Close

Results 1 to 19 of 19
  1. #1
    DF VIP Member muttleymacclad's Avatar
    Join Date
    Aug 2006
    Location
    Here
    Posts
    5,717
    Thanks
    931
    Thanked:        659
    Karma Level
    646

    Default How to secure/run a school or college network?

    Hi guys,
    I'm looking at taking on some extra work in a local secondary school with about 1000 pupils, as an assistant network mgr (or IT dogs body by the looks of the job spec!!).

    Can any of you who do this role let me know how the average school network is set up and how its managed? Obviously every school will be slightly different but any general info would be great ta. I'd like to be on the ball if I get asked for an interview.

    Thanks in advance
    Mml



    Sent from my D5503 using Tapatalk
    Last edited by muttleymacclad; 28th June 2015 at 11:20 PM.

  2. #2
    DF VIP Member blacksheep's Avatar
    Join Date
    Jun 2006
    Location
    Manchester
    Posts
    3,877
    Thanks
    87
    Thanked:        265
    Karma Level
    546

    Default Re: How to secure run a school / college network?

    Depends on what they want to spend - it's usually software based restricting websites. The companies that target schools are usually a rip off. Have a google around for corporate security software, website restriction etc.

    obviously you want each computer locked down so the user can't install/run alternate code, obvious ways round this and plenty smart Alec kids will know how to do this and get the master password - as for master password make it long, at least 12 chars with numbers, symbols letters etc and the one that fucks most up is chars with accents such as é.

    Are there different subnets for years or subjects (or both) - storage as well, segregation of student work etc.

    tbh they probably won't know what they want so if you go in with a professional sounding plan at the right price you'll be ahead of most of the game.

    Thanks to blacksheep

    muttleymacclad (29th June 2015)  


  3. #3
    DF VIP Member consoles's Avatar
    Join Date
    Jan 2007
    Location
    Way out there
    Posts
    2,710
    Thanks
    365
    Thanked:        874
    Karma Level
    395

    Default Re: How to secure run a school / college network?

    We use Smoothwall for our proxy/web filtering
    Student accounts are locked down using windows policies which are vigorously tested before rolling out, as for a subnet for each year ? not sure why you need that when you can simply map profiles and home drives.
    IT technicians job in a school is proper dogs body work tbh

    2 Thanks given to consoles

    JonEp (3rd July 2015),  muttleymacclad (29th June 2015)  


  4. #4
    DF VIP Member muttleymacclad's Avatar
    Join Date
    Aug 2006
    Location
    Here
    Posts
    5,717
    Thanks
    931
    Thanked:        659
    Karma Level
    646

    Default Re: How to secure/run a school or college network?

    Thanks guys. I get the impression it's a dogs body work, but will give me a chance for a bit more structure in my life, I'll be able to do my private IT work for a few good regulars and its a 5 minute walk from my house.

    Sent from my D5503 using Tapatalk
    "When a naked man is chasing a woman through an alley with a butchers knife and a hard-on, I figure he isn't out collecting for the Red Cross." - 'Dirty' Harry

  5. #5
    DF VIP Member muttleymacclad's Avatar
    Join Date
    Aug 2006
    Location
    Here
    Posts
    5,717
    Thanks
    931
    Thanked:        659
    Karma Level
    646

    Default Re: How to secure run a school / college network?

    So i'm being interviewed next week, haven't had an interview for years! Have to dig my suit out now and get a hair cut.
    Last edited by muttleymacclad; 1st July 2015 at 09:10 AM.
    "When a naked man is chasing a woman through an alley with a butchers knife and a hard-on, I figure he isn't out collecting for the Red Cross." - 'Dirty' Harry

  6. #6
    DF VIP Member cyprus's Avatar
    Join Date
    Feb 2005
    Location
    Destination
    Posts
    4,460
    Thanks
    864
    Thanked:        1,121
    Karma Level
    808

    Default Re: How to secure run a school / college network?

    Start here:

    http://www.rm.com/shops/ranger/Default.aspx

    Designed specifically for education, Ranger Software provides everything you need to manage your ICT network and equipment, improve the effectiveness IT in the classroom and protect pupils from the increasing threats of cyber bullying and grooming. With Ranger software you can:

    • Simplify network management and administration
    • Improve ICT network continuity
    • Improve network security and control
    • Streamline ICT budget - and allocation-planning
    • Simplify and enhance ICT in the classroom
    • Improve energy efficiency and sustainability
    • Protect students from cyber-bullies, paedophi1es and inappropriate behaviour




    With a simplified Ranger-enabled network, staff are freed-up to focus on what they do best - be that teaching, managing or developing the ICT network.


