Jump to content

Recommended Posts

Posted

Seeing as we're going to be virtualising over the summer the old chestnut of how split the network needs to be has come to the forefront again.

 

As it stands everything is separate; two physically split networks with their own domains etc for students and staff. Plus points of this; can't get better security than 2 separate cables, if one network gets affected the other carries on etc. Downsides; two lots of management for AD, AV, GPOs etc.

 

So the choices as I see it...

 

  • keep as is
  • 2 domains split by VLANs i.e. merge the comms but keep the ADs separate
  • domain \ subdomain with merged comms
  • single domain doing the lot

 

The main issues I have is with security because currently the student workstations have machine-based logons; not sure if I'm happy with having the possibility of those machines getting any chance of being near admin data.

 

The other thing that stays in my mind is if there's a Conficker-type virus outbreak again we can keep our business side locked down but it's much harder to do with student network.

 

So it comes down to whether easier network administration is worth the tradeoff in security. What's the flavour of the month on your networks at the moment and what direction are you looking towards for the future?

Posted

You've also got to consider the running / support costs of two physical networks. Historically, across the county there has been a single physical network, 2 IP ranges but not VLANed properly (ie VLANed at the router but actually bound to the same interface).

 

Slowly this is disappearing to a single physical network with one domain, and then the more advanced schools are applying VLANs to segregate some services.

 

I would prefer to spend the time, money and effort on working towards user-based account, perhaps through biometrics or access tokens if you don't want usernames / passwords, and keeping it simple. Remember that for all your efforst on the security side of things, if it is not also followed up with staff training, and policies & procedures ... then it could be a waste of time.

Posted

Hi gshaw, we have a split network here. one for Admin one for Student. I wasn't around when it was done but the Admin network is completely different to the student. Student machines are completely locked down but we do have local logins at the machines so if we really need to we can login as local Administrator on machines, we never really panic when viruses like conficker come along as we know we have good security but also the network is really locked down. It's that locked down that only admin machines can use Novell Groupwise and anything on the Student Network can't - if I was to login as admin on the student machines you can't even ping the server for email,proxy,imaging etc etc, we use 2 different IP ranges for both networks, but also we have other networks implemented alongside the one we have now so if anything where really seriously to go wrong we have the other network as a backup.

 

The admin on our network is actually quite good, a lot better than some I've come across, personally I think if you have the right tools (software ;)) then security and admin can go together easy, considering we have many many sites across the UK as a Tech I've not come across anything that cant be done remotely and not many calls come through for the other sites.

 

We use our own Proxy Servers and Firewalls too, I think for security this is the best option, changes can be made if need be immediately and if something goes wrong you know how everything is set up which equals less down time.

 

We are going to keep our machine based logons, so we can login locally as Admin but we have VERY secure passwords which no student will ever guess :)

 

Hope this helps you in your decision

Posted

I would prefer to spend the time, money and effort on working towards user-based account, perhaps through biometrics or access tokens if you don't want usernames / passwords, and keeping it simple. Remember that for all your efforst on the security side of things, if it is not also followed up with staff training, and policies & procedures ... then it could be a waste of time.

 

Yup the student accounts is something we're nearly there with as we've had to do it for Moodle, it's just keeping on top of daily changing student enrolments that's the challenge and making sure no student gets stuck in a class because they joined late etc. Just not sure if it will be there in time if I was to go down that route this summer.

 

My real preference would be to start on a fresh domain and rebuild from scratch but the thought of rebuilding shares and user permissions puts me off tbh. Probably just as easy to rebuild GPOs on the admin network and go from there if we wanted to merge.

 

It's really the case of two ADs \ SCCM etc where the support time comes into it :(

Posted
We have 2 linked domains running on the same physical network. Seems to work OK most of the time. Only problem I've really hit has been the occasional permissions issue. Having said that, the networks were already set up like this when I started and if I were to have a hand in re-doing them I'd probably lean toward setting up a proper domain forest system.
Posted

We happened to be one of the leading schools in our LA that broke with the tradition of 2 networks and now just have one which has been operating for 9 years under a single domain. We have never had any security issues as the students have no access to the data fullstop.

