pritchardavid Posted November 3, 2010 Posted November 3, 2010 (edited) How do people do their network? Do you have a seprate domain for admin and curriclum or do you have everything all in one domain? We most likely are gonna go all virtual (Hyper-V) Our support company are recommending to merge them into one network This is what he has said on the migration steps that I asked him about, has orginally I never said anything about the admin network. 'I was assuming that the domains to be merged, keeping them seperate was the old way of doing it. If we keep a seprate file server VM this is normally sufficient, if we grant an explicant 'deny' right for the admin data it is secure' We run both sims.net and sims fms for just the finince side and Secro Factiliy & eportal for the MIS I think that is right, dont really deal with the admin network alot So there is a few advantages for doing that, less to go wrong Only one print server instead of two Only one domain instead of two Only one WDS instead of two Only one WSUS instead of two Only one DNS System instead of two Only one DHCP System instead of two Only one Active Directory System instead of two Plus problery some others So what do you think? And what do you do? Edited November 3, 2010 by pritchardavid
GrumbleDook Posted November 3, 2010 Posted November 3, 2010 2 things ... 1 - I have preferred flat networks for some time. It makes little sense to say "but we are trying to protect data" if you the give access via ePortal anyway. As long as you are happy that you are taking the required steps to control sensitive data such as personnel files, etc then fine. Use this as a chance to do a data audit, make sure you know who the data owners are, get a SIRO in place, etc. Also use it to look at consolidating storage and backups. 2 - I don't know the company who is doing this so the following isn't a reflection on them, more a question for any such company .... from the cynical part of me. Perhaps they want to do it as it will earn them more money? Something to consider. Then again, from the day I have had in Reading looking at efficiencies in ICT (blog post over the weekend or look at the Twitter hash tag #ictefficiencies) then even if it does cost more, perhaps it will pay for itself. Whatever you do, try to make sure you only retire kit when it is end of life ... If a server still has two years to go and you are virtualising it now, that might be a waste of money. Just a thought.
pritchardavid Posted November 3, 2010 Author Posted November 3, 2010 (edited) Sort of can see what there saying What I thought might be a better idea If the vm hosts have both admin and curriculum (two ethernet cables configured to the correct vlan on the switch port) And IF you can select what vlan on the hyper-v manager for a VM then we could make a VM for the admin file server and configure that to admin vlan only And then set all other VMs to use use both vlans Sims is on it own pysical server like it is now Serco Facility is on its own pysical server like it is now Both connected to the admin vlan And maybe upgrade both servers from 2003r2 to 2008r2 (only if there comptable with them, or 2008 if not compatiable with 2008r2) Does that sound like that would work? Would you say that would be better than their idea? Edited November 3, 2010 by pritchardavid
clareq Posted November 3, 2010 Posted November 3, 2010 We merged both networks years ago, as it became harder to identify whether a person required an admin or a curriculum machine - so many users have a foot in both camps - teachers take registers and write reports in SIMS, and need to use curriculum software to plan lessons. Do you give them 2 machines, or insist they log off one machine and onto another to do a different job? File permissions keep data secure. 1
elsiegee40 Posted November 3, 2010 Posted November 3, 2010 I admit I have a much smaller network than most of you, but admin and curriculum are on the same domain. At my last (state) school, they were separate only because Kent's EIS that were responsible for SIMS flatly refused to let SIMS be installed anywhere other than on its own domain. It was a pain!
sted Posted November 3, 2010 Posted November 3, 2010 were beginning to merge them as most admin networks are a server and 2-3 workstations. it seems silly too have a domain and all the related roles for 4 computers. We now tend to run the admin server as a vm that is a file store for admin suers and sims server. Its not a dc anymore has no other sql datacabses for wsus/sophos etc just has 2 nics (due to lea requiring admin server to have ip of 10.even.x.100 to send data to them) much simpler setup and the sims server isnt used as a workstation etc so is a simple machine less to go wrong
witch Posted November 3, 2010 Posted November 3, 2010 Dorset (bless) still advocate separate domains - although being part-time it means I dont have to worry about issues on the admin network which are generally more urgent than on the curriculum side. However, they are now sorting out a trust -with firewall - so that teachers can see SIMS and eventually we can sort the data out for the parental engagement bit of the VLE.
