Jump to content

Recommended Posts

Posted
There is a technical reason (or was) to have two Microsoft networks - password policy.

 

I can't remember when it changed but at some point it was only possible to have one password policy per domain.

2008 now allows seperate PP per OU
Posted

Dorset LA still advise two networks and only recently have both my schools gone down the 'trust' route in order to get SIMS on the workstations for the teachers. Many Dorset schools have just merged their networks but there is another consideration, smaller schools often have part-time techs and if admin machines fail they tend to be a bit more mission critical than a teachers machine. If the tech isnt there to fix the machine, problems can ensue!

Also, speaking as a curriculum network person, the separation of networks keeps me away from, and not responsible for, SIMS, for which I am duly very thankful :)

Posted
if admin machines fail they tend to be a bit more mission critical than a teachers machine.

 

That's a different approach than we use, our SLA always prioritises T+L over administrative tasks as teaching and learning is our core business. Is this admin>T+L concept normal or particular to Dorset?

Posted

So...sims goes down and there is a fire, your registers are electronic or are paper but not printed off for the week/kept in a place inaccessible during a fire on that instance...how do you fix this?

 

Admin is just as vital as teaching and learning, anybody that thinks otherwise is just fooling themselves.

Posted (edited)
So...sims goes down and there is a fire, your registers are electronic or are paper but not printed off for the week/kept in a place inaccessible during a fire on that instance...how do you fix this?

 

 

The SIMS server is listed as a mission critical system on our SLA, here we're talking about an admin machine vs a machine used for T+L

 

Admin is just as vital as teaching and learning, anybody that thinks otherwise is just fooling themselves.

 

I disagree. Administrative tasks are just that. The primary objective of the school is teaching and learning, admin supports that and is important for that reason, but it isn't critical; if I have the choice between getting a machine fixed used to deliver a lesson, or one used by a secretary then I'd move the secretary to a different machine and fix the T+L machine. This is also a good reason why NM's should be managed senior by T+L staff, not by business manager/bursars.

Edited by CyberNerd
Posted
I was managed by deputy heads who were curriculum leaders and they had it the other way.. shift teachers to diff machines and fix admin ASAP. Suppose its different in different schools.

 

sounds like it, not just a Dorset thing then, lol. In the end I guess it comes down to the SLA and the amount that ICT is embedded into T+L at the particular school.

Posted

::can't resist::

 

There is a technical reason (or was) to have two Microsoft networks - password policy.

 

That problem was solved a long time ago: You either made the code (wasn't difficult) or bought a password change notification DLL to worry about password policy for different user groups. Add-ons to improve security are acceptable in so many other ways e.g. AV, so it's curious that there has apparently been resistance/indifference to improving this notoriously vulnerable area.

 

the dreadful security in NT4

 

Way I remember it "dreadful security" was the milieu, not a notably unique attribute of NT. Like most of the alternatives NT4 was OK if you knew what you were doing and that was part of my job on the private side of fence, where I heard quite a bit of poorly understood received opinion (typically picked up from the MS vs. Netware vs. commercial Unix PR battle raging in the tech press) from county public sector folk whose existing network security was a naively box-ticked joke they simply couldn't or wouldn't see.

 

More techs obviously know more about security now and MS have obviously made it easier for those who don't to survive (system integrity protection, UAC, more secure out-of-box etc.). But a lot of networks still have notable flaws, so I think some of the change in attitude is about risk perception i.e. networks were scarier in their infancy, but by and large folk running networks behind LA/RBC firewalls have gotten away with the flaws, nothing bad has happened or at least if it did, they didn't notice.

 

--

 

Separate obviously can be better, but I don't think there is a rule. In practice, subject to techs and users, 'separate' networks can be roughly as secure or insecure as combined ones. Perhaps the more useful question is:

 

"If I combine the networks, what are some pragmatic approaches to achieving enhanced security for especially sensitive network resources?"

  • 3 weeks later...
Posted

Sorry to jump on this thread, but I have a security question related to this...

 

We have 2 VLans currently, as described, which has worked well with regards to security of the MIS etc. However, this is about to change and I am wondering whether anyone knows how I can protect our Bromcom MIS (Web based) from would be student hackers? I know I can enforce password policies, but I was hoping not to even give them the chance to see the log in page...

 

Any thoughts anyone - your help is appreciated!

Posted

if it is internal, then you can set a policy on ISA Server (if you use it) or your filtering of choice (smoothwall/bloxx/websense/whatever) whereby the students try to access the page and it redirects to a page like google or something.

 

You can also set up on your hosting (if its a good one) to have a white list of IP addresses that can access the page from outside of the school, and everything else gets redirected.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...