Jump to content

Recommended Posts

Posted

We have a Curriculum Network and an Admin Network. Our Deputy Head want's the Head and himself to have SIMS access from their Curriculum machines into SIMS off the Admin Network.

 

Is this easy to do - if so how do I do it please?

Posted

you just need to set up a trust relationship between the two domains. quite simple if they are on the same subnet, slightly more difficult if they are on different ones, but it still not amazingliy hard. use the instructions here How to Create a Trust Relationship from One Computerr

 

you then just need to set up a gpo that only applies to those two members of staff with a login script to add the S:\ drive i would suggest a security group called "sims users". then install sims on the pc's in question, then give the 'sims user' group permission to the share =NTFS permissions. Then to give further staff access to sims just add them to the group plus install sims.

  • Thanks 2
Posted
Are you sure you really want to do this? from my understanding by reading threads on here that they are commonly separate for security and that some LEAs/Districts have policys saying that SIMs and other school admin data can't be on the pupil network so you might want to check that as well.
  • Thanks 1
Posted
That's entirely contrary to what we're getting round here - it's the preferred method, having registration done directly from the classroom and whatnot. The data itself isn't on the curriculum network, it's still all server hosted obviously, and without the relevant authentication details can't get any information from the curriculum network. Can't see what the problem is there.
  • Thanks 3
Posted (edited)
That's entirely contrary to what we're getting round here - it's the preferred method, having registration done directly from the classroom and whatnot. The data itself isn't on the curriculum network, it's still all server hosted obviously, and without the relevant authentication details can't get any information from the curriculum network. Can't see what the problem is there.

 

I think this was the common instruction way back before they realized that is was pointless having them on separate networks. We had it at my last school when i set it up, not because of security reasons but for up time of the separate networks. if something went wrong on the admin side the students where not affected, and vice versa, also during the holidays we could shut things down and do upgrades when and where we wanted on the curric range and leave the admin staff working okay.

 

But the security concerns where quashed when they wanted to bring in the registers and stuff for teachers.

 

Toby

 

EDIT: I actually mento to quote p858 snake!

Edited by glennda
  • Thanks 1
Posted
Set up properly the loss of one server shouldn't effect the other - and in some configurations you could run failover quite easily, actually minimising any downtime. Very handy when you need to restart a server after udpates :D
  • Thanks 1
Posted
That's entirely contrary to what we're getting round here - it's the preferred method, having registration done directly from the classroom and whatnot. The data itself isn't on the curriculum network, it's still all server hosted obviously, and without the relevant authentication details can't get any information from the curriculum network. Can't see what the problem is there.

 

In theory, this is the neatest solution but where I see it falls down is at operator level. Teachers are going to leave SIMS logged on, they are going to display it for all to see on the IWBs. No amount of education, threats, floggings is going to prevent it. We have a similar setup to the OP and the HT wants all teachers to have access to SIMS. My recommendation is that we have dedicated curriculum computers in every classroom and put their laptops onto the admin domain.

 

The added bonus to this is that every classroom is the same and will have a working computer for the supply teacher.

  • Thanks 1
Posted
Teachers are going to leave SIMS logged on, they are going to display it for all to see on the IWBs.

 

They could run SIMS over Terminal Services. It works just fine here, and I'm planning to have VPN access for home use by staff - VPN access would probably also be the thing to use to access the admin network from the curriculum network. Running SIMS over TS means you can set a 3-minute timeout on the screensaver on the TS server, so the SIMS session will be locked even if the teacher's PC isn't.

 

--

David Hicks

  • Thanks 1
Posted

We have been encouraged to flatten our networks here, two have my schools have done it so far.

A letter we had from the LA stated that the two network approach was adopted for security but is not seen as an issue with modern OSes.

  • Thanks 2
Posted

As the second post suggested this isn't that hard to achieve even if the SIMS and curriculum networks reside on separate domains and or subnets.

 

We have a lot of schools running SIMS in a workgroup / separate domain environment for small offices and although it isn't difficult to work around it's just a nuisance when it come to setting it up and requires more time.

