Search icon CANCEL
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Microsoft System Center Configuration Manager Cookbook

You're reading from   Microsoft System Center Configuration Manager Cookbook Over 60 applicable recipes to administer and manage System Center Configuration Manager Current Branch

Arrow left icon
Product type Paperback
Published in Nov 2016
Publisher
ISBN-13 9781785881206
Length 354 pages
Edition 2nd Edition
Arrow right icon
Authors (5):
Arrow left icon
Samir Hammoudi Samir Hammoudi
Author Profile Icon Samir Hammoudi
Samir Hammoudi
Brian Mason Brian Mason
Author Profile Icon Brian Mason
Brian Mason
Greg Ramsey Greg Ramsey
Author Profile Icon Greg Ramsey
Greg Ramsey
Chuluunsuren Damdinsuren Chuluunsuren Damdinsuren
Author Profile Icon Chuluunsuren Damdinsuren
Chuluunsuren Damdinsuren
Matthew Hudson Matthew Hudson
Author Profile Icon Matthew Hudson
Matthew Hudson
+1 more Show less
Arrow right icon
View More author details
Toc

Table of Contents (10) Chapters Close

Preface 1. Designing a System Center Configuration Manager Infrastructure FREE CHAPTER 2. Deploying Windows 10 with Operating System Deployment 3. Deploying Applications and Software Updates 4. Managing Compliance Settings 5. Managing Mobile Devices using Configuration Manager with Microsoft Intune 6. Managing Sites 7. Managing Clients 8. Managing Inventory 9. Managing Reports and Queries

Managing Internet-facing clients

Depending on the environment, you may have clients that:

  • Regularly move between the Internet and the intranet
  • Are home computers and never connect to the intranet

Managing clients that are not always connected to the internal network can be a challenge. If remote computers use Virtual Private Networking (VPN) to connect to the corporate network on a regular basis, Internet-facing support may not be required. But if we know that clients may use some type of remote desktop to connect to the corporate network, or maybe they don't have to connect to the corporate network at all to do their job, then Internet-facing support should be considered to ensure proper patch and asset management.

CM has two client communication methods: HTTPS only and HTTPS or HTTP. One CM site can support both HTTPS and HTTP communication if required.

Managing Internet-facing clients

Getting ready

Public Key Infrastructure (PKI) certificates are required for Internet-based client communication. Engage with the team that owns PKI in your infrastructure. If a PKI infrastructure doesn't currently exist, follow Microsoft's step-by-step example of deploying PKI https://technet.microsoft.com/en-us/library/mt627852.aspx. Once you have all valid certificates, proceed to the next section.

How to do it...

To enable Internet-facing clients, perform the following steps:

  1. Navigate to Administration | Site Configuration | Sites, and select the desired site to support Internet-based clients. Right-click on the site and select Properties.
  2. From the Client Computer Communication tab, select either HTTPS only if you only want to support HTTPS, or HTTPS or HTTP as required.
  3. Enable the checkbox to Use PKI client certificate, and then click on the Modify button to select the client certification selection criteria, as well as the store name, and then click on OK.
  4. Click on the Set button to specify the Trusted Root Certification Authorities, and then select the starburst to browse to a new certificate file.
  5. Select OK to save changes to Site Properties.
  6. From the Servers and Site System Roles node, select the desired site in the top pane. Select the desired roles from the bottom pane (Management Point, Distribution Point, Software Update Point, as well as Application catalog Point, if required).
  7. Specify HTTPS for client communication types.
  8. As long as the new site systems are accessible from the Internet at this point, the infrastructure configuration is complete. Follow the client installation instructions given at https://technet.microsoft.com/en-us/library/mt489016.aspx; to install the CM client properly.

How it works...

CM allows clients assigned to the same primary site to use either HTTP or HTTPS communication. If a client has the PKI cert, it can be set to use HTTP for the intranet and HTTPS for the Internet.

See also

You have been reading a chapter from
Microsoft System Center Configuration Manager Cookbook - Second Edition
Published in: Nov 2016
Publisher:
ISBN-13: 9781785881206
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €18.99/month. Cancel anytime