- Posts: 1302
- Thank you received: 0
Help needed for network design setup and implementation
19 years 6 months ago #8401
by DaLight
Replied by DaLight on topic Re: Help needed for network design setup and implementation
Hope this helps:
Q: I will set up AD but how do I set up accounts for the individuals that need to have access to files on the server without giving everybody access to the server?
When you say individuals need to have access to files on the server, are these shared files or files unique to these individuals. If it is the former, you could simply set up Security Groups with access to specific directories or files. If the latter, you could set up "Home" directories for each user on the server.
You can of course give certain users the right to interactively logon to the server, although I would severely restrict this priviledge.
Q: Do I need to set the server up for terminal services as well?
You are allowed up to two concurrent terminal server logins to W2K3 in Remote Administration mode. You need to know that terminal services is not installed by default anymore in W2K3, and you will need to add it using Add/Remove Programs fom Control Panel.
Q: Can any of the computers be the BDC?
You need to have another Windows Server product as the BDC, or you could simply stick SAMBA on a spare machine and have a free BDC.
Q: Do I still need to set DNS up on the server or should I just use the ISP's. Which approach is better to set the router up as DHCP server or to set DHCP up on the windows 2003 Server?
Since you've got an all windows shop, best to have the W2K3 server handle both the DNS and DHCP. Then have it point to your ISP's DNS (using the DNS forwarders option) for unresolved addresses.
Q: How about NAT?
Let your router act as the gateway and provide NAT separation. I would feel more comfortable sticking an IPCOP www.ipcop.org or something similar in between the router and the rest of the network so you get better firewalling capabilities, logging, etc.
Q: I will set up AD but how do I set up accounts for the individuals that need to have access to files on the server without giving everybody access to the server?
When you say individuals need to have access to files on the server, are these shared files or files unique to these individuals. If it is the former, you could simply set up Security Groups with access to specific directories or files. If the latter, you could set up "Home" directories for each user on the server.
You can of course give certain users the right to interactively logon to the server, although I would severely restrict this priviledge.
Q: Do I need to set the server up for terminal services as well?
You are allowed up to two concurrent terminal server logins to W2K3 in Remote Administration mode. You need to know that terminal services is not installed by default anymore in W2K3, and you will need to add it using Add/Remove Programs fom Control Panel.
Q: Can any of the computers be the BDC?
You need to have another Windows Server product as the BDC, or you could simply stick SAMBA on a spare machine and have a free BDC.
Q: Do I still need to set DNS up on the server or should I just use the ISP's. Which approach is better to set the router up as DHCP server or to set DHCP up on the windows 2003 Server?
Since you've got an all windows shop, best to have the W2K3 server handle both the DNS and DHCP. Then have it point to your ISP's DNS (using the DNS forwarders option) for unresolved addresses.
Q: How about NAT?
Let your router act as the gateway and provide NAT separation. I would feel more comfortable sticking an IPCOP www.ipcop.org or something similar in between the router and the rest of the network so you get better firewalling capabilities, logging, etc.
19 years 6 months ago #8402
by lan2wan
Replied by lan2wan on topic Re: Help needed for network design setup and implementation
DaLight,
Thanks a lot.
I'll look IPCOP up.
If I have further questions, I'll post them.
Thank you
Thanks a lot.
I'll look IPCOP up.
If I have further questions, I'll post them.
Thank you
19 years 6 months ago #8406
by DaLight
Replied by DaLight on topic Re: Help needed for network design setup and implementation
no problem
19 years 6 months ago #8536
by lan2wan
Replied by lan2wan on topic Re: Help needed for network design setup and implementation
Can someone please take a look at this network config and tell me if it will work or not .If it will not work please make suggestions.
Thank you.
I am still preparing for the WLAN setup
Now we have 2 Laptops on the Network( 1 for the Administrator and 1 for the Lab Instructor)
13 Desktop Computers with Win XP SP2
1 HPLaser Printer
1 Server (Dell PowerEdge 2600 with Win 2003 Standard Edition)
1 Linksys 2.4GHz Wireless-G Broadband Router with SRX
Braodband Cable Internet Access with Dynamic IP address.
Some of the users on the network will need to have access to some programs on the server eg an ESL course and others will just have access to the internet and do homework and possibly play games.