 

Putting it all on one domain is just easier for all concerned, it's easy enough to use NTFS and SIMS SQL based security to make sure non SIMS users can't start accessing the shared drive or the SQL Server. On top of that use GPO and login scripts to make sure those who do need access get it.

 

As laserblazer said - it only really falls down at operator level where people give away passwords or leave it logged in for all to see. I see this as more of a security culture issue than of a technical one.

  • Thanks 1
Posted

Imagine the millions of pounds that would be saved in consolidation if schools would move on from this seperate networks nonsense which predates the 90's :rolleyes:

 

Take our overpaid LEA consultants with very little knowledge in what they deal with - on one hand they're telling schools to get "SIMS into the classroom" but under no circumstances should they put "admin" machines into classrooms or at any point join these networks to facilitate the overall objective.

 

Just how do they expect school to go about this?

 

We collapsed our network a few years ago - you are only paid to run one network afterall :rolleyes:

  • Thanks 1
Posted
If your LEA hosts the SIMS database all you need to do is setup a shared drive on one of the curriculum servers and map it from curriculum machines as say the S: drive and thern alter the connect.ini appropriately. We have done this type of setup here.
  • Thanks 1
Posted
If your LEA hosts the SIMS database all you need to do is setup a shared drive on one of the curriculum servers and map it from curriculum machines as say the S: drive and thern alter the connect.ini appropriately. We have done this type of setup here.

 

this will work - but what happens when your LEA updates SIMS? How do you make sure your local SIMS version is at the right level as your LEA SIMS sql db?

  • Thanks 1
Posted (edited)
but what happens when your LEA updates SIMS?

 

We had a bit of trouble at first with this, they always inform us when an upgrade is taking place but I would have to hunt people down by telephone for them to make the necessary updated SIMS folder available, but at the end of the day the updated files where already on the admin network as these get updated by the LEA, so we just copy the S: drive from one of the admin machines and copy it to the curriculum server. Messy I know but it works. I suppose I could find an easier or automatic way of doing it. I am in favour of the one network approach but either the school or the LEA want to keep them seperate at the moment.

Edited by jsnetman
  • Thanks 2
Posted

The way we currently do it for reports etc is to allow all teaching staff an account on our SIMS server. Then whenever they are on a curriculum machine they can RD over to the admin network.

However people are now saying it takes to long. They want a combined solution similar to what is being asked by the OP. I would rather keep them separate for the security implications

 

The accounts on the admin and curriculum are separate accounts and what we are finding is that staff can never remember their passwords for the admin network.

  • Thanks 1
Posted

When we introduced Electronic Registration here I setup a trust between the two domains. Teachers get a 'hidden' mapping to the S: drive which enables SIMS to launch.

 

Have moved all the users of the Admin Domain now, setup a seperate OU structure with Loop Back for all the Admin Machines so they behave differently regardless of your login.

 

Plan is to flatten the Domain eventually, may do it over the Summer break when we need to go to SQL2008 which will involve me getting a Capita engineer in for the day to assist in ensuring all goes well.

 

Pete

Posted
Are you sure you really want to do this? from my understanding by reading threads on here that they are commonly separate for security and that some LEAs/Districts have policys saying that SIMs and other school admin data can't be on the pupil network so you might want to check that as well.

 

Acording to Becta guidance combining the two networks / crossing over is OK. At least thats what our LEA says

 

Thanks

- Stuart

  • 2 weeks later...
Posted
Imagine the millions of pounds that would be saved in consolidation if schools would move on from this seperate networks nonsense which predates the 90's :rolleyes:

 

Take our overpaid LEA consultants with very little knowledge in what they deal with - on one hand they're telling schools to get "SIMS into the classroom" but under no circumstances should they put "admin" machines into classrooms or at any point join these networks to facilitate the overall objective.

 

Just how do they expect school to go about this?

 

We collapsed our network a few years ago - you are only paid to run one network afterall :rolleyes:

 

I work at an LA and agree to some extent on the overpaid consultants remark, however as far as joining the two domains is concerned a trust relationship between the two should work.

 

Personally I'd prefer a single domain properly managed.

 

The rest of us get peanuts by the way.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...