Presentation is loading. Please wait.

Presentation is loading. Please wait.

Internet Based Client Management In System Center 2012 Configuration Manager R2 Justin Chalfant blogs.technet.com/jchalfa nt Jason

Similar presentations


Presentation on theme: "Internet Based Client Management In System Center 2012 Configuration Manager R2 Justin Chalfant blogs.technet.com/jchalfa nt Jason"— Presentation transcript:

1

2 Internet Based Client Management In System Center 2012 Configuration Manager R2 Justin Chalfant blogs.technet.com/jchalfa nt Jason blog.configmgrftw.com

3 Overview In-scope IBCM Hierarchy Scenarios Reverse Proxy (TMG) SSL Bridging Out-of-scope HTTPS Client Communication Basics Public Key Infrastructure (PKI) Configuration Implementation Basics or Details

4 Steps To Implement IBCM Setup PKI Deploy site system and client certificates Setup/configure site systems and client facing roles Configure site Test, Test, Test

5 What’s Needed Server authentication certificates for each site system*

6 Lab Environment – Traffic Flow BOBOI BOBOI = Big Old, Bad Old Internet Site System (MP, DP, SUP, App Catalog) Site Server Reverse Proxy (TMG) Edge Router Internet Client

7 Certificate Templates WSUS Configuration Verify IIS Certificate on Internet Facing Site System Exporting the Certificate for Workgroup Client Requesting the Certificate Template for Workgroup Client Issuing the Certificate Templates Creating Certificate Templates DEMO

8 IBCM Site Architecture – No DMZ FSP MP / DP / SUP Site ServerReverse Proxy Bridged Passthrough

9 IBCM Site Architecture – DMZ FSP MP / DP / SUP Site Server Reverse Proxy Site Server initiated communication SQL Replica Bridged Passthrough

10 TMG Create TMG Web Publishing Rules Create Website Publishing Rules for DP and SUP Review TMG Configurations Review the Web Listener Review Website Publishing Rules MP, Application Catalog DEMO

11 Site Systems and AD Forests/Domains Site System Site Server Site DB Site Server’s AD Computer Account or Specified Installation Account 2.MP Connection Account 3.Site System’s AD Computer Account or Specified Installation Account 3 Internal Forest DMZ Forest

12 IBCM Three Client Modes Intranet only Intranet or Internet Internet only BOBOI ccmsetup.exe CCMALWAYSINF=1 CCMHOSTNAME=SERVER3.CONTOSO.COM SMSSITECODE=ABC AD GC CCMHOSTNAME set via policy starting in R2

13 IBCM Three Role Modes Intranet only - HTTPS Intranet or Internet BOBOI Internet only

14 Clients Workgroup Client Review Importing the Client Authentication Certificate Review Installation of the Client Domain Joined Client Review Client Switching from Intranet to Internet Review Software Update Installation on Internet Client Review Application Catalog from Intranet Client DEMO

15 The Missing Link LDAP, HTTP, SMB, FTP Certificate Revocation Lists (CRL) are hard-coded in each certificate at certificate creation time CRLs are available on CRL Distribution Points (CDP) CRL checking is optional

16 IBCM Communication and Content Sources WSUS Cloud DP Other Content** Software Updates* Internet Client Update Catalog * Content only MP Policy DP ** Does not include any updates All Other Content

17 IBCM vs. VPN vs. Direct Access Highlights IBCM ConfigMgr only PKI Required VPN User Initiated The networking team Direct Access Always on IPv6 May require PKI

18 Hints, Allegations & Things Left Unsaid Most of this has nothing to with ConfigMgr PKI is not easy Manually bind certificates in IIS* Certificate deployment can be challenging Client auth certs define ConfigMgr client identity ccmhttpstate is undocumented for a reason

19 Links native-mode-client-mp-error-messages-and-what-to-do-about- them.aspx _sms_writing_team/archive/2008/01/17/tips-tricks-hints-for- native-mode-and-internet-based-client-management-part-3-of- 3.aspx

20 Evaluations Please provide session feedback by clicking the Eval button in the scheduler app. One lucky winner will get a free ticket to the next MMS! Platinum Sponsors Gold Sponsors Visit all of our sponsors in the expo area and online!


Download ppt "Internet Based Client Management In System Center 2012 Configuration Manager R2 Justin Chalfant blogs.technet.com/jchalfa nt Jason"

Similar presentations


Ads by Google