Below is my proposed network config:
The internal network address will be----192.168.2.0/24
Subnet Mask 255.255.255.0
Set out below is the IP address assignment.
Static IP addresses
Server: 192.168.2.1
Printer: 192.168.2.3
Access Point: 192.168.2.2
DHCP Server Configuration (Dynamic Host Configuration Protocol)
Start Address : 192.168.2.50
End Address: 192.168.2.239
IP address exclusions- Printer, Server and 2 Laptops (192.168.2.1- 192.168.2.5)
Subnet Mask: 255.255.255.0
DHCP Lease Limited to 7 days
Default Gateway: AP Or Server ? which one is best to use
I also need to proceed and I am wondering which ones to configure first.
Should I configure the server or the AP first?
How should I create the user accounts for this the users who need access to the programs on the server as well as the instructor and administrator.
I am asking all these question so that I do not mess the network up. It is my first time doing this alone.
Thank you all.
Thank you.
I am still preparing for the WLAN setup
Now we have 2 Laptops on the Network( 1 for the Administrator and 1 for the Lab Instructor)
13 Desktop Computers with Win XP SP2
1 HPLaser Printer
1 Server (Dell PowerEdge 2600 with Win 2003 Standard Edition)
1 Linksys 2.4GHz Wireless-G Broadband Router with SRX
Braodband Cable Internet Access with Dynamic IP address.
Some of the users on the network will need to have access to some programs on the server eg an ESL course and others will just have access to the internet and do homework and possibly play games.
Below is my proposed network config:
The internal network address will be----192.168.2.0/24
Subnet Mask 255.255.255.0
Set out below is the IP address assignment.
Static IP addresses
Server: 192.168.2.1
Printer: 192.168.2.3
Access Point: 192.168.2.2
DHCP Server Configuration (Dynamic Host Configuration Protocol)
Start Address : 192.168.2.50
End Address: 192.168.2.239
IP address exclusions- Printer, Server and 2 Laptops (192.168.2.1- 192.168.2.5)
Subnet Mask: 255.255.255.0
DHCP Lease Limited to 7 days
Default Gateway: AP Or Server ? which one is best to use
I also need to proceed and I am wondering which ones to configure first.
Should I configure the server or the AP first?
How should I create the user accounts for this the users who need access to the programs on the server as well as the instructor and administrator.
I am asking all these question so that I do not mess the network up. It is my first time doing this alone.
Thank you all.
19 years 6 months ago #8538
by DaLight
Replied by DaLight on topic Re: Help needed for network design setup and implementation
The IP address assigment scheme seems OK.
Default Gateway: Use the AP otherwise you would need two network cards in your server. I don't like multi-homed domain controllers.
Configure your AP first. Assign it with its internal IP and allow ot to pick it external IP by DHCP. You could also use the built-in dyndns.org functionality to track changes in your public IP.
Q: How should I create the user accounts for this the users who need access to the programs on the server as well as the instructor and administrator.
It would be best to create a security group for the normal users, say "students". You could then give this group restricted access to parts of the server. When you say you want to give users access to some programs on the server, do you mean access to the shared program data, as I assume the programs will be installed on the client PCs, or are they web-based programs - please clarify.
Hope this helps
Default Gateway: Use the AP otherwise you would need two network cards in your server. I don't like multi-homed domain controllers.
Configure your AP first. Assign it with its internal IP and allow ot to pick it external IP by DHCP. You could also use the built-in dyndns.org functionality to track changes in your public IP.
Q: How should I create the user accounts for this the users who need access to the programs on the server as well as the instructor and administrator.
It would be best to create a security group for the normal users, say "students". You could then give this group restricted access to parts of the server. When you say you want to give users access to some programs on the server, do you mean access to the shared program data, as I assume the programs will be installed on the client PCs, or are they web-based programs - please clarify.
Hope this helps
19 years 6 months ago #8547
by lan2wan
Replied by lan2wan on topic Re: Help needed for network design setup and implementation
DaLight,
Yes I mean access to shared program data. This set of users will change as they complete their courses.
Thank you
Lan2Wan
Yes I mean access to shared program data. This set of users will change as they complete their courses.
Thank you
Lan2Wan
Time to create page: 0.173 seconds