DMZ / Internet systems - Design recommendations

I have a full SCCM 2012 R2 setup configured in our internal network.  Now I'm needing to add DMZ systems as clients, as well as supporting laptop users who connect via both the internal network and the internet.
1) I have a separate AD forest in the DMZ that has no connectivity to the internal AD domain
2) I have the ability for SCCM site component systems in the DMZ to connect directly to the internal SCCM database.
3) Computers on the internet will most likely not be allowed to connect to internal systems directly.  DMZ based clients most likely will be unable to as well.
4) I have an AD PKI infrastructure on the internal network, but not on the DMZ AD environment.
Based on that, what's the best way to set up SCCM for what I'm wanting to do?

When you can connect from the DMZ to the "internal" environment (as you mentioned in point 2) than I would go for a site system in the DMZ that contains a management point, distribution point and software update point. By having those roles in
the DMZ you can provide those laptops with the required updates and software.
The laptops should get their certificates from the internal PKI infrastructure.
My Blog: http://www.petervanderwoude.nl/
Follow me on twitter: pvanderwoude
Peter,
If I go that route, will the laptops be able to connect to the internal ConfigMgr systems when inside the corporate network, and then connect to the DMZ systems when on the Internet?

Similar Messages

  • Fuzzy System Designer in Labview 8.5

    I am using LabView 8.5. My project requires me to use fuzzy logic. In the Labview manual, stated that, I need to click to Tools > Control Design and Simulation > Fuzzy System Designer to launch the Fuzzy System Designer. However, in LabView 8.5, I follwed the steps but it did not lead to Fuzzy System Designer as the intruction mentioned in the manual. How to find it?

    In addition, I strongly recommend to update your LabVIEW version to 2009 or later. We did a major improvement to the toolkit at that version.
    Barp - Control and Simulation Group - LabVIEW R&D - National Instruments

  • More from Adam Taylor about Zynq and SDSoC: "Zynq is a device every embedded system designer should be familiar with"

    Adam Taylor publishes the MicroZed Chronicles weekly in the Xcell Daily blog so you are likely familiar with his writing. Adam has just published an article about SDSoC and Zynq titled “High-level synthesis comes of age with SDSoC” on the Embedded.com Web site. Here’s his motivation for writing this article:
    “…Zynq is a device every embedded system designer should be familiar with and considering for their application. At its heart the Zynq is not a FPGA with embedded processors -- like previous generations of FPGA with Power PCs -- but a true embedded processor with very flexible interfacing capabilities (DDR, CAN, UART, USB, Giga Bit Ethernet, SPI and I2C to name a few). What separates the Zynq from other embedded processors is the attached programmable logic, and with SDSoC embedded system developers can exploit this pretty simply…
    SDSoC takes the eclipse front end, Vivado HLS, Vivado and a lot of behind the scenes intelligence to create seamlessly the option to accelerate software functions in the attached programmable logic of the device.”
    What follows is a simple explanation of what SDSoC brings to the party from a design engineer’s perspective.
    Recommended reading.
     

    xisal wrote:
    Take a look into /etc/hal/fdi/policy/10-keymap.fdi. This works with portuguese layout:
    <snip>
    The file did not exist, so I created it and changed "pt" to "it". Thanks a bunch, that fixed it!
    Try SMPlayer.
    Ah, I'd rather not involve Qt. Besides, isn't SMPlayer simply a frontend to Mplayer (who already has GMplayer integrated into it, IIRC)?
    Mikko777 wrote:
    Why would you want to use 75Hz with lcd display?
    Does it make a difference?
    On my monitor, from my point of view, it appears to make a difference. It's that simple
    azleifel wrote:In gmplayer Preferences -> Audio -> (assuming alsa selected) -> Configure driver and change the mixer channel to something other than PCM, e.g. Master.
    For all the three combos, I have "driver default" selected. The other option is "default"; I tried to manually type "Master" into the mixer channel field, but then gmplayer's windows and my Xfce taskbar started blinking, so I knew I had just "crossed streams".
    Regarding NVIDIA X Server Settings, running "usr/bin/nvidia-settings --load-config-only" at login is the only way to apply the settings "automatically".
    I've slapped that on my ~/.xinitrc before "exec startxfce4". Thanks in advance, going to test it now!
    About the refresh and non-decorated windows issues (which *appears* to be solved after I've wiped the xfce-session cache), I've been thinking: could they somehow be related the login manager I've chosen, SLIM?
    P.S. New question: is there any way to enable the ALT+num126 for ~ keyboard behaviour I'm used to under M$ environments?
    Last edited by Akaraxle (2009-01-03 09:43:02)