    Thanks to cyprus

    muttleymacclad (1st July 2015)  


  7. #7
    DF VIP Member akimba's Avatar
    Join Date
    Jun 2006
    Location
    UK
    Posts
    2,846
    Thanks
    1,034
    Thanked:        783
    Karma Level
    369

    Default Re: How to secure run a school / college network?

    Have a plan for some sort of PC refresh policy maybe like all computers get wiped and reinstalled overnight/on shutdown (seems common practise in schools these days)
    Support for tablet devices, Apple seems to be pumping iPads into schools heavily over the past few years bit like Bill did with windows ;-)
    Do some research into interactive whiteboards seem all the rage but really just a PC with a Bluetooth pen attached

  8. #8
    DF VIP Member consoles's Avatar
    Join Date
    Jan 2007
    Location
    Way out there
    Posts
    2,710
    Thanks
    365
    Thanked:        874
    Karma Level
    395

    Default Re: How to secure run a school / college network?

    Ranger networks are ok, but as they are a front end to your AD etc used for too long you forget the simplest things within AD we used it for 3 years and took ages for me to get my head back around AD having used ranger for so long.

  9. #9
    DF VIP Member MajorFU's Avatar
    Join Date
    Dec 2000
    Location
    London
    Posts
    3,206
    Thanks
    106
    Thanked:        135
    Karma Level
    442

    Default Re: How to secure run a school / college network?

    I'd say use VLAN's and as many as you want. Broadcast domains could be allocated by class / year / dept or a mixture of them all. As most VLAN's will have similar restrictions config templates can be used for minor changes that affect multiple VLANs

    You can secure resources quite easily by either restricting certain VLAN's on certain Trunk Links as well as using Firewalls between VLANs that need to communicate

  10. #10
    DF VIP Member Over Carl's Avatar
    Join Date
    Apr 2006
    Location
    London
    Posts
    13,125
    Thanks
    3,975
    Thanked:        1,690
    Karma Level
    1252

    Default Re: How to secure run a school / college network?

    Sorry if it's a bit of a hijack but the VLAN per year thing interests me as I am baffled how this would be implemented. From what I remember, schools would typically have IT rooms and computers in places like the library that were either shared between all years or reserved for a certain group. Would this mean the VLAN changes during login or something?

  11. #11
    DF VIP Member MajorFU's Avatar
    Join Date
    Dec 2000
    Location
    London
    Posts
    3,206
    Thanks
    106
    Thanked:        135
    Karma Level
    442

    Default Re: How to secure run a school / college network?

    VLANS are logical layer 2 separation of networks, eg you can have 3 x 48 port switches in a stack which looks like 1 x 150(ish) port switch but you can have say 5 vlans with 30 ports in each vlan and you can either filter and route between vlans in this switch if it has layer 3 funtionality or you can run a layered collapsed core design with the virtual default gateways (SVI's) configured on a router or layer 3 switch in a "router on a stick" type design. from there you can apply access lists or even route to a firewall.

    The thing is nobody in 1 vlan can get to any other of the vlans unless you have allowed it with either a static route or access list/firewall

    Most switches will also support the use of 1 x data vlan and 1 x voice vlan per access port and even if all ports have the same voice vlan they can all be in different data vlans

    hope this clarifies

    Thanks to MajorFU

    JonEp (3rd July 2015)  


  12. #12
    DF VIP Member Over Carl's Avatar
    Join Date
    Apr 2006
    Location
    London
    Posts
    13,125
    Thanks
    3,975
    Thanked:        1,690
    Karma Level
    1252

    Default Re: How to secure run a school / college network?

    I've setup and configured VLAN's before, but those tended to be more static, say maybe servers on one VLAN, desktops one 1st floor on another, desktops on 2nd floor on another, phones on their own VLAN, etc.

    The thing that baffles me is how the computers would change VLAN when a student from a different year logs in.

  13. #13
    DF VIP Member MajorFU's Avatar
    Join Date
    Dec 2000
    Location
    London
    Posts
    3,206
    Thanks
    106
    Thanked:        135
    Karma Level
    442

    Default Re: How to secure run a school / college network?