AngryTechnician Posted November 3, 2010 Posted November 3, 2010 (edited) I've always been in favour of a single domain. My feeling is that a split system is really only done in cases where whoever looks after the admin side doesn't trust whoever looks after the curriculum side to deliver a secure network. If the security is set up by somneone with even half a clue, there is NO security problem with having a combined network. The only schools I've worked in that had separate networks were those where the LA looked after the admin network in its entirety. You're looking after both, and you've already identified some serious benefits in your first post: really I wouldn't be thinking "why have a single domain", but "why NOT have a single domain". Edited November 3, 2010 by AngryTechnician
pooley Posted November 3, 2010 Posted November 3, 2010 Admin & Curriculum are separate here, dictated by LA. I'm hoping to "flatten" within the next year and have once nice domain.
pritchardavid Posted November 3, 2010 Author Posted November 3, 2010 Liking the idea of one domain then! I'll speak to the boss about this tomorrow then, plus need to speek to him about our support company quote for migration ok another few questions here Has I said I dont know much about the admin network Sims FMS - Is that an addon to sims or older version of sims, im a bit confussed, heard my supervisor talk about it before to someone, makes my think its a seprate product or something If we would do to this im gonna suggest upgrading the servers os to a newer version can you tell me what supports what and also the sql version Sims.net support upto Server 2008R2? Sims.net support SQL 2008R2? Sims FMS support Server 2008R2 Sims FMS support SQL 200R2? Serco Factility support Server 2008R2? Serco Facitlity sypport SQL 2008R2?
Steven_Cleaver Posted November 3, 2010 Posted November 3, 2010 I have worked on both and found that as long as you secure everyting correctly a single Domain is much easier to manage, in fact one of the first things I was asked at my interview for my present position was wether I prefered single or split as they had Admin/Curriculum on seperate Domains and wanted to move these together. To be honest we Virtualised the Curriculum Network first and put in a better backup solution. Then it wasn't to difficult to add in the Admin Systems and P to V the admin Server and move over the admin workstations onto the Curriculum Domain.We did this with some support from an external company as we wanted to do this pretty quickly and support the Admin side more as previously this had been done by the LEA although this was done pretty well we were just trying to bring as much as possible in house.
Butuz Posted November 4, 2010 Posted November 4, 2010 Well here my Admin Network is actually part of the LEA network so I am limited in what they will allow. Therefore we had to keep a separate admin and curriculum domain. However I have Virtualised both the Network Infrastructure (Procurve VLANs) and the Server Infrastructure (VMWare) for both curriculum and admin domains. This means I can keep both networks virtually separate (and keep the LEA Happy) whilst actually saving money by collapsing them both onto one physical network and server set up. Money is saved by: a) reducing the number of switches used (from 30 to 20) thus bringing replacement and electricity costs down b) reducing the number of servers used c) being able to tag any network drop as either admin or curriculum - whereas before with the physically separate infrastructures I often had to get new network runs put in just for admin drops so money saved there too. It works well. I can change any network drop in the school to curriculum or an admin and I can give any server admin or curriculum network access simply at a few clicks of the mouse. Ideally everything would be on one domain but with very tight security - but the LEA won't allow that. Butuz 1
jsnetman Posted November 4, 2010 Posted November 4, 2010 Merged our admin network into the curriculum summertime, easier to manage, easier for users. Admin network formerly under LEA control but they were pushing for schools to merge them to curriculum as we are all going trust status, sorry we already have gone trust and most schools to follow up here.
