A
A
Alter-ego2015-08-10 20:36:08
Microsoft
Alter-ego, 2015-08-10 20:36:08

Domain and proxy. Are they needed???

Good day!
In general, everything works, but there is a desire to develop and improve security.
For normal user operation, you need Internet access and a working 1C server (locally).
Both are available. About 40 machines, all on win7+8.
1. I am tormented by the question - is it worth raising a domain?
For convenience of administration it is clear it is necessary.
But how to justify the gender that the thing is useful and necessary.
We need some solid arguments that are understandable to the average user.
2. What are the real benefits of a proxy server?
Internet usage control and protection from "bad" sites.
But now the corporate Kaspersky seems to cope with this.
Or am I confusing concepts? Help me to understand.
3. Tell me what proxy options
for a small company + how to justify the gender again?

Answer the question

In order to leave comments, you need to log in

8 answer(s)
S
Spetros, 2015-08-10
@Spetros

Judging by the questions, you are in the position of a computer specialist recently and have a keen desire to try everything.
If you want to continue working on it, follow the main rule: if it works, don't touch it.
1. It depends on the specifics of the activity. If the savings (money organization and working time) from the purchase of Windows Server (and related licenses) will be noticeable, then yes - you need a domain. By the way, not every edition of Windows is suitable for a domain.
2. You are a specialist there - you know better: what are the pros and cons of employees on the ground.
3. If the Internet is not abused, then the usual NAT will be enough.
And do not forget about the budget of events, it is also needed for justification.

T
TyzhSysAdmin, 2015-08-10
@POS_troi

1. Need
2. control, caching, logging
3. My IMHO - Squid
4. Raise the internal jabber :)

A
Artem @Jump, 2015-08-10
Tag

I am tormented by the question - is it worth raising a domain?
It is purely a matter of convenience, if it is convenient for you to administer 40 machines without a domain, you can not raise it.
Although personally I doubt that it is convenient.
But how to justify the gender that the thing is useful and necessary.
Improve your work efficiency, more convenient operation..
What are the real benefits of a proxy server?
It is difficult to say, in most cases it is simply not needed and useless.
Although sometimes it is necessary, so think about it - why do you need it?
Internet usage control and protection from "bad" sites are done in many ways, and proxies are just one of them, and not the best.
Tell me what proxy options
for a small company + how to justify the gender again?
To begin with, you tell me why you need a proxy, then you can tell something.

S
Sergey Kovalev, 2015-08-11
@Sergey-S-Kovalev

1. With so many PCs, yes, it's worth it.
Cost reduction, growth margin without the need to hire another person in the IT department, faster problem resolution, control of access to documents and programs, more stable PC operation and, as a result, no downtime.
2. Controlling access to the Internet, reporting to management who is doing what, restrictions on channel downloads (one with torrents cannot gobble up everything)
3. Ideco. or Squid

A
Andrew, 2015-08-11
@droner92

1. Yes, it's worth it.

But how to justify the gender that the thing is useful and necessary.
Try to refer to the speed and scalability of infrastructure expansion. Give examples, such as - 1) a new employee has appeared - the time spent to set up the workplace of a new employee will be much less. 2) We came up with new rules to restrict access to resources - they were implemented faster. Looked - who climbed where. It often happens - that someone moved something, deleted it - and then "it itself". This will be avoided.
IMHO I would start by referring to the fact that there are many enterprise products (many of which are free) that could be implemented in any organization, such as an enterprise collaboration portal (Sharepoint Foundation to the rescue). Plus, many backup systems work much better with domain controllers (in this case, it’s generally better to refer to buying a backup server, be sure to have a Raid array (although you can also use a software raid))
1) Differentiation of access to Internet resources 2) Caching 3) Limiting the speed of the Internet channel into separate groups. 4) Join Sergey Kovalev
2. Internet access control, reporting to management who is doing what, restrictions on channel downloads (one with torrents will not be able to gobble up everything)

PS If you still decide to implement it, then you should clearly be able to do it all. If you doubt your abilities, it is better to test everything on virtual machines (IMHO). Because if you start to raise and run into problems, moreover, obvious ones, you can fall in the eyes of the authorities ...

S
seekinganswers, 2015-08-12
@seekinganswers

1. I am tormented by the question - is it worth raising a domain?
If you have such a question, then it is not yet too early, 40 cars is not such a huge fleet. For easy administration, install LiteManage.
2. What are the real benefits of a proxy server?
The real plus is the ability to distribute even traffic between users, caching web pages.
3. Tell me what proxy options
Take ideco, a good commercial Internet gateway, how to justify, for example, the ability to block Internet sites en masse, for example, all gaming sites are blocked in our country. Even distribution of Internet speed between users, no matter what kind of pupkin started downloading the movie and everyone's Internet sagged.

A
Alter-ego, 2015-08-11
@Alter-ego

What are the disadvantages I see so far without a domain.
1. Shared printers are sometimes asked to enter a password. The user is at an impasse, calling me.
2. Sometimes the name is not visible by ip. There is no dns inside the network. Used provider + from Google. Maybe I’m doing something wrong (
3. Everyone has the same local accounts. It’s not safe. Setting different ones is a hemorrhoid.
4. There’s no way to cut the rights with group policies. And the lack of roaming
profiles
. " Kasper
cuts some of the "bad" sites. But his pre-installed groups often include normal ones. You have to add handles to the exceptions. I thought things are better there through a proxy.

A
Alexander Chekalin, 2015-09-24
@achekalin

What are the parameters of the channel and its loading? Analyzing Netflow as an option is also an option, it will give a picture of where and how devices go (not users, but IP addresses). In this fresh picture, you can already analyze whether something happened on the network.
Casper - he's good, but he can't do everything. Alas. Just like any other antivirus. But it can also interfere with traffic, alas, and you don’t know when it will get stuck on this topic. I would not really believe him, but this, of course, is only personal, and only their experience.
A proxy will save you, but not from everything either. Skype and other p2p scum don't really like restrictions, so you need to answer the question for yourself: what do you want, filter or just have a beautiful report. The report, I repeat, and netflow will allow you to collect, but at the same time it will be passive. If there is a desire to restrict access to resources, a firewall is indispensable, and the options are clear: either the firewall closes the Internet to users in principle, and the proxy forwards several protocols, or there is no proxy, the traffic goes straight (through nat), but the firewall blocks access to " unwanted" resources. All options have pros and cons.
There is usually no way to justify a gender, except for the cost of maintenance - but usually the admin's salary is less than the amount of the investment. Rely on manageability, on reducing the number of errors, on security, when someone quits, and his accounts must be closed everywhere.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question