Jump to content

Recommended Posts

Posted

Hello,

 

Out of interest, how do people have their admin networks set up?

 

Currently, our admin system runs on an old version of NetWare and our curric system is on Windows 2003. However, we are moving the admin network over to Windows (for a number of reasons) in the next few weeks.

 

I was wondering if other people have put the admin servers onto a seperate domain from the curric system, or whether all servers are members of the same domain, but with really tight security in place?

 

Mark.

Posted

here 2 networks two domains linked via a router allowing sims info to pass between.

no we didnt set that up, it was the council way, they didn't want it merged for security reasons

Posted

two sites connected via fibre,

 

one Domain. two file servers, two DC's, two internal webservers, one SIMS server, one exchange server.

Posted
Admin server but only one LAN/Domain which everyone logs in, admin staff simply have membership of the admin group to control access to the admin office server shares.
Posted

One Domain, 2 Files Servers, One Exchange Server, One SIMS, Server, One Applications Server, One Web Server, Another Database Server, Two Backup Servers, 3 DC's

 

The rule nowdays is One Domain and a Server for Every Application

 

File

Database

Backup

Exchange

 

ETC

Posted

1 domain, Sims dedicated server. Admin staff in a seperate OU.

 

Pretty simple really, there is no need to have seperate networks these days in a 2003 environment.

Posted
Pretty simple really, there is no need to have seperate networks these days in a 2003 environment.

 

Disagree with that there is always a need for added security. My networks are ultra secure but I still like the comfort of having seperate networks and I will never change on that.

 

We have 2 networks here and a stack of servers.

Posted
Pretty simple really, there is no need to have seperate networks these days in a 2003 environment.

 

Disagree with that there is always a need for added security. My networks are ultra secure but I still like the comfort of having seperate networks and I will never change on that.

 

We have 2 networks here and a stack of servers.

 

He said there was no real need. Liking it that way is not a need, it is a preference. Windows Server 2003 is designed around complex and secure networks, and as such, complete segregation of networks should be a thing of the past. However, that doesn't mean you are wrong doing it your way. There is more than 1 way to skin a cat.

 

(PS. No cats were injured during the writing of this message)

Posted
Pretty simple really, there is no need to have seperate networks these days in a 2003 environment.

 

Disagree with that there is always a need for added security. My networks are ultra secure but I still like the comfort of having seperate networks and I will never change on that.

 

We have 2 networks here and a stack of servers.

 

Yeh that's kind of my point, a properly configured Windows 2003 domain structure should be just as secure as 2 seperate networks, that's the whole point of active directory.

 

You could also argue that having an integrated network is more secure as you only have to worry about 1 set of security policies :)

Posted

2 Lans, Well V-Lans 1 Curric, 1 Admin

 

Setup & maintained by LEA - well the Curric Domain isn't but the VLAN is - Pain in the a**e as have to go thru all the red tape (or should the be Pink as were are "IN Salford") to get a port switched

 

Think they chose the VLAN ports at random as ther is no logic to what Port belongs to what VLANs

Posted
Pretty simple really, there is no need to have seperate networks these days in a 2003 environment.

 

 

He said there was no real need.

 

 

He said no need which is a statement of fact you said no real need which isnt' a statement of fact. I ma saying that to say there is no need (Fact) is incorrect.

 

Active Directory directory service provides the means to manage the identities and relationships that make up network environments. Saying that Windows 2003 domain structure should be just as secure as 2 seperate networks, that's the whole point of active directory is also incorrect. Two physically seperate networks is always going to be more secure. :p

 

I am sure the Linux users here would testify that you don't need Active Directory or Windows 2003 to have a secure network.

Posted

Active Directory directory service provides the means to manage the identities and relationships that make up network environments. Saying that Windows 2003 domain structure should be just as secure as 2 seperate networks, that's the whole point of active directory is also incorrect. Two physically seperate networks is always going to be more secure. :p

 

I am sure the Linux users here would testify that you don't need Active Directory or Windows 2003 to have a secure network.

 

Nope, that is simply not true. As someone else pointed out before - if you have 2 networks, you have to worry about maintaining 2 separate security policies, 2 sets of servers with updates, 2 sets of users etc...