 

We do not have to VLAN as it is not necessary to VLAN a network until you have at least 1000 workstations.

 

I cannot believe that LAs have still held fast to outdated operations of networking it beggars belief.

 

Some LAs are so out of touch with the schools :(

Posted (edited)

On the simplest level I guess I could bring the teaching machines into the admin domain and just rely on the ACLs to stop any student machines \ accounts getting to files. I'd feel more secure if I did this with VLANs so the admin servers with critical data weren't actually able to be contacted by the student PCs. Not sure how this would work with those same machines needing to contact AD though?

 

Could give AD severs access to both VLANs so they can service requests from admin or teaching but keep the admin file server, email and SQL on the admin VLAN only? We also could do with setting up another VLAN for wireless guest traffic ready for when we get Ruckus (although they say there's a way to do it without needing the VLANs as well)

 

We've got HP Procurve 2610s in the room cabs and a 5406zl in the server room which I believe are layer 3 switches so they would handle the VLAN routing with no extra hassle if I'm right?

 

We had the 2 networks long before I was here, I think it used to be something our local council enforced if you wanted to access their services. Now it's all done over Citrix so doubt that rule still applies. Up until now there's been no reason to change it as the 2 networks does work tbh. Just thinking when we virtualise the servers if it's worth moving to something a bit more standarised.

Edited by gshaw
Posted (edited)

gshaw:

 

You wouldn't need to VLAN if your MIS server is just added to the domain and only the teaching staff user groups have access to the server through ACL permissions, with this in place no other user types will be able to gain access to the server job done.

 

Keep things simple is the best policy I feel, why make more work for yourself and it just works with no extra file permissions etc etc, so no connectivity problems or MIS application failures plus total security. :)

Edited by bossman
Posted

Very true, guess I'm just paranoid :p

 

Would be the easiest route, that way all I'd need to do is re-join the teaching machines to our existing domain on next re-image, tweak AD with some new GPOs and job done.

 

One thing that will need doing is extending the IP addressing scheme as both are on a 255.255.255.0 scheme which is getting tight on the teaching side what with switches, printers, probably wireless APs etc!

Posted

thats is the issue we had 8 years ago when we had 3 domains and brought them all into one on NT4 . we setup up vlans

1 for switches

2 servers

3 public workstations ( student access)

4 private workstations (staff access)

6 wireless

7 VOIP

 

this gave us loads of advantages

security

isolating broadcast traffice accross vlans ( great for ghosting)

more ip adresses available.

 

but most of all ease of management

Posted
the old chestnut of how split the network needs to be has come to the forefront again.

 

I'd go for a single domain, with servers & workstations, printers, wireless and VoIP on seperate VLANs. Handle any information security issues by simply accessing your MIS and any admin documents through Terminal Services / Virtual Desktops - handily provides for nice, secure home access for staff at the same time.

 

--

David Hicks

Posted

@dhicks:

 

Would agree with you on single domain but no need for VLANs unless as I have stated you have at least 1000 workstations plus all peripheral equipment.

As for Terminal services yes would agree with you on this but only for remote access as TS server would only support at max 30 concurrent connections and this would mean more than 1 TS server to manage.

 

I would go with MIS server virtualised and 1 TS server virtualised which will cover any eventualities but this is only my feelings on this as I like to keep everything simplistic as this works remarkably well.

 

I am not against VLANS but even Microsoft advise against complicating a network design unless you have more than 1000 workstations or have split sites and organisations within them.

 

I would agree with VLAN for VOIP and also media streaming to keep the bandwidth at a minimum for the data traffic needed.

 

As the backbone speeds along with 10Gbps switching protocols allow for more dataflow then there becomes less need to seperate traffic with VLANS as the bandwidth is already available to support all types of data at increasing speeds which will only get faster with Cisco's new protocols which will allow transfer wirelessly at speeds of 60Gbps with backbone data transfers of 100Gbps to follow.

 

@dhicks: only my suggestion not to undermine yours as I have great respect for your work and your posts on this forum. :)

Posted
gshaw:

You wouldn't need to VLAN if your MIS server is just added to the domain and only the teaching staff user groups have access to the server through ACL permissions, with this in place no other user types will be able to gain access to the server job done.

