Hi All,
First appologise for very long writing.
I am planning to implement the IBCM functionality of SCCM as described in the scenario 3 (Network Diagram for Internet-Based Servers - Scenario 3 with No SQL Server Replica) (http://technet.microsoft.com/en-us/library/bb693602.aspx)
Before starting, I would like to discuss on the ports required in this scenario.
I have gone through "Ports used by Configuration Manager" (http://technet.microsoft.com/en-us/library/bb632618.aspx) document.
I want clarification on following points described in port document with respect to above mentioned scenario:
1. Under section "Installation Requirements for Internet-Based Site Systems", term used Site Server means Intranet SCCM Central Site Server and Site System means Internet based MP/FSP/DP/SUP. Is the understanding correct?
2. Under section "Installation Requirements for Internet-Based Site Systems", will these ports are required to open for the installation of site sytems only? After installation can ports be closed? As Dynamic ports are required to open across DMZ and intranet,
hence is the concern.
3. Across all the document, ports requirement is specified for (in relation with) MP, DP, SUP, FSP site systems. Are these also apllicable for Internet based MP, DP, SUP, FSP site systems?
4. If I list out the port requirements in relation with MP, DP, SUP, FSP site systems as belows:
Site Server < -- > Software Update Point8530/8531
Client -- > Software Update Point8530/8531
Site Server < -- > Fallback Status Point445, 135, DYNAMIC
Client -- > Fallback Status Point80
Site Server -- > Distribution Point
445, 135, DYNAMIC
Client -- > Distribution Point80/443, 445
Client -- > Management Point80/443
Management Point -- > SQL Server1433
Management Point -- > Domain Controller
389, 636, 3268, 3269, 135, DYNAMIC
Software Update Point -- > WSUS Synchronization Server8530/8531
Management Point < -- > Site Server
135, 335, DYNAMIC
Configuration Manager Client -- > Global Catalog DC3268/3269
Then will these ports have to open across DMZ and intranet network? As these contains DYNAMIC ports, it may be security risk.
5. As per my understanding, for the above scenario mentioned (scenario 3), site systems in the DMZ (MP, DP, SUP) will also require Web Server Certificate and Client Authentication certificate. So to request a certificate to CA server which will be a part
of intranet, which ports should be open between Site System to CA server? Will these ports permanantly open?
Regards,
Kedar
Thanks & Regards, Kedar