Jump to content


Tolik

IBCM with Web Application Proxy

Recommended Posts

Trying to get Internet Based Client Management working for domain clients that may leave intranet network. Not so much concerned about workgroup clients
Current setup is single MP on domain with a Web Application Proxy server setup in DMZ (port 443 opened on firewall). SCCM 2012 SP1 R2 CU1

 

The SCCM client is installed while the system is on the domain and is properly registered with SCCM (installed vie client push). The system knows when it leaves the intranet and switches (as seen in Configuring Manger). The internet client whoever cannot communicate with the MP. All communication (internal and external) is setup to use PKI. All certificates are loaded on client system and MP.

 

How can we get this setup to work properly? We would like to avoid installing a site system in the DMZ.

 

Thank you.

Share this post


Link to post
Share on other sites

I was afraid of that. Thank you for the clarification.

 

In our scenario then how would we proceed to setup IBMC to manage "roaming" systems? Right now our current server in DMZ is a standalone server. I understand we would need to install a site system role (DP) to the server in DMZ. The part that’s confusing is that the server in DMZ would need to be part of "a" domain. Our security team would like to avoid domain joined servers in DMZ. How can the certificate then be passed along?

 

What would be simplest and secure way to establish a trust between the server in DMZ and our internal MP? Thank you.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.