 

Also, Active Directory was designed to allow a secure way of operating a Windows based network. It improved on the old 'trust' based system of NT server and it also increased overall security via GPO's and integration with Windows XP. Those combined make as much of a secure system as having 2 separate networks.

 

Under a combined system, this can be managed in one simple way - a single security policy under a single domain.

 

There is simply no need, in a school, to go further than one domain. There is no legal requirement, no technical reason and it shouldn't be justifiable when it comes to budgets either - it just makes things difficult for staff who get confused with different usernames all the time.

Posted

One parent domain, to child ones, and 16 (ish) grandchild domains on each of the child domains.

 

In the CLC were I have been working they provide content filtering, internet etc. We have 2 sites. The child domains are one for each site and the grandchild ones are for one domain for each school. Every school has there own servers on there site. We are linked upto each school via fibre. We have 4 full 7 ft racks in each building full of servers for various things.

 

100mb internet connection, we only have one domain per site.

Posted
You would be hard pressed to find any company running 2 such disparate networks these days, how inefficient would that be!? I'm sure if it's good enough for them it's good enough for us. As long as you know what you're doing you should be fine (although by no means be complacent).
Posted
by no means be complacent

 

The MS line on this kind of scenario was to give [sensitive group] their own member server(s) for their top-secret data & apps and require IPSec on those servers.

Posted
Pretty simple really, there is no need to have seperate networks these days in a 2003 environment.

 

Disagree with that there is always a need for added security. My networks are ultra secure but I still like the comfort of having seperate networks and I will never change on that.

 

We have 2 networks here and a stack of servers.

 

How do you run Exchange and SIMS over the 2 Domains ?

 

Do staff have 2 seperat logons for each Domain.. and can Admin Staff logon to the Curricilum Domain ?

Posted

Just in case people are keeping 2 seperate domains for historical reasons, it really is easy to merge them.

 

All you need to do is demote the Admin DC, then join it to the domain, and create the users again. It really is that simple, it took us about 2hrs to complete the procedure.

Posted
here 2 networks two domains linked via a router allowing sims info to pass between.

no we didnt set that up, it was the council way, they didn't want it merged for security reasons

 

What security reasons have they told you? I have basically been told that there is a "direct" link from the School to the council and the reason they split the two up is because of security with students possibly compromising it (primary by the way).

I am still yet to understand the real reason. We have two networks (1 wire and they become 1) and two sets of usernames and passwords.

We have a company called INDEXTeam who "manage" the admin network and i look after curriculum. I am more then capable of looking after both and cant imagine how much money could actually be saved by me doing that.

 

Pretty simple really, there is no need to have seperate networks these days in a 2003 environment.

 

Disagree with that there is always a need for added security. My networks are ultra secure but I still like the comfort of having seperate networks and I will never change on that.

 

We have 2 networks here and a stack of servers.

What is the need? Enlighten me? A secure network should be just as secure no matter what data etc you have or what services are run.

 

2 Lans, Well V-Lans 1 Curric, 1 Admin

 

Setup & maintained by LEA - well the Curric Domain isn't but the VLAN is - Pain in the a**e as have to go thru all the red tape (or should the be Pink as were are "IN Salford") to get a port switched

 

Think they chose the VLAN ports at random as ther is no logic to what Port belongs to what VLANs

Yeah our admin domain is maintained by Index via the LEA (http://www.indexteam.co.uk or com).

 

Thanks

Matt

Posted

This is an argument that comes up from time to time and will probably run and run.

 

There are numerous reasons for having multiple domains and even multiple forests. These may be based on security policies or risk assessments and unless anyone has been through this process, I think that all discussions are somewhat moot. Microsofts guidelines are that you start with a single domain and break it down if necessary. If you need different password or other domain level settings then you need multiple domains. If you need total service or data isolation then seperate forests are the way to go.

 

For what it's worth, our sites run on a single LAN with no routing or isolation at the network layer. We operate single forests with an Admin forest root domain and an additional tree with the Curriculum domain. This lets us run a single Exchange organization (single forest); maintain seperate password policies and user accounts (dual domains). We value the isolation that the additional domain gives to our Admin systems especially when so many contractors (unlikely to be CRB checked) who may be installing software on our curriculum networks are simply handed the Administrator password when they ask for it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...