  • We got a new Apple TV for Christmas and it works wonderful. However, my question is this. We are on a satelitte internet system and our bandwidth is limited. Can anyone tell me what effect it will have on using up my 10 megs of bandwidth?

    We got a new Apple TV for Christmas and it works wonderful. However, my question is this. We are on a satelitte internet system and our bandwidth is limited. Can anyone tell me what effect it will have on using up my 10 megs of bandwidth? If I run over the 10 mgs, the service either slows way down until it is reset on the first of the next month or I have to purchase additional bandwidth and it can get expensive.
    Any information would be greatly appreciated.

    If you only have a 10MB limit on the Internet connection you might as well not have Internet access and certainly should not attempt to stream anything.
    If the limit is 10GB, then you will need to be careful with streaming as most video is 1-3GB for a one hour show.

  • Design Recommendations 1941 and 2921 still good?

    Hi All,  I've been asked to make some design recommendations.  The 1941 and 2921 would be a good fit for this customer.  Anybody know if there are plans for these routers to go EOL anytime soon?
    Thanks in advance

    I'm installing many 19/29xx series routers and haven't heard anything from my rep about EOL. Even if it goes EOL you still have support for many years after that and a solid piece of equipment.

  • Systems Design Engineer for Orange County, CA

    Please mail your resume in Adobe PDF format to [email protected]
    If you have an extraordinary passion for engineering and are not afraid to take on an extremely challenging position,
    we have exactly what you have been looking for!
    Employer information:
    moviMED is a small systems engineering consulting firm located in Southern California. The central focus of our operations is to provide exceptional engineering services to the Life Science Industry in the Academic and Commercial arena. We develop cutting edge technology for major biomedical companies. We offer a broad range of services to our clients to assist them in conceptual prototype design, medical device testing, motion and vision applications.
    Job Description:
    Employee will plan, document, design, specify and build comlpex systems using best engineering practices. He/She will be required to interact with other employees, vendors and other consultants to solve problems on his/her own. Application software will be mainly developed using LabVIEW and relevant tool packages, such as (but not limited to): NI MOTION, NI VISION, Data Base Connectivity, SPC etc.
    The employee will be further required to develop custom electronic signal conditioning and other interfaces to sensors and actuators. The frequent integration of new technology and third party products will require the employee to keep him(her)self up to date by studying relevant documentation and by engaging in a substantial amount of research.
    This job is heavily oriented towards the Life Science Industry and demands more than just electronic engineering and computer science skills.
    The Ideal Candidate:
    Will have experience in the following categories:
    - Application Development using LabVIEW V6.1 and V7.x
    - Analog and Digital Circuit Design
    - Micro-Processor, Micro-Controller Programming in embedded C and/or assembly for 8-bit and 16-bit cores
    - Motion Control (Pneumatics, Servo, Stepper etc.)
    - Computer Science Skills (MS Windows, MS OFFICE, Data Base/SQL, Networks etc.)
    - Project Management
    - Sensors of all kinds, Actuators of all kinds
    Required Skills:
    - Exceptional Sense for Details
    - Highly Organized
    - Self Sufficient
    - Ability to quickly learn on its own
    - A great deal of Common Sense
    - Capabilty to work of poorly documented requirement specifications
    - People Skills
    - Teaching Other People (Holding Seminars and Presentations)
    - Great Improvisation Skills
    - Fluent in English Language (in writing and verbal)
    - Analytical Problem Solving
    - Methodical Trouble Shooting
    - Working with Time Constraints
    We look forward to receiving your resume
    Regards,
    Markus Tarin
    President & CEO
    www.movimed.com - Custom Imaging Solutions
    www.movitherm.com - Advanced Thermography Solutions