bio Posted November 4, 2010 Posted November 4, 2010 one domain, different vlans. best of both. same here bio
IanT Posted November 5, 2010 Posted November 5, 2010 We have 2 domains here, i'll be demoting the admin network soon as there's nothing running on it, im a fan of running everything on one.
bondbill2k2 Posted February 3, 2011 Posted February 3, 2011 we also have two and a separate for SIMS. I don't really see the need as theirs only reception and accounts that use the admin side, around 6 computers in total
gshaw Posted February 7, 2011 Posted February 7, 2011 Looking at bringing our two together in summer with VLANs and ACLs to keep classroom PCs away from sensitive data. Will make life easier as it's a single management entity for SCCM, AV, AD etc but as much as it's exciting it also makes me nervous as there's no way for one network to carry on if the other has issues (although you could argue that if it's set up robustly with virtualisation that shouldn't be an issue)
bondbill2k2 Posted February 7, 2011 Posted February 7, 2011 Ours are two seperate servers but they are connected to eachother, mainly for resources and printers, we also run a 2 vlans for admin and curric.
pritchardavid Posted May 16, 2011 Author Posted May 16, 2011 (edited) Ok bit of an update What do you think of this VM01: CurriculumFileServer (File Server For CurriculumFiles) VM02: AdminFileServer (File Sever For Admin Files) VM03: WebServer (Hosts VLE, School & Library Website) VM04: SCCM (SCCM 2007R3, Forefront) VM05: StreamingServer (Windows Media Server) VM06: DeploymentServer (Windows Deployment Services Role) VM07: PrintServer (Print Server Role) VM08: Impero (Impero Server & Console) VM09: Mail (Exchange 2010) VM10: DC1 (Domain Controller, Spilt FMOS Roles, GlobalCatalog, DNS, Spilt DHCP) VM11: DC2 (Domain Controller, Split FMOS Roles, GlobalCatalog, DNS, Spilt DHCP) VM12: AppServer (LexiaServer, Wordshark, Ultrakey) VM13: SimsServer (Sims/FMS/SQL For Sims/FMS) VM14: SercoServer (Facility/ePortal/SQL For Facility/ePortal) WM15: SharePoint (SharePoint 2010) WM16: SharePointSQL (SQL 2008R2 for SharePoint 2010) Anything you recommend to change or add? Would you say its the best for the SQL database for the Secro ePortal/Factility would be better on a seperate server instead of hosting it on the same server? Gussing this would be good idea, due to we can make a clean virtual server when any new SQL Server release comes out, and just transfer the database? Also if you recommend that, should that be done with the sims/fms database - note only three users use this in the fincance office. In fact would you recommend any SQL database have its own Virtual Server The other things we have using SQL is Forefront, WSUS, SCCM, thats all on the same server, thats all so hosting all the software/roles for thoses. Thanks Edited May 16, 2011 by pritchardavid
cpjitservices Posted May 16, 2011 Posted May 16, 2011 Why not just have the one domain and VLAN your network - we had 3 - 4 VLANS for different people on different networks keeping the admins completely separate from the students in terms of security.
pritchardavid Posted May 16, 2011 Author Posted May 16, 2011 Why not just have the one domain and VLAN your network - we had 3 - 4 VLANS for different people on different networks keeping the admins completely separate from the students in terms of security. Hi there Thats what I want to do!!! ... One domain, just make the serco,sims, admin file server on the admin vlan. What I wanted to know what did you think of my virtual server setup list? any comments, plus answer my few questions
cpjitservices Posted May 16, 2011 Posted May 16, 2011 What about proxy server ? - you could host your own virtual proxy with squid & dansguardian unless you go through the LEA's - other than that I'd say you have it covered VM side.
pritchardavid Posted May 16, 2011 Author Posted May 16, 2011 What about proxy server ? - you could host your own virtual proxy with squid & dansguardian unless you go through the LEA's - other than that I'd say you have it covered VM side. Yer we go throught the LEA at the momment, but once we done all this, might look at the forefront for filtering and proxy, cache Would do you think about sql for the vm then?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now