Management point location for workgroup clients in DMZ

Hi All,
I am trying to install the SCCM 2012 client to some servers that are located in a workgroup and in a DMZ at our organization.
I have read up about the config for this and I think that we have everything in place but the clients themselves are not locating a management point which I think is due to the setup of the IIS on the management points.
Firstly, I ammended the local hosts file on the system to ensure that the server could resolve the SCCM site server and 2 management points by using NetBIOS and FQDN. I also checked that the ports are opened from the client to the
management point.
I then ran ccmsetup using the following switches /noservice /mp=smsmp SMSSITECODE=XXX SMSSLP=SMSMP FSP=SMSSITESERVER CCMHTTPPORT=24555 CCMHTTPSPORT=24556 RESETKEYINFORMATION=TRUE which appers to have sucessfully installed the client
but is now failing to communicate with the MP specified. I am seeing on the client the following repeated in the locationservices.log
<![LOG[Raising event:
instance of CCM_CcmHttp_Status
            DateTime = "20141127153834.775000+000";
            HostName = "SMSMP";
            HRESULT = "0x87d0027e";
            ProcessID = 4004;
            StatusCode = 401;
            ThreadID = 5184;
]LOG]!><time="15:38:34.775+00" date="11-27-2014" component="LocationServices" context="" type="1" thread="5184" file="event.cpp:715">
<![LOG[Successfully sent location services HTTP failure message.]LOG]!><time="15:38:34.962+00" date="11-27-2014" component="LocationServices" context="" type="1" thread="5184"
file="ccmhttperror.cpp:396">
<![LOG[Error sending HEAD request. HTTP code 401, status 'Unauthorized']LOG]!><time="15:38:34.962+00" date="11-27-2014" component="LocationServices" context="" type="3"
thread="5184" file="util.cpp:2568">
<![LOG[Workgroup client is in Unknown location]LOG]!><time="15:38:34.962+00" date="11-27-2014" component="LocationServices" context="" type="1" thread="5184"
file="lsad.cpp:1078">
<![LOG[[CCMHTTP] ERROR: URL=http://SMSMP, Port=24555, Options=224, Code=0, Text=CCM_E_BAD_HTTP_STATUS_CODE]LOG]!><time="15:38:34.993+00" date="11-27-2014"
component="LocationServices" context="" type="1" thread="5184" file="ccmhttperror.cpp:297">
And on the management point I am seeing the following repeated in the IIS logs
x.x.x.x HEAD / - 24555 - x.x.x.x SMS+CCM+5.0 - 401 2 5 216 0
I understand that this points to the IIS authentication issue so I have tried browsing to http://smsmp.domainname.com/sms_mp/.sms_aut?mplist and
I do get a list of management points returned so I'm a little confused now. The other thing that confuses me is that we also have another domain we manage clients
in and these systems have all registered with the MP fine even though there is no trust relationship in place between the 2 domains.
I have checked anonymous authentication has been enabled on the SMS_MP virtual directory but I can see that it is set to use a user account of IUSR, but this is not a local user on the MP nor an AD user from what I can see.
Is anybody able to point me in the correct direction of either what I am doing wrong or which settings I should be checking?
Thanks in advance for any help
Andrew

You mention in your ccmsetup install properties: CCMHTTPPORT=24555 CCMHTTPSPORT=24556
While the MPList test you provided shows:
http://smsmp.domainname.com/sms_mp/.sms_aut?mplist
This is on port 80
Where is your MP? Port 80 or 24555 ?

Similar Messages

  • How to manage multiple locations for Item (Management warehouse locations)

    Is there any way, with UDF and Formated Search, to manage multiple locations for Item in the same warehouse
    I must have several (at least 2) locations for the item in the Warehouse and that  i enter in goods receipt and have track of this location and search possibilities at sales order by item and WHS.
    read carefully and imagine how (Management warehouse locations)
    I added a user table '@Location' who linked to a user field 'U_Location in Item master data --> lnventory data line and an ather user field 'U_Location' in sales order
    I met the value of location in the table (list of locations for any warehouse), I select the location of each item while receiving merchandise in the user field of inventory data line (Item M data) and this value appears in the sales order 'U_Location' user field ( only the location value in the default warehouse for this Item)
    or
    create an user field 'location' in Good receipt PO to fill it while receiving merchandise that appears in the sales order to give possibility to find/select the location of the item at this order and in Item master data
    I think we will use all these tables and there is a relationship between all.
    @LOCATION
    PDN1
    OITM
    OITW
    OWHS
    RDR1
    a piece of code has been proposed, but it is not so simple
    SELECT T0.U_Location FROM [dbo].[OITM] T0 WHERE T0.ItemCode = $[$38.1.0]
    Thanks,
    Ouchen

