Does 2012 OSD get around requirements to get to the MP during the task sequence?

Currently right now I am working in an environment where we are on SCCM 2007, but will be going to 2012 next year. We are in the process of trying to make it so we can build on a secure network that cannot route to any other network. I am prepared to put
a DP out on this same network, but the problem I am running into is that during the task sequence starting, it downloads the task sequence from the MP, not the DP as it is not associated with the package. The MP is not on the same un-routable network. We will
need to have about 6 or so of these, so we do not want to setup 6 MP because now you are looking at not only 6 primary site licenses, but 6 SQL installs (Our environment will not let me get away with doing SQL express for support reasons) which adds up quickly.
Below is a link to exactly what I am speaking about:
http://blogs.technet.com/b/configurationmgr/archive/2009/04/16/configmgr-2007-primary-site-mp-is-used-for-the-task-sequence-even-when-deploying-osd-images-to-secondary-sites.aspx
What I am wondering is if SCCM 2012 OSD was structured differently in a way that access to the MP is no longer necessary during the task sequence process (say for example the task sequence xml is replicated to DPs too)?
Thanks. 

My apologizes. I was meaning to say Primary, Secondary Sites. Not MPs. I brought this up to give reference to idea about the boundaries that I am going to have to use to prevent these clients from contacting DPs they they can't route to.
The idea behind getting off the build network and onto a prod is that security requirements from my companies Infosec require that we limit the amount of traffic on production networks. The idea is that the server be built on the build network, disconnected
and brought into prod. The whole time the MP would be the same, but the DP would switch based on the prod network they were brought into as DP will reside in these prod networks which will get flipped over by the boundary for the prod subnets. Once on the
prod network they would be able to contact the MP. 
I would love to do stand-alone media, this is one of the first roads I started looking down as I have done them in the past for offline builds, but I need the machine to auto assign its hostname from a external servers that will script the build. The build
process we are trying to put into place will be started from an external website. My first thought was to have it add the machines to a collection and add a variable that would be turned into a task sequence variable during the TS and use it for the hostname
when it attempt to apply the Windows settings. The only way I think I could get this to work would be to write a script that is executed during the task sequence that would match the MAC address of the machine and assign the hostname by calling on another
share that is written to by the external website with the MAC and hostnames. The only problem that I cannot get around is that this build process needs to be fully automated and this is for both virtual and physical. I have no problems mounting a stand-alone
build ISO using a script for VMWare, but the problem starts when I look at the physical and limitations of scripting for both iLo and iDRAC for performing this step. iLo can be done, but iDRAC is limited. 
As for a reverse-proxy I will not be able to look at that. They have specific requirements against using reverse-proxies in only specific situations and this it not allowed. I got turned down on this one. This requirement is created by a federal regulation
my company has to follow. 

Similar Messages

  • HT1311 i tried to do a backup from my old iphone as i have a new one that was signed into another itunes account. it said i cant do it because the iphone rejected the request. how do i get around this? i have signed out of the old acct and into mine on th

    i tried to do a backup from my old iphone as i have a new one that was signed into another itunes account. it said i cant do it because the iphone rejected the request. how do i get around this? i have signed out of the old acct and into mine on the phone

    What is the precise wording of the error message that occurs on the old iPhone when attempting to do a backup?
    Are you attempting to backup via iTunes on the computer or iCloud?

  • Why when I try to re download my music it says this device is already associated with another device and I have so many days to re download my music back? How do I get around this and get my music back?

    Why when I try to re download my music it says this device is already associated with another device and I have so many days to re download my music back? How do I get around this and get my music back?

    It is telling you that the device has been associated with another Apple ID. Once an Apple ID has been associated with a device, there is a 90-day waiting period before another Apple ID can be associated with that device. Here is a Support Article that explains the 90-day waiting period:
    iTunes Store: Associating a device or computer to your Apple ID
    Cheers,
    GB

  • HT1657 do you get a discount if you buy the movie during the rental period?

    i'm thinking of renting a movie. I would like to know if i rent it and enjoy it enough to buy the movie, will i get a discount during the rental period toward my movie purchase? Similiar to Complete my Album for the iTunes music store.

    Thanks.
    Apple please add some form of this into your store! Like Complete my Album I'm sure it would increase sales.
    I know you just lost 1 sale =/

  • Deploying the SCCM 2012 Client to WES 7 devices that are locked down with the FBWF using 2007 task sequence via WEDM.

    I'm wondering how people are migrating their embedded devices that are using the FBWF. I've done some googling and it seems like most people are just re-imaging the devices and after migrating a single device i see why. Its not a pretty process. This will
    be a long description but ultimately my question stems more from trying to find a better way to execute the device migration from 2007 to 2012.
    Some back ground on my situation might be in order here. I'm in the process of wrapping up our 2007 to 2012 migration. We have a 2007 infrastructure that was a central server with 2 primaries and 286 secondary site servers. I've consolidated that to a single
    2012 primary site server that hosts all the main roles. There are 2 more servers in the data centers both operating solely as push distribution points I'll refer to them as 2012 01 02 and 03. I'm over half way through the migration and so far haven't needed
    to offload any site roles. There are almost 10,000 clients now reporting to the 2012 site server and almost a 100 field servers pulling content from 2012 02 as their source dp as pull dp is the only way forward for this many devices. I've read the horror stories
    of trying spin up 200 plus push dps. We are running PKI. I'm at the point now where i need to start migrating the Windows Embedded Seven Standard clients that have the 2007 sccm client on them with WEDM for write filter handling.
    What i'm wondering is if anyone has any pointers for me regarding migrating the WES 7 devices. My plan that i've come up with is to somehow script the process using a 2007 WEDM Task Sequence to try and migrate them over to 2012. Things are complicated as
    I need to somehow script the install, the policy checkin, hardware inventory, software inventory, and validate the SCEP client installs before I reboot the device one last time to enable the FBWF. How I handled the SCCM 2007 client install on these devices
    when they were provisioned was to just create a batch file that would sleep for ten minutes then check to see if the inventoryagent.log file had been created yet. I realize now that is inefficient as i can kick off the inventory using a WMI method once the
    client has installed. Also I need to make sure the machine gets its first policy as that is how it creates the communication using PKI through that first policy transfer and that also finalizes the client install. The biggest piece i'm uncertain about in this
    regard is the SCEP client.
    I had to change the SCEP client install from yes to no in the default client settings as we have some Mcaffee servers that can't have the SCEP client on them. I have incremental updates enabled on the collection that has the policy that installs the SCEP
    client but this will take an unknown amount of time unless i force the environment to update as the device starts in 2012 install, or if I could kick off the SCEP isntall... IDK. I'm also wondering if i should keep the device in the migration process until
    i validate it has its proper scep policy applied which I believe can be validated by a registry key somewhere.
    Once the 2012 client gets installed will that cause it to lose its place within the 2007 Task Sequence? Considering its going to take a minimum of 2 reboots I'd normally use the task sequence to handle its progression through the process.
    I'm also considering trying to use an Orchestrator runbook, as that would be a good way to keep track of the migration process as each device migrates. Especially since this might take several seperate scripts.
    I'm going to take a stab at scripting the migration process, but if anyone has any pointers that might make this a less complicated I'd really appreciate it as I've got about 3000 of these devices that need to be migrated over. The other things i've learned
    the hard way is any time you have something this complicated over the course of 3000 devices you will run into unknowns and the failure rate increases. I'm in the precarious position of having to not only build this process out but in some situations have
    it complete in the shortest amount of time possible as we have sites running 24x7. I know the end users behavior all to well and they will just keep hitting the power button sometimes even though their not supposed to so they can get their device functional
    again. In those situations i'd end up, if i'm lucky with a device that no longer has a healthy SCCM client in either environment and the write filter disabled.
    So like i said any pointers anyone could throw my way i'd really appreciate. I manually went through the migration process on a single device for proof of concept and ended up with almost 2 pages of pseudo code for my migration script/scripts.
    Thanks,
    -K.R.