 

At the moment, if a student knows a staff password, the only way they can gain access is if they sit at a staff machine - typically those will be in staffrooms etc and not accessible to students. Move to a single LAN and that changes. As we all know, not all people can be trusted to use secure passwords so security which just relies on file ACLs may not be as secure as you need it to be.

 

Adding VLANs so that classroom machines are on a different VLAN from staff machines and the SIMS server etc is only accessible from the staff VLAN puts back some of the security you had with 2 physical LANs but without the cost/complexity etc

 

You put the AD servers and any servers which need access by both staff and students on a different VLAN.

 

KISS is a really good principle but you can be too simple :-)

Posted

Another handy thing with VLANs is applying QoS can be useful, but this is only if you really have some heavy duty stuff on segments on the network.

 

I'm another fan of pushing out access to the MIS via a terminal server. It increases security, reduces the need for client updates and can also help with remote access for staff to sensitive data.

Posted
You're a funny man. This is a joke, right?

 

To be honest, if you don't need it then you don't worry about it. KISS can be very handy to remember and if your network performs well as it is then should you need to make changes to introduce VLANs then why worry. For some of the schools in our area it is needed, but many get on fine without it.

Posted

I had to think about this a few years ago and found people claiming to get away with ~ 1000 and I recall finding yet another 80/20% rule for other/broadcast traffic somewhere. Given an IP network it's mostly ARP (with a relatively tiny dash of DHCP) and that's normally few_servers<->workstations+printers, not everything<->everything. But I would consider subnetting at 510, unless of course there was another reason e.g. I wanted ACLs between boxes, multicasting or something.

 

It must depend on the "character" of you network surely? Whether everything gets turned on at the same time.. where the traffic flows.. what the percentages actually say.

Posted

I have worked in a few schools and seen a few setups now. I like the one I have now all in one big domain, do anything anywhere within reason and its just great. Staff can hotdesk and work as they need wherever they are, students can do the same its much more flexible for teaching and learning. My school used to have the 2 seperates but more and more mess and files on one and not the other so I heard from staff so this way is much better.

 

If you are worried though, why not do as another school I used to work at had. They had one Domain so all users were on that, and then servers were either dual NICs (one in each LAN) or single (and dedicated to one LAN or the other). They needed 2x DHCPs, 2x DNS's and thats about it so it was 2 IP ranges used. All other servers were either for one specific LAN EG Finance only on the Finance LAN, main MIS program on the main Admin LAN (they used Eportal for the teaching side so they had easy registers in the classroom via that), ISA had 3 NICs one from each Internal LAN and the WAN card.

 

Users could logon to any PC anywhere in the school, and if you were at an admin one you could access admin file shares and folders, if you were on an academic one you coulnd't access some things. Teaching PCs in Classroms were academic, the Admin LAN was very much an administration LAN for the Administration staff such as SLT, Finance etc. Some Desktop PCs were dual carded, such as ours in ICT Office as well, that made life easier so you could do it all on one PC rather than having 2 which I did at one point.

 

If you asked me if I would do that setup myself now, If I had the risk they had (boarding school lots of kids PCs on the LAN) then I would probably look at that or VLANs, but I am happy with our one big happy LAN system that I have now. The risks, if well setup and managed, are minimal and you do need to look at the TCO of the systems, Virtualising them all can help with the TCO, but its still 2 sets of systems to manage, switching, setups etc...

Posted

The VLAN thing is very dependent on your setup and the 1000 number is purely speculative and kind of a worst case scenario. It all depends on the throughput and capacity of your switches, links and workstations. If all of your workstations are on 100mbit cards it will take a lot less to saturate them with broadcasts than 1gbit ones. Also if you have smaller trunks between switches these will also lead to saturation eairlier. Having things like wireless involved also pushes the limit down massivly and should always be subnetted/VLANed off as a networks worth of broadcasts ratteling through shuch a limited bandwidth will choke the wireless clients quickly.

 

Devices and protocols that you have running on your network also play a big part, anything running Appletalk (printers usually) will do their best to drown your nework with rubbish broadcast traffic that is completely pointless unless you have older macs floating around.

