I’m writing this article because I want to explain a design scenario I had at one of my customers. After upgrading their SMS 2003 to ConfigMgr 2007, it was decided that their ConfigMgr 2007 should be upgraded to Native Mode because the customer wants to use Internet Based Clients.
With a customer which has 5 sites across the country the question raised by them was if it is necessary to have a site server in the DMZ at each location of these 5 sites. (Because each corporate branch has a site server, meaning different site code and different boundaries)
Or is it a design decision which can be made based on the number of clients intended to be switching between being Internet Based Clients or Intranet clients. So simply if the customer is having very few number of clients to be internet based clients all over the corporate branches, can one site at the DMZ supports this requirements?
The short answer is No! But let me first clarify the Internet Based Clients types explained well in here http://blogs.technet.com/b/configmgrteam/archive/2009/03/03/tips-and-tricks-using-internet-only-client-management-on-the-intranet.aspx by Carol Bailey.
Clients related to this idea can be shortly listed as below:
The first one is the Internet ONLY clients, so these clients will never try to find an intranet management point (that’s the normal management point)
The second one is the intranet only clients, (and as the name indicates these will be majority of clients).
I assumed that because most of them are workstations which are not suppose to be moving out! (Hopefully)
The third is the type of clients which supports both (internet and intranet) which means that the clients can connect over the internet and finds an internet-based management point or stays in the company’s network and connect to intranet based management point.
Having said so, and to address the above questions, there MUST be a site in the DMZ to handle the clients which are assigned to this site when they go out on business trips for instance. But the long answer is, are we absolutely sure that we will have Internet based clients all over our five primary sites? If the answer is YES, then we need to have 5 dedicated servers in the DMZ zone. If the answer is NO, the IT team needs to determine what are the sites\location which has no Internet Based Clients.
The good news is that using the Virtualization technology these 5 servers (from my customer scenarios) can be hosted on a Hyper-V virtual server and all of them can run as Virtual Machines.
This article was inspired by the customer’s questions and I would like to thank Mr. Wilfried Schadenboeck for contribution.
Posted
07-12-2010 12:14 PM
by
Asem Alhourani