    Hi,
    In R2 there are some new variables you can use to solve this,
    http://ccmexec.com/2014/12/smstsmplistrequesttimeout-value-in-milliseconds/
    In Sp1 though adding a step to sleep for 2-5 minuter after reboot and before the application install step is a common workaround.. a powershell command with "Start-Sleep
    -s 120" should do it. 
    /Jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • On Sympatico homepage, my local weather and news does not come up unless I refresh the page. But when I return to the homepage during the same session, local news/weather is gone again. Is this correctable?

    When I first open the browser and it goes my homepage, Sympatico.ca, there are 2 areas of the homepage you can personalize. On the left hand side "News" Column, the bottom box "Local News" allows you to select a location (Toronto, Ontario Canada for me) to display news from that area. On the far right hand column, below the advertising bar, is "Weather" where you select your city (Brantford in my case) and it will display the 4 day forecast in C or F degrees. Once you close the homepage the settings are saved. The problem is that when I leave the homepage to any other website, if I return to the homepage the weather and local news is back to the default setting of having to select the city again. I did find if I just refreshed the page, the personalized settings appear. I have Firefox 4 and it seemed to correct the problem when I installed 4 as the same problem had been occurring with my previous version of Firefox. But now it's back to having to refresh the page to get the saved location for local weather and news. My wife uses IE8 on the same PC and has not had this problem on her Sympatico homepage.

    aha!
    Wed Feb 14 12:29:16 2007
    PUSH:
    Received control message:
    'PUSH_REPLY,
    route 192.168.100.3 255.255.255.255,
    route 192.168.1.0 255.255.255.0,
    route 192.168.3.0 255.255.255.0,
    route 172.16.0.0 255.255.0.0,
    route 10.123.123.0 255.255.255.0,
    redirect-gateway,
    dhcp-option DNS 172.16.70.12,
    dhcp-option WINS 172.16.70.2,
    dhcp-option DOMAIN timberline.int,
    route-gateway 172.16.70.254,
    ping 10,ping-restart 120,
    ifconfig 172.16.70.216 255.255.255.0'
    The ifconfig line the server is pushing is not right. That is meant for a point to point connection. That is why the local client is puking on it...it is not correct. At least for a tun type device. If it was a tap, then it would be fine.
    http://openvpn.net/man.html
    (look for "--ifconfig l rn" )
    so.... change the line to dev tap, and then do this stuff..
    http://wiki.archlinux.org/index.php/OpenVPN_Bridge

  • TS1702 i fogot the password to my photo vault app . how can i retrieve the password or get around it to get my pictures in it?

    i forgot my password to my photo vault app. help how can i get into it to retrieve my photos?

    You should try contacting the app's developer to see if they have some sort of password recovery system.

  • IDVD working till I installed 2TB ED. Keep getting message"There was an internal iDVD error during the last action. This is not a movie." Any help is appreciated.

    iMovie message "There was an internal iDVD error during the last action. This is not a movie." comes up after trying to create a movie to burn to iDVD. Recently added a 2TB external drive to free up memory from HD. iDVD was working fine till the ED was added. Can't burn DVDs anymore. Any suggestions on how to fix the problem?

    What  folders did you move to the EHD? Any of the basic Home folders?  What format is the EHD?  It should be OS X Extended (journaled).  Do you have any files that iDVD uses on the EHS, i.e. project files, media files?
    OT

  • Hi. I have purchased Lego Indiana Jones for my Macbook Pro. On trying to install it, it is telling me it encountering an error. Does anyone know how I can get around this? Cheers

    Hi. I have purchased Lego Indiana Jones for my Macbook Pro. On trying to install it, it is telling me it encountering an error. Does anyone know how I can get around this? Cheers

    I have this problem too the error message for me is error 36
    (It works on my Macbook but not my Macbook pro)
    Any help you could give would be great

  • TS1474 I changed my computer (old one is dead!) and now when I want to sync the contents of my iPod onto my new computer, it tells me I can only sync with one computer (i.e. the one that died!) How do I get around this??

    I changed my computer (old Dell is dead!) and now when I want to sync the contents of my iPod onto my new computer (a Sony Vaio), it tells me I can only sync with one computer (i.e. the one that died!) How do I get around this??

    -Transfer iTunes purchases to the compuer by:
    iTunes Store: Transferring purchases from your iOS device or iPod to a computer
    - Transfer other music by using a third-party program like one of those discusssed here:
    Copy music
    - Connect the Ipd to the computer and make a backup by right clicking on the iPod under Devices in iTunes and select Back Up
    - Restore the iPod from that backup
    Note that the backup that iTunes makes does not contain synced media like apps and music.

  • HT2518 How do you reset the password on a migrated user account? Mac wants the old password putting in before we can set a new password and the old password won't work.  How do we get around this?

    Used Migraton Assist to transfer data from old Dell PC onto new Macbook Pro.  Data has come across but cannota access the User Account from the Dell.  It is displayed on the desktop of the Mac but is requesting and new password.  Before we can reset the password we have to put in the old password.  We have put in the old password but it doesn't work and therefore we can't reset the password and get into the User Account. 
    How do we get around this problem so that we can access the User Account.
    Although the data has transferred we cannot see our contacts transferred from Outlook into Mail.  We are wondering if they are contained within our User Account, but can't find out until we can access the it?
    Help wold be much appreciated.
    Pensos

    Hello:
    Hopefully this will help you:
    http://support.apple.com/kb/PH4117
    Barry

  • I can't download music from my library to my ipod because it says only 5 accounts are allowed to share content. How do I get around this?

    I can't download music from my library to my ipod because it says only 5 accounts are allowed to share content. How do I get around this?

    Or how do I change the 5 devices. Some are not used anymore

  • I have so much trouble with the plug in part of the program I want to disable this in Mozilla. I have to go to windows explorer to get around this plug in problem with Mozilla.

    # Question
    I have so much trouble with the plug in part of the program I want to disable this in Mozilla. I have to go to windows explorer to get around this plug in problem with Mozilla

    Depending on the CSS, live view and design view can be totally different.
    Its often best to type in your copy in the divs and then add the CSS to format it.
    Post the css and the set of divs with some content in order to enable people to try work out what is wrong.

  • How do I get around password?

    My ipad was upgraded and password wont let me pass to get to settings to disable password. Can't even get pass signin screen.

    If you set a passcode to lock the iPad, you can't get around entering it. What good what having the passcode be if you could workaround it?
    If you bought the iPad from someone else and it is asking for their password, you will have to ask them to erase the device for you before you will be able to activate it. If they can't erase it, for whatever reason, you have a bricked iPad on your hands that you will never be able to use.
    If I am not understanding you correctly and you just need to unlock the device because you forgot your own passcode, you need to restore the device using one of the methods here.
    iOS: Forgot passcode or device disabled - Apple Support

  • I bought an iphone 5 put a passcode i forgot it done a restore with i tunes and it is still asking for user id and password during activate how do i get around that ??

    i bought an iphone 5 put a passcode i forgot it done a restore with i tunes and it is still asking for user id and password during activate how do i get around that ??

    You need to contact the previous owner and have them follow these instructions: http://support.apple.com/kb/HT5661

Maybe you are looking for

  • NtfsServer problem on Windows 2000 Advanced Server

    I've installed Oracle 8.1.6 and iFS 1.0 on Windows 2000 Advanced Server. Everything else seems to work fine with iFS, but the NtfsServer always fails to start up. Is this a compatibility problem between Oracle and Windows 2000? I have no drive letter

  • SLLLOOOWWW calender and task performanc​e

    My 8830 worked very well till recently(except that ringtones are almost inaudible).  When a reminder pops up, it takes 5 to 60 seconds to open, dismiss or edit a reminder.  This is not the way it used to perform. I have reset the BB - no effect.  I p

  • IPOD MINI&UPDATER PROBLEM!! THIS IS NOT NORMAL!!

    Hello guys I just downloaded the newest iPod updater 2006-01-10 for my brother's iPod mini. There was an update necessary. So then I install it, plug the iPod into my computer, and it determines that update is necessary. So I then update it. Normal r

  • Mapping: Time limit exceeded although we already tested successfully

    Hi everybody, we have a java-mapping where a large message has to be mapped. We tested already successfully. In another test we got a  error in SMQ2. So between the first and the second test, there must be any difference in the system. We did'nt chan

  • Where is Insert File Name?

    In pages 09, you can insert file name (Insert menu), e.g. into a header so that if you have hard copy, you know what file is called.