    I believe you are talking about defining BIN's (locations) within a Warehouse.
    This is quite possible and has been explained / discussed on this Forum a few times in the past.  Though I am completely clear on how you would like to implement this I could give you some guidelines..
    Creating a @location UDT is correct to maintain list of warehouse locations
    UDF in Items - Warehouses (Item Master ..Inventory Data Tab..Rows)
    UDF in Marketing Document Rows (When you add a UDF here U_Location then this will available in all marketing documents, both AR and AP)
    You will define a location for an Item in the Item Master....
    In the GRPO..you can use FMS to list the location/s for the Item being received from the Item Master and the User can Select it.
    In the Sales Order, you can select the location from which the Item could be picked..
    Let me know if your process / ideas are different
    Suda

  • Installation sccm client on workgroup client in DMZ

    Hi Guys,
    i tried to install the sccm client on workgroup clients in a DMZ environment.
    First I created a client certifikate for the workgroup client on the sccm server and installed the certifikate on the workgroup computer with certutil.exe.
    commandline for installation:
    ccmsetup.exe /usePKICert /NOCRLCheck SMSMP=servername.bla.com SMSSITECODE=BLA
    i get this errors in the ccmsetup.log:
    Unexpected row count (0) retrieved from AD.
    Failed to get site version from AD with error 0x80004005
    thanks for your support,
    Chris

    Refer these Pls
    http://eskonr.com/2013/08/sccm-configmgr-2012-manage-workgroup-computers-for-deploymentremote-tools-etc/  (An Excellent article)
    Client installation in DMZ step by step :
    http://myitforum.com/cs2/blogs/cstauffer/archive/2009/02/06/sccm-client-install-in-a-dmz.aspx
    http://blogs.technet.com/b/keithmayer/archive/2012/07/30/planning-system-center-configuration-manager-across-dmz-and-protected-subnets-sysctr-configmgr.aspx
    http://nikifoster.wordpress.com/2011/01/31/installing-configmgr-clients-on-servers-in-a-dmz/
    Thanks, Prabha G

  • What process manages XA transaction for Corba clients?

    Hello,
    what process manages the XA transactions on behalf of Corba clients?
    Is it ISL itself? Or should there be a transaction manager associated with the group that includes ISL? Or is a TM automatically associated with the ISL?
    Here is an excerpt of the ubbconfig:
    *GROUPS
    SYS_GRP
    LMID = "s1"
    GRPNO = 1200
    APP_GRP
    LMID = "s1"
    GRPNO = 1300
    OPENINFO= "Oracle_XA:..."
    CLOSEINFO= "Oracle_XA:..."
    TMSNAME = "TMS_ORA"
    TMSCOUNT = 6
    Q_GRP
    LMID = "s1"
    GRPNO = 3700
    OPENINFO = "TUXEDO/QM..."
    TMSNAME = TMS_QM
    TMSCOUNT = 6
    *SERVERS
    ISL
    SRVGRP = SYS_GRP
    SRVID = 1010
    CLOPT = "-A -- -O -n //s1:4101 -d /dev/tcp"
    SEQUENCE = 140
    MIN = 1
    MAX = 1
    TMQUEUE
    SRVGRP = Q_GRP
    SRVID = 3200
    GRACE = 0
    RESTART = Y
    CONV = N
    MAXGEN=10
    CLOPT = "-s TuxQSPACE:TMQUEUE -- "
    SEQUENCE = 180
    MIN = 21
    MAX = 21
    SvrApp
    SRVGRP = APP_GRP
    SRVID = 6100
    RESTART = Y
    CLOPT = "-A -- ..."
    SEQUENCE = 250
    MIN = 9
    MAX = 9
    The client uses a Corba object in SvrApp. SvrApp uses the DB and a Tuxedo queue.
    The client uses the TransactionCurrent object in the ISL to start and finish the transaction. SvrApp uses TMS_ORA to handle the DB part of the transaction, and TMQUEUE uses TMS_QM to handle the queue part of the transaction. What coordinates the overall transaction?
    Thanks...
    Roger

    Hi Todd,
    we have been able to collect system call information with tusc. It appears that at times the client process is spinning on a semop() call. We only have a few samples, and they show 0, for or 6 semop() calls just before the commit.
    Here is an excerpt from the tusc log:
    1307433992.346554 gettimeofday(0x7fffd0f8, NULL) .................................... = 0
    1307433992.346685 write(13, "0 7 - 1 0 : 0 6 : 3 2 . 3 4 6 ".., 119) .............. = 119
    1307433992.347194 semop(516140, 0x7fffd210, 1) ...................................... = 0
    1307433992.348095 semop(516140, 0x7fffd250, 1) ...................................... = 0
    1307433992.350263 semop(516140, 0x7fffd080, 1) ...................................... = 0
    1307433992.350408 semop(516140, 0x7fffd0c0, 1) ...................................... = 0
    1307433992.350495 time(NULL) ........................................................ = 1307433992
    1307433992.351105 msgsnd(2414006, 0x406be6e8, 300, IPC_NOWAIT|0) .................... = 0
    1307433992.351375 time(NULL) ........................................................ = 1307433992
    1307433994.046557 msgrcv(2839780, "0 \0\005\0\0\0Z \0+ T e4\0\0\0\0".., 5476, 805306373, 0) = 248
    1307433994.047046 gettimeofday(0x7fffd118, NULL) .................................... = 0
    1307433994.047336 write(13, "0 7 - 1 0 : 0 6 : 3 4 . 0 4 7 ".., 115) .............. = 115
    The writes to socket 13 are our debug logging. The timezone is GMT + 2; 1307433992 is 10:06:32. Below is our debug logging.
    07-10:06:32.345 (InfXaTransactionManager.cpp@[InfXaTransactionManager] 99) Entering InfXaTransactionManager::commit
    07-10:06:32.345 (InfXaTransactionManager.cpp@[InfXaTransactionManager] 55) Entering InfXaTransactionManager::getCurrent
    07-10:06:32.346 (InfXaTransactionManager.cpp@[InfXaTransactionManager] 55) Leaving InfXaTransactionManager::getCurrent
    07-10:06:34.047 (InfXaTransactionManager.cpp@[InfXaTransactionManager] 99) Leaving InfXaTransactionManager::commit
    Roger

  • How to manage one wsp and dll for multiple clients in farm environment

    1. There is a product which is developed using C sharp , jquery,CSS and sharepoint object models which have been packaged into .wsp file. Whenever we introduce new functionality to the product we used to branch the
    previous code as a version , say Version 1.0 and new functionality of the product will in another solution. This is how we are managing the code in TFS as versions. Each newer version will have new functionalities. We do not give latest functionality for all
    the clients. Each client is having its own version of functionality. Technically in order to access the functionality, the wsp solution should be present in the solution repository which is available in SharePoint central administrator site. This solution
    will be deployed on the client’s site. We are following the above process in SharePoint standalone installation where we used to purchase dedicated server per client and installed sql, SharePoint foundation 2010 as standalone installation and adding the client
    related version of the code to the solution repository. Later host on the site which is created for that client purpose. This process is same for all the clients where we purchase individual server for each client .
        Now we want to host our product in farm environment of sharepoint foundation 2010 where we are going to try 3 level architecture. 
    • SQL Server-In this sever we are going to install sql server 2008R2 standard edition. Which should serve the database service for all the web applications/sitecollections which we are going to create in Web front end server.
    • Application server- In this server we are going to install the sharepoint as farm and will install search server express for serving search functionality for our product
    • Web front end server- In this server we are going to add this server to Sharepoint farm which we have created in application server. Here we are going to create web applications and site collections for all the clients.
    In this scenario how to manage multiple versions of same wsp solution?
    Another major issue w.r.t the architecture of the product and new approach for client deployment as follow.We have CSS, jquery files for serving the functionality.These files have been mapped to 14 hive folder.If any changes we do one of the jquery file or
    css file which is meant for latest version and not for old version, then how to manage this new functionality for that particular css or jquery file in 14 hive folder, since there is only one 14 hive folder. What is the best practice to make this happen? Another
    thing is, how to manage dll files for individual client?

    It sounds like you have a farm scoped solution at work. In that case you can only have a single instance of it per farm, you'd have to branch each version so they appear to be seperate solutions entirely (thus ruining your clients upgrade process).
    Bluntly i don't think a single farm can manage all your user environments.

  • Unable to change reference point location while using the Transform Functions in Photoshop Elements 6.0.

    Unable to change reference point location while using the Transform Functions in Photoshop Elements 6.0.

    Which operating system are you using?
    In photoshop elements 6, as far as i know, you can only change the Reference Point Location for transforms using the small grid in the left hand corner of the tool options bar with Transform enabled.

  • DMZ Client Deployment failing. Unable to find Management Point

    I'm trying to install SCCM 2012 R2 client to a server in our DMZ.  This server is in a workgroup.  I have been following this article
    http://nikifoster.wordpress.com/2011/01/31/installing-configmgr-clients-on-servers-in-a-dmz/ however the SCCM agent doesn't seem to be able to find the Management Point, which is on the internal LAN.
    Step so far
    1) Port 80 and Port 8530 opened on the firewall between the DMZ server and the Primary site server (bi-directionally).
    2) Host and LMHost file on the DMZ server updated with the IP address of the Primary site server (where the MP is located).
    3)Boundary created on the Primary site server to include the IP address of the DMZ server.
    4)Client install files copied locally to the DMZ server.
    5)Installed with the following command ccmsetup.exe /MP:servername SMSSITECODE=ABC DNSSUffix=contoso.com
    The client installs but does not pick up the correct site code.  On the site tab the settings are blank and I can't manually update them.  In the locationservices.log it looks like it assigns the server to the correct site and then the following
    error appears Failed to retrieve DNS service record.... Unable to to find Lookup MP in Registry,AD, DNS and WINS.
    I'm not using Certificates.  The DMZ server IP address can be resolved from the Management Point (which is the site server) and the DMZ server will resolve the Management Point address.
    Does anyone have any ideas what I've missed?
    Thanks in advance

    Also note the difference between /mp and SMSMP:
    http://blog.configmgrftw.com/ccmsetup-mp-and-smsmp/
    Both are required in this case.
    Jason | http://blog.configmgrftw.com | @jasonsandys

  • Manage SCCM 2012 clients in DMZ (OS Deploy, Windows updates) via DP/MP

    Hi,
    We ’d like to manage (=OS Deploy, Packages,Windows updates) Windows clients (Windows 2008/2012 R2 servers for now, about 20 of them) in a DMZ (= different domain).
    There is this article
    https://nikifoster.wordpress.com/2011/01/31/installing-configmgr-clients-on-servers-in-a-dmz/ which explains what to do … in 2011. Since then lots of things are changed I guess
    Before I dive in, I’d need to have an overview + do some administrative tasks (like asking for firewall accesses).
    Current setup DMZ:
    Our SCCM 2012 R2 server is on a Windows 2008 R2 OS
    Client communication is done via HTTP (not HTTPS)
    An extra physical Distribution point is setup (only DP, nothing more) in our current domain
    A new Windows 2012 server is setup in the DMZ which should host the DP and probably management point (since it should manage the clients over there)
    There are clients in DMZ that are currenlty managed by SCCM 2007 but 
    this server will be phased out, these client have:
    Correct sccm functionality
    Correct DNS resolution
    My steps/questions, please comment:
    Add the DMZ ip range to SCCM 2012 boundary as “DMZ”
    Add the network access account to be able to deploy as well clients as distribution point in DMZ
    In the DMZ accesses on firewall for server VLAN have to be asked
    When we have a distribution point and communication is “HTTP only” then http (port 80) from DMZ to sccm server should suffice, correct? Or are
     extra firewall openings needed for management point access/packages and windows updates sync?
    Now the sccm clients will be deployed to the servers in DMZ: deploy SCCM clients to hosts in DMZ, how this should be done: we connect a console to the SCCM-server in the DMZ then deploy the discovered clients?
    OS Deploy should be made available, but no dhcp is available in DMZ and it is not an option either, therefore we would boot from an ISO then enter an ip (or pre-enter it so there is already filled in an ip?). So tasksequences/deployments
    for servers in DMZ, where are they configured/deployed then? Via console access on DMZ management point or can we deploy on our domain SCCM management point (not in DMZ) and it will be synced to the DMZ management point? Not clear
    Selective sync of software to this distribution point (howto? not sure), we don’t need any Windows 8 software/drivers to be synced.
    Thanks for your input!
    J.
    Jan Hoedt