    They don't mate, you just either connect the computer to the new port in the new VLAN and its gets a new IP in that VLAN or if there is no physical move then you just change the data VLAN on their port to the new one and then there will get new IP details

    That's the benefit of VLANs, its a logical separation rather than physical

    Thanks to MajorFU

    Over Carl (6th July 2015)  


  14. #14
    DF VIP Member muttleymacclad's Avatar
    Join Date
    Aug 2006
    Location
    Here
    Posts
    5,717
    Thanks
    931
    Thanked:        659
    Karma Level
    646

    Default Re: How to secure run a school / college network?

    Well I had the interview this morning and did ok in I think but struggled a bit with the networking practical assesment.

    MAjorFU was pretty much correct, It was all run on server virtualizations, which i told them i was new to. Broadcast Domains were allocated by dep't etc.

    Will hopefully find out in the next 24 hours.

    Thanks for everyone's help.

    mml
    "When a naked man is chasing a woman through an alley with a butchers knife and a hard-on, I figure he isn't out collecting for the Red Cross." - 'Dirty' Harry

    2 Thanks given to muttleymacclad

    akimba (9th July 2015),  ant3b (9th July 2015)  


  15. #15
    DF VIP Member MajorFU's Avatar
    Join Date
    Dec 2000
    Location
    London
    Posts
    3,206
    Thanks
    106
    Thanked:        135
    Karma Level
    442

    Default Re: How to secure run a school / college network?

    Good luck mate, network engineering rocks. I rarely speak to idiot users, mostly other network guys or server guys.

  16. #16
    DF VIP Member consoles's Avatar
    Join Date
    Jan 2007
    Location
    Way out there
    Posts
    2,710
    Thanks
    365
    Thanked:        874
    Karma Level
    395

    Default Re: How to secure run a school / college network?

    we have various vlans, but the main ones are Curriculum "all pupils/staff" Admin for our connection into LCC payroll etc WLAN with 3 levels of access filtering cisco phones internal cctv
    each year group is in its own security group which dictates what resources that year group can access which also applys to our smoothwall depending who logs on as to what filtering is applied for net access.

  17. #17
    DF VIP Member muttleymacclad's Avatar
    Join Date
    Aug 2006
    Location
    Here
    Posts
    5,717
    Thanks
    931
    Thanked:        659
    Karma Level
    646

    Default Re: How to secure run a school / college network?

    So no decision has been made yet. Although i call BS.
    I reckon they've offered it to someone before the weekend and the person they've offered to is stalling. Apparently i will know one way or another tomorrow.
    "When a naked man is chasing a woman through an alley with a butchers knife and a hard-on, I figure he isn't out collecting for the Red Cross." - 'Dirty' Harry

  18. #18
    DF VIP Member blacksheep's Avatar
    Join Date
    Jun 2006
    Location
    Manchester
    Posts
    3,877
    Thanks
    87
    Thanked:        265
    Karma Level
    546

    Default Re: How to secure run a school / college network?

    You only had the one interview mate? Almost everywhere I know will be looking at 2-3, some of those might be phone ones.

  19. #19
    DF VIP Member muttleymacclad's Avatar
    Join Date
    Aug 2006
    Location
    Here
    Posts
    5,717
    Thanks
    931
    Thanked:        659
    Karma Level
    646

    Default Re: How to secure/run a school or college network?

    It was a low paid school job, they still haven't appointed yet, keep emailing me saying 'tomorrow'.

    Sent from my D5503 using Tapatalk
    "When a naked man is chasing a woman through an alley with a butchers knife and a hard-on, I figure he isn't out collecting for the Red Cross." - 'Dirty' Harry

Similar Threads

  1. cable in UNI / college
    By {film_man} in forum Internet Connections & VPNs
    Replies: 21
    Last Post: 23rd November 2002, 10:50 PM
  2. ntl broadband, usb or network
    By DAVEY26 in forum Internet Connections & VPNs
    Replies: 17
    Last Post: 3rd October 2002, 11:18 PM
  3. Network Internet Sharing Help
    By Dark Angel in forum Internet Connections & VPNs
    Replies: 7
    Last Post: 4th September 2002, 01:20 PM
  4. School - happiest days of your life!!!1
    By guvnor in forum Funny Pictures
    Replies: 10
    Last Post: 30th August 2002, 09:52 PM

Social Networking Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •