their password. doh!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now