Jump to content


thanke

SCCM 2007 and DMZ-Server

Recommended Posts

Hello togehter,

i need some help about the topic i have started.

We use SCCM 2007 for the internal patchmanagement and all works fine.

 

Now we need to patch our servers which are located in the DMZ but i didnt know what i nned to do this.

 

We didnt want to open any ports on the firewall only which are minimized needed! What is the best solution for our needs?

 

The servers in the DMZ are in the moment not in the local domain but this should not be an problem, what information i need is what we need in teh DMZ. An primary site and secondary site etc. whihc ports have to be opened?

 

I have reading many articles in the internet but not really sure what to do.

 

Thanks a lot for help

 

Regards

 

Thorsten

Share this post


Link to post
Share on other sites

Hi Thorsten,

 

this probably doesn't help but: that is up to you. Using the diagram on the link you can get the firewall ports open from all DMZ Clients to your Software Update Point, etc. Or, if you want to cut down on the amount of clients you have talking through your firewall, then you can put in a Secondary Site and then have ports open between the Secondary Site server and your Primary Site, then have the Secondary Site configured as a Downstream WSUS server and have the Software Update Point role installed. I would still suggest that you open the firewall between the Primary Site and all clients (outlined in Section 17 on the link) because clients will by-pass the Secondary Site and want to talk to the Management Point directly when you try to run deployment jobs.

 

If you only want to use the WSUS capabilities of SCCM, then ports open outlined in section 3 & 6.

 

Hope that helps!

 

Martin

 

*** EDIT *** Apologies, you wouldn't need to have it as a downstream server, just a DP would do the you would advertise Software Update Deployment Packages and add the DMZ DP to the list of Distribution Points on the Deployment Package.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.