    I have just read your job posting for LabView Programmer and would like to introduce myself.
    I have over six (6) years experience with LabView, from versions 3 to 7.1.1, in systems design and programming of LabView based SCADA/DCS and signal analysis applications.
    Your job description is very interesting to me as I have had some exposure to intelligent vision systems use in manufacturing quality control and have been a practicing audio/video engineer since 1987.
    I have also looked closely at the Lake Forest, CA location and would consider relocation as I have been recently considering a warmer climate. I have been working as an independent consultant and would be willing to assist you on a part-time or full-time, term, basis if you would find that helpful. I would like to discuss the position further and will send my resume early next week. Please feel free to contact me in the mean time with any questions.
    Thanks,
    Tom Held
    [email protected]
    414-964-0518

  • Xilinx SDAccel and NI LabVIEW Communications System Design Suite win a pair of EETimes/EDN ACE Ultimate Product Awards

    Last night, EETimes and EDN presented a number of ACE Awards including twelve “Ultimate Product” awards. The Xilinx SDAccel Development Environment for C, C++, and OpenCL won the Ultimate Product Award in the Development Kits category.
    EETimes/EDN 2015 ACE Awards
    From the SDAccel entry form:
    “The SDAccel development environment for OpenCL, C, and C++, enables up to 25X better performance/watt for data center application acceleration leveraging FPGAs and combines the industry’s first architecturally optimizing compiler supporting any combination of OpenCL, C, and C++ kernels, along with libraries, development boards, and the first complete CPU/GPU-like development and run-time experience for FPGAs. SDAccel streamlines the development and deployment of critical algorithms such as Deep Neural Networks used in machine learning.
    SDAccel includes the industry’s first architecturally optimizing compiler that makes efficient use of on-chip FPGA resources along with a familiar software-development flow based on an Eclipse integrated design environment (IDE) for code development, profiling and debugging, providing a CPU/GPU-like work environment.
    SDAccel leverages Xilinx’s dynamically reconfigurable technology to enable accelerator kernels optimized for different applications to be swapped in and out on the fly. The applications can have multiple kernels swapped in and out of the FPGA during run-time without disrupting the interface between the server CPU and the FPGA for nonstop application acceleration. This functionality is ideal for swapping applications during peak loading periods.”
    (Note: For more information about the Xilinx SDAccel design environment, see “CPU/GPU-like software development environment for OpenCL, C, C++ delivers FPGA-based app acceleration with 25x better performance/W,” “and “Latest SDAccel release adds 4 new hardware dev platforms, 4 new libraries, 6 new design services firms.”)
    Vinay Singh accepts an ACE Award for the SDAccel design environment from Max Maxfield
    The LabVIEW Communications System Design Suite from National Instruments (NI) won the ACE Ultimate Product Award in the Software category. NI’s LabVIEW Communications System Design Suite combines software defined radio (SDR) hardware with a comprehensive, unified software design flow to help engineers prototype 5G systems. The package includes built-in application frameworks for WiFi and LTE that enable wireless developers to focus on creating specific components based on existing standards rather than designing new algorithms from scratch.
    The LabView Communications System Design software is coupled with the company’s USRP software-defined radio development platform for 5G research, which is based on a Xilinx Kintex-7 All Programmable FPGA. Wireless engineers can use the NI USRP RIO and the NI LabVIEW Communications System Design software to rapidly prototype real-time wireless communications systems and test them under real-world conditions.
    (Note: For more information about the NI LabVIEW Communications System Design Suite, see “LabVIEW Communications System Design Suite combines SDR hardware with a unified software design flow for 5G development.”)
    Congratulations to all of the talented developers from both National Instruments and Xilinx who created these award-winning products.
     

  • System Design of ava2 ORB

    hi,
    can some one help me out with the system design of Java2 ORB.i mean how actually object request broker has designed in the system.(system level design not application level).
    any sites,references deals with this...??
    Thanks,
    Kishore.

    Sun's ORBs com.sun.corba.se.internal.*.ORB are proprietary I think. The JACORB is freely distributed with source code (www.jacorb.org). The OMG is responsible for the overall CORBA design and specification (www.omg.org). I hope this helps.

  • Design Recommendation

    I am looking for some design recommendation. Our application has set of n (lets assume 2) processes. The definition of each process is in a XML file. The XML file looks like:
    <processes>
    <process name ="a" action="b" />
    <process name ='x' action="y" />
    </processes>
    Now we have several clients that have certain characteristics and run these processes in specific order. For example:
    Client 1 name = "clean" order = a, x
    Client 2 name = "fun" order = x, a
    I am trying to figure out what will be a good, clean design to store this information. Should I create another XML with client list?

    Thanks for your replies. The process is currently in
    production. I recently joined the team and I am now
    trying to clean up the design. In current
    implementation every thing is hard coded and we have
    tough time adding any new clients that use the
    current set of processes. Our goal is to add new
    clients with minimum turn around.OK, is the in memory design cleaned up?
    My experience is that when the design approach comes from the input or output perspective, the resulting design tends to be rigid and sub-optimal. Once you have determined how you wish to represent the data in memory, then you can desing the input and output to be a natural extension of that design (you may want to change it subtlely.) You can even use built-in classes from the JDK to write and read your Objects to/from XML.

  • 'Fuzzy System Designer' problem

    After I completed set up the 'Fuzzy System Designer' (2 inputs and 1 output). How can I use it in vi program? I find it can save as .fc (custom pattern) file in 'Fuzzy Logic Controller Design'. But how to use the .fc file?

    Hi,
    To use the Fuzzy Logic file, you need to use the "FL Load Fuzzy Controller" to load the file and use the "FL Fuzzy Controller" VI to execute the controller.
    The best way to see how to use it is accessing the manual and examples that ship with LabVIEW. You can access both function by going to "Help>>Search LabVIEW Help..." and go to "LabVIEW Modules and Toolkits" Options, browse the content for PID and Fuzzy Logic Toolkit. To access the example finder, go to "Help>>Find Examples.." and under Modules and Toolkits, find PID and Fuzzy Logic and open the examples.
    Hope this helps!
    Barp - Control and Simulation Group - LabVIEW R&D - National Instruments

  • Fuzzy system designer

    Hi,
    Is it possible to start "Fuzzy system designer" from a .vi so that the .fs file is loaded?
    I would like to tune my rules and memberships. Now I must look for Tools -> Control... -> Fuzzy System Designer, then wait for it to load. After that I must find the right .fs file. It could  be more easily to use if the operation is: press button which stops fuzzy controller, starts/change control to Fuzzy system designer. After that I can edit rules etc, save the system. Back to my .vi. Press button to load new fuzzy system.
    Thanks in advance!
    Seppo Rantala

    To change parameters of Fuzzy WHILE the Fuzzy Controller, you have two options:
    1. You need to use the programmatic API (LabVIEW 2010 and later) that allow you to change any parameter while the VI is running. Please look at documentation and examples "examples\control\fuzzy\Dynamic greenhouse controller\FuzzyEx Dynamic Fuzzy Controller for a greenhouse.vi" to see how to use the API.
    2. You can automate the process you described below by place the load VI "inside the loop" and use a case structure to reload the controller after you modify the parameters with the existent tool. Notice that you do not need to stop the Fuzzy System Designer to operate your VI and you can modify the controller, save to a file and then, you can "reload" the controller, which will update all the parameters for you.
    Hope this helps.
    Barp - Control and Simulation Group - LabVIEW R&D - National Instruments

  • Anyone used VisionNet system "designed to provide real-time streaming video feeds over the Internet"?

