Hi,
We d like to manage (=OS Deploy, Packages,Windows updates) Windows clients (Windows 2008/2012 R2 servers for now, about 20 of them) in a DMZ (= different domain).
There is this article https://nikifoster.wordpress.com/2011/01/31/installing-configmgr-clients-on-servers-in-a-dmz/ which explains what to do in 2011. Since then lots of things are changed I guess
Before I dive in, Id need to have an overview + do some administrative tasks (like asking for firewall accesses).
Current setup DMZ:
- Our SCCM 2012 R2 server is on a Windows 2008 R2 OS
- Client communication is done via HTTP (not HTTPS)
- An extra physical Distribution point is setup (only DP, nothing more) in our current domain
- A new Windows 2012 server is setup in the DMZ which should host the DP and probably management point (since it should manage the clients over there)
- There are clients in DMZ that are currenlty managed by SCCM 2007 but
this server will be phased out, these client have:
- Correct sccm functionality
- Correct DNS resolution
My steps/questions, please comment:
- Add the DMZ ip range to SCCM 2012 boundary as DMZ
- Add the network access account to be able to deploy as well clients as distribution point in DMZ
- In the DMZ accesses on firewall for server VLAN have to be asked
When we have a distribution point and communication is HTTP only then http (port 80) from DMZ to sccm server should suffice, correct? Or are extra firewall openings needed for management point access/packages and windows updates sync? - Now the sccm clients will be deployed to the servers in DMZ: deploy SCCM clients to hosts in DMZ, how this should be done: we connect a console to the SCCM-server in the DMZ then deploy the discovered clients?
- OS Deploy should be made available, but no dhcp is available in DMZ and it is not an option either, therefore we would boot from an ISO then enter an ip (or pre-enter it so there is already filled in an ip?). So tasksequences/deployments for servers in DMZ, where are they configured/deployed then? Via console access on DMZ management point or can we deploy on our domain SCCM management point (not in DMZ) and it will be synced to the DMZ management point? Not clear
- Selective sync of software to this distribution point (howto? not sure), we dont need any Windows 8 software/drivers to be synced.
Thanks for your input!