Jump to content

Recommended Posts

Posted

My two cents...

 

Single physical network (natch)

 

Single/multiple subnets (as required) but not designated to either admin or curric

 

VLAN (as required) to control traffic flow, but not particularly for security

 

Single AD forest, admin domain is forest root, curric domain as additional domain in the same forest.

 

Having both domains in the same forest means you can get away with a single Exchange server. Also, the trust relationship is implicit so cross domain permissions can easily be set up.

 

Having seperate domains means you can think clearly about what links are required between admin and curriculum, then set them up specifically, rather than worrying about what security you need to put in place to prevent inappropriate access to admin work.

 

Workstations are generally in the admin domain for office staff/smt and the rest are on the curric domain. Users can log into either domain from any workstation because of the implicit trust relationship however.

 

SIMS.NET and FMS will both happily run from curric workstations, and the SQL server takes care of security

 

Single AV & WSUS server can service the entire site

Posted

In reference to staff leaving themselves logged in, why not put a screensaver which times out after x minutes (for us 5) and locks the workstation, into the staff gpo?

 

Works for us!

Posted
Thanks for all of your inputs. I can't see what the advantage of having two domains running in the same forest over just the single domain. (Taking into account I've never done this.) If a trust is setup between the two domains, then either is accessible anyway. Why not just have the one?
Posted

Ah, so you can allow teachers on Admin to see shares or other things on curriculum, but stop curriculum from seeing anything on admin.

 

Got it.

Posted
Thanks for all of your inputs. I can't see what the advantage of having two domains running in the same forest over just the single domain. (Taking into account I've never done this.) If a trust is setup between the two domains, then either is accessible anyway. Why not just have the one?

 

Because some school had totally seperate admin and curric networks inc naming structure. It is a victory in itself to bring both into the same namespace. The seperate networks were done under the name of security (fair point) and also under the name of 'paying lots for a support contract which was hardly used' from a third party.

It is much better with a single LAN which is configured whichever way suites your purposes.

Posted

Ok, so if both of my servers are domain controllers on seperate physical networks and I want to keep the two domains but have admin as forest root domain, and curriculum as second domain with a trust relationship, what is the step by step process? Can anyone point me to some documentation to do this or even record the steps here for me?

 

Thanks in advance!

Posted
You would have to migrate your Curriculum domain into the admin domains forest. 2003 supports some kind of inter forest trusts as well I think.... but problably best having both domains in the same forest.
Posted
Ok, so if both of my servers are domain controllers on seperate physical networks and I want to keep the two domains but have admin as forest root domain, and curriculum as second domain with a trust relationship.

 

Ours is set up like that, well, curriculum is forest root and admin a sub domain. It WAS our intention to have the trusts set up as discussed here. There's some linking going on between the root domain and the sub domain - so the consultant that set it up couldn't break the trust between them. Bit pointless really. I think there was an old teacher group left on the DC that was still active on a policy. Must try and get that fixed!

Posted

@mark_wood

 

If your reply was to me i think you misunderstood me. We only have one domain, the Sims box is just a server in a multiple server domain. We set up a security group called SIMS USERS and if the staff who use Sims are not a member of this group then they have no access to the server at all.

  • 1 month later...
Posted

Hello all,

 

I think main issues are staff leaving stations logged on etc and giving password to students. Also another differance is that schools who utilise curriculum network which are on RM CC3 Networks tends to have a seperate network for admin. We thought about migrating and its a pain to have all the services that we can offer the admin staff to be migrated to the curriculum and have one big network.

 

For people who have normal networks (without RM) congratulations!!! all the way, you can probably merge the two without many problems but for people who have RM network there are other things to consider ie. technical work required, training staff and getting them to used to the new network etc.

 

Someone mentioned the AUP - we have that and to be honest the SMT makes mistakes as well and don't follow it either so is there any hope about the rest of the teachers following it. However i do agree to having a AUP of somekind because it takes us out of the equation and cover us if any incidents happen.

 

We have seperate networks are present most viruses are on the curriculum network and not admin. Also stuff like WSUS and other tools like Microsoft SBA (security baseline analyser) helps keep the admin secure and patched consitently.

 

I'm with Russ on this if you have to give some access to the other network use software like ISA 2004 (great software!) which allow you to set restrictive access to and from both networks.

 

Ashok.

Posted
No, was replying to ChrisH :)

 

The microsoft tool for this is the active directory migration tool or ADMT

Look up the docs for that. Most info will be on about NT 4 to 2003 but in the description is does say:

 

restructure Windows Server Active Directory domains between forests or within a forest
  • 2 weeks later...
Posted
I'm in the process of merging the 2 networks. I'm only allowing access from curriculum to admin via the staff laptops. I've given them all static IP addresses outside the dhcp scope and organised for the ISP (RM trading as South West Grid For Learning) to allow that range of addresses to go through the firewall. As you say, the hardest part is getting them to lock the laptops when they leave the room. How hard is it to press Ctrl Alt Del followed by Rtn for goodness sake!!!! You'd think I was asking them to teach ICT as well!!
Posted

Good point Declan.

 

I can't tell you the amount of times a certain member of staff has sent me pieces of paper declaring that "the computers in [whatever room] don't work" (when all that's wrong is an errant mouse on ONE machine) but who then leave their admin system unlocked ALL DAY!

 

Or there are the staff members who allow sixth formers to log in to the admin systems and take the register (of course letting them surf and stuff while they do it).

 

And oh yes- last week one told me that he had forgotten his password so couldn't unlock the machine; a helpful student told him, "no problem- I'll log in with [enter staff member's name here] and you can use lesson monitor through their account"!

 

Help!

 

Paul :-P

Posted
How hard is it to press Ctrl Alt Del followed by Rtn for goodness sake!!!!

 

Even just pressing the Windows key & L is too difficult for them!

Posted
Even just pressing the Windows key & L is too difficult for them!

 

Ordinarily I would laugh, but I've had the exact same thing. When told "you can just to windows + L" the reply came, "but I've got so much stuff to do when I'm leaving the office". Ack.

 

It wouldn't be so bad, but there's a bug in the group policy setting in XP SP1 which sometimes causes it to fail. :(

Posted

we have ours separate wth a trust between them so teachers can access sims from their laptops. A 3rd party company manages the technical side of the admin network & sims. We suffer from the problems of having long established networks. c. 12 years and network managers who dont see eye to eye on some things lol.

 

i'm of the opinion that its fine by me. I dont need even more work for no more money. cant trust teachers to be sensibly security conscious. teachers frequently let kids use their laptops with the teacher logged in and in extreme circumstances have been known to tell kids their password. doh!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...