 

Keeping it simple is a good idea but a certain amount of complexity can save you from some of the pitfalls like broadcast storms caused by loopbacks and some security issues. It is a balance though. In the end the number and required complexity of your setup depends entirely on your network environment itself and any numbers should be looked at as loose guidelines rather than rules when it comes to such variable things.

Posted
no need for VLANs unless as I have stated you have at least 1000 workstations plus all peripheral equipment.

 

But I'd use VLANs to simplify different aspects of the network. I'd put wireless on its own VLAN, ensure it had a robust filtering policy in place and then leave it open, allowing all pupils, staff, visitors, etc to use it without messing around with passwords. Any "real" networking would be done via the wired network, so if the wireless network ocasinally gets nuked by a virus or something being passed around then that's the user's lookout.

 

Printers would be on their own VLAN for security - all printing would have to go through a print-tracking gateway, with no option to go directly to a device's IP address.

 

TS server would only support at max 30 concurrent connections and this would mean more than 1 TS server to manage.

 

A TS "server" is actually a big, glorified workstation, and should be treated and managed as such, i.e. it should be reconstructable via an imaging / unattended install system. Once one TS server is set up and configured it should take no real effort to add more. Load-balancing amoungst a farm of TS servers can be done well enough via round-robin DNS rather than paying for a fancy load balancing solution.

 

@dhicks: only my suggestion not to undermine yours as I have great respect for your work and your posts on this forum. :)

 

Hey, if you want an argument we can settle this like gentlemen at BETT - Queensbury rules, no striking below the belt, dos_box can act as an impartial referee :-)

 

--

David Hicks

Posted
@dhicks:

 

Would agree with you on single domain but no need for VLANs unless as I have stated you have at least 1000 workstations plus all peripheral equipment.

 

The advantages of VLANs are a lot more than controlling broadcast traffic amount.

 

We have about 500 devices on our network here, and its split into 8 VLANs:

 

Servers

Office Machines

General

ICT1/2/3

Wifi

Phones

 

The reasons for VLANs for us were:

 

Limit broadcast virus propagation

Allow more targeted broadcast ghosting

To prepare for a more complex system with ACLs between VLANs for use with Wifi and guests

Easier targetting of IP address ranges, so when an IP is spotted doing something, I can instantly recognise where it is etc...

 

Not to mention, that 1000 devices number is a bit high IMO.

Posted
if you are worried about "admin data" in a single domain environment then i put that on a separate server on the domain even most staff dont have access to it. You can always block / allow login to pupils on office pcs ditto for office users (cant see them wanting to use a suite to run sims). I also have the permissions on my admin server set up with things like on the d drive i just deny pupils so even if they find the server and i make a slight mistake in the permissions they are kept off. as to staff leaving passwords lying around there is only so much handholding you can do at some point users have to be responsible for themselves. You could also using group policy preferences map drives on a per pc basis and only certain pcs get access to them thatway and then block students from those pcs
Posted

Hmmm I think I prefer the idea of the VLAN environment if there's just the one domain, something like...

 

- Admin PC VLAN (offices)

- Teaching PC VLAN (classrooms)

- Wireless VLAN (isolated guest access)

- Wireless VLAN (trusted network for our laptops)

 

As for the servers the ideal thing would be to have the email and database servers sitting in a place only the admin PCs could contact; however I'd need the AD servers to be seen by all PCs and the database server needs to see AD so not sure how that works out.

 

Had a bit of a Google yesterday and it all seems to be down to the routing... need to find a lot more about this really as it's something we've never gone near before.

 

Have to admit by the time you isolate the teaching from admin machines you've effectively got two networks again, although they're split in a different way. I guess the main improvement is the single AD domain but I do wonder if that benefit alone is worth the time and effort of changing everything over...

Posted

Correct me if I'm wrong but if you have phones on your network shouldn't these be on a separate VLAN / Network than your PC's because voice will completely annihilate your PC's on the network ??

 

I think I'm right but I don't deal with the phones :) - so a good idea for another VLAN if need be.....

Posted
We're not on VOIP at the moment but as you say I'd imagine would be important to segment that away if we ever went down that route

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...