    I'm a Mac user and we only have Macs at home. My son just started preschool, which offers a VisionNet system--"a state-of-the-art system of cameras, servers, and software designed to provide real-time streaming video feeds over the Internet." However, on the VisionNet FAQ page, it specifies the following:
    "You need a web browser that is Java-enabled, perferably Microsoft Internet Explorer.  If you're running Microsoft Internet Explorer, it needs to be version 6.x or higher.  We recommend Internet Explorer 6.x as this is the latest and most up-to-date product release.  Some Windows XP and Windows XP Professional users will have do download a Java runtime environment in order to use the VisionNet system if they have not done so already."
    We don't have any PCs at home, so I  tried to log in using my MacPro desktop, my old MacBook Pro and my new MBP. Basically, for the last 3 weeks I've managed to access the site only ONCE from my desktop and after the time-out session, I wasn't able to log on ever again (I just cannot enter any keys on the Username and Password fields at login). If I hit the Logon button from the FAQ page, I get an "Unauthorized Access" pop-up message: "This site may only be entered from an authorized web site! Please enter this site from your childcare provider's web site." When I enter "OK" I immediately get a pop-up menu "Confirm Dialog Preference. Prevent this page from creating additional dialogs" but I still can't enter any keys at login. It does nothing!
    The "support guy" has NO knowledge of Macs, so I don't know where else to go. The fact that I had successfully logged on once makes me believe it's something I have to update/delete/add in my Preferences in Firefox (I've used Safari and Chrome with no success). I've also considered purchasing an inexpensive PC just for this lousy VisionNet system  but I want to see if anyone has any ideas or advice.
    Can anyone please help me?   Thank you in advance!

    Here is a link to the finished PSA at Vimeo. It is not an outstanding production or anything too special, but it is worth noting that while some of the stills were doctored in Photoshop, the entirety of the editing and motion graphics were done in Premiere CS6.02; and the timeline playback was RealTime thanks to the MPE Hardware Acceleration and a GTX 560 2GB.
    DUI PSA
    Happy Editing.

  • Trying to set up AV server on mini late 2012.  Will upgrade to Yosemite tomorrow.  Home Internewt is ATT Sierra mobile hotspot only.  So I think I need a wifi router that will tether the hotspot as sole internet source.  Recommendation for system set

    My system: Mac Mini late 2012 w/ 1 TB disk and *GB memory (for AV server), iPad air 2 w/ 64 GB, iPad, iPad 2, iPhone 6, iPhone 4, Macbook running Yosemite, older Macboo w/ 2GB memory & 160 GB hard drive, 1 TB back up drive, WiFi Printer
    Internet:  Wireless hotspot ATT 4G LTE limited to 5 GB/mo (no cable or DSL available. Router to be determined
    AV equip:  Vizio smart TV (WiFi capable & network cable), high end analog audio, DAC, Samsung TV/display w/ HDMI.
    Looking for a router recommendation that will utilize my ATT device and stream music (and of course less demanding DATA)
    What is/are recommended connection(s) between devices?  Hardwire Mini to main TV w/ HDMI, network or USB?  Help?

    Another way to set things up, use an Apple Airport Extreme Basestation.
    My system setup has a cable modem directly connected to the AEBS.
    The AEBS is then setup to do all of the network management,  I use
    both hardwired and WiFi access via the AEBS.  It also has a USB port
    that you can use for attaching HDDs for common data access and even
    Time Machine backups.
    FWIW, here's my system:
    2011 MiniServer used as HTPC - hardwired ethernet to AEBS
    2010 Mini used as server - hardwired ethernet to AEBS
    (these are hardwired simply because of proximity to AEBS but could be WIFi connected)
    Late 2013 27" iMac workstation- hardwired or WIFi depending on needs
    Early 2011 Macbook Pro - WiFi connected
    iPhone 5S - WiFi connected as needed
    The 2010 Mini Server I use as my "iTunes hub" set up with Home Sharing and
    by running Server on it, have Apple download caching of both Mac and iOS
    apps, Time Machine backups and general backups for various content from
    the different computers.

  • Simple recommendation system design

    Dear All
    I want to design a simple recommendation system for the item on my web site, so i am thinking of doing the following:-
    1.     Recommendation table (item_id, item2_id, count)
    2.     when the user select an item then i will store this item id in my application and i will call this item (initial item) for example item id =10 , then when the user select another item(item id = 20)
    3.     I will update the recommendation table to be
    4.     10 , 20, count+1
    5.     If this is the first time for this combination then i will insert ht following
    6.     10, 20, 1
    7.     If the user select another item = 30 then i will assume that it is the recommendation for the last item
    8.     I will update the recommendation table to be
    9.     20,30,count +1
    10.     ....
    For me i found this will work fine, so does the above design considered valid?

    i will explain the issue more;
    now when the user first select item 10 , and then he select item 20;
    so i will wirte the following buisness logic:-
    check if the 10 ,20 combinatino exsists in the recomendation table
    if yes
    then update recommendation set count = count+1 (count represents who many time item 20 was selected after selecting item 10)
    if no then
    insert into recomendation values( 10,20,1)
    then the user select item 30 so
    check if the 20 ,30 combinatino exsists in the recomendation table
    if yes
    then update recommendation set count = count+1 (count represents who many time item 30 was selected after selecting item 20)
    if no then
    insert into recomendation values( 20,30,1).

  • ERP System Design

    Hii Freinds,
    Myself Priyanka ,and fresher in .net ,I have some queries Please suggest me Right Path,
    I have to Develop ERP Sytem in asp.net MVC4 ,so what steps i have to follow,which platform required for that,Is Visual studio12 Internet Templet used for designing ERP System.
    Regards,
    Priyanka
    [email protected]

    This forum supports .NET Framework setup.
    Your question about MVC4 should be asked in a forum where MVC is discussed.
    I suggest you ask here: http://forums.asp.net/1146.aspx/1?MVC
    Thank you for your understanding.

Maybe you are looking for

  • My fonts that are installed in Font Book are not showing up in Microsoft Word. Can someone help me fix this problem?

    Hello! I am needing some help. I own a Mac Book Air with OS X 10.7.5. This computer belongs to the school district I teach for, so I do not have permission to do a huge wipe that would uninstall programs such as Word. When I first got my computer, I

  • HTMLB

    Hello</b>, I want to create a JSP using HTMLB tag. My problem is that i'dont how to do this well ? I created some JSP exactly as in the samples I found but it doesn't work when I ran them on my EP6. The view stay empty ?! By default, NWDS don't put t

  • Hidden iPhone File Tracks Users' Every Move

    The security of Apple's iPhones and iPads is being called into question after it emerged the devices contain a hidden file that tracks the owner's locations. full story - http://uk.news.yahoo.com/5/20110421/twl-hidden-iphone-file-tracks-users-ever-3f

  • Uploading 3G-S videos to Mobile Me Gallery - won't play on AppleTV

    Uploading 3G-S videos to Mobile Me - won't play on AppleTV Posted: 19-Jun-2009 11:56 Reply Email Hi all - i can upload my photos to MobileMe and view them on my appletv - no problem at all but when i try to upload a video (which it is happy for me to

  • Suggestion for future Archlinux Releases.

    Hello everybody, today I read the release announcement of Archlinux 2007.08 on distrowatch.com. See http://distrowatch.com/4394. I registered immediatelly the Archlinux forum only because I wanted to tell the releasers / developers of Archlinux this