    No comment;
    I think you mean the client push installation account and the site system installation account;
    More ports are required, see site server > distribution point and distribution point > management point from the provided link;
    The console will always be connected to your primary site server. The client will be pushed from the primary site server and it will provide the initial files. The other files will be downloaded from the local distribution point;
    The task sequence deployment will be just like a normal taks sequence deployment. The only difference is the location of the server;
    Only the content that's distributed to the distribution point in the DMZ will be available on that distribution point.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • Client communication port for workgroup servers

    We have SCCM 2012 R2 Single Primary Site in intranet. We have PKI with ADCS 2012. We are in process of mirating to HTTPS communication using certificates. We have few servers in workgroup and we plan to manage those servers with configuration manager by
    manually installing client and specifying smsmp=sccm fqdn. for lookup management point. 
    Can we change client communication port for these servers?
    For successful client communication do we need to open any ports except 443 in firewall?
     What all ports needed to be open in this scenario?

    Hi,
    You configure the Communications port for the MP in the site so they must use the same ports, you can configure alternate ports so if it cannot communicate on port 443 it tries the next port.
    http://technet.microsoft.com/en-us/library/gg712276.aspx
    443 is sufficient, the client will also try to communicate on port 10123 for Client Notification,
    http://www.google.se/url?sa=t&rct=j&q=&esrc=s&source=web&cd=1&ved=0CCsQFjAA&url=http%3A%2F%2Fblogs.technet.com%2Fb%2Fconfigmgrteam%2Farchive%2F2012%2F09%2F27%2Ffast-channel-for-system-management.aspx&ei=1dAhU7qqOIL8ygPb1IHQAQ&usg=AFQjCNF4_G2sZBMbDDtJa95LBx7EYYBrRw
    But it should fallback to 443 if not available as well.
    Regards,
    Jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • Internet based management point on workgroup comuter

    Hi
    I have a question about internet based site system (mp and dp and maybe sup). I already have primary site and i want to install another site system with mp/dp/sup for internet clients on server in DMZ which is not in active directory. It is in regular workgroup.
    Is it possible or it has to be joined to domain??? For security reasons i would prefer if it wasnt in domain.
    Thx in advance.

    All site systems have to be domain-joined.
    Torsten Meringer | http://www.mssccmfaq.de

  • Internet based management of SCCM clients and management points ?

    We have an SCCM backend infrastructure which is used to manage what is in affect multiple external organizations over the internet.  Currently each SCCM client is managed by the primary server directly over the internet. 
    Am I right that we could place a configmgr management point on the internal networks and for the clients to talk to this server when connected to the company network instead of all clients getting patched across the internet connection ?  Meaning that
    just the MP would communicate with our backend infrastructure ?

    So your internal clients are now connecting over the internet to the local MP? How does this setup look like exactly? How were the clients installed (parameters)?
    Torsten Meringer | http://www.mssccmfaq.de

  • Management point and Distribution point behind netscaler for virtual ip/dns name

    Is it supported to place a server behind a netscaler for using a virtual IP/DNS name?
    We are looking into placing our distribution points and management points behind the netscaler to provide firewall functionality.
    We would point our clients to a different DNS name for each individual MP and DP to provide routing through the netscaler.
    As far as I know this is only possible using IBCM.
    Please let me know if this is possible without IBCM internally.

    Using a different DNS name is problematic as there is no way to specify an alternate fqdn for a site system on the intranet. Clients use the actual fqdn of the system hosting the role; this is given out by the MP directly to the client based upon the site
    system's actual name.
    You could manipulate name resolution in a variety ways so ultimately the actual IP used wouldn't matter, but that's useless unless the client is using the proper name.
    If you you could use the same name and IP, then it should work no problem as long as the traffic is properly delivered to the site system. Ultimately, nearly all client agent to site system traffic is nothing more than WebDAV via IIS on the site system so
    just basic web traffic.
    Jason | http://blog.configmgrftw.com | @jasonsandys

  • Configure SUP location for IBCM (Internet Only) Clients

    I'm using ConfigMgr 2012 R2 with a single primary site.   I have a second site server deployed in the DMZ configured
    for Internet  clients.  I have a Internet MP and DP configured with SSL and they are working well. 
    I have a question about how to configure the SUP for internet only clients.   I configured my internet facing SUP to require SSL and configured it for Internet and Intranet clients.
    I installed the ConfigMgr 2012 client on my test machines with the CCMALWAYSINF=1 option to be connected internet only.  
    The clients are not getting a local policy to connect to the SUP and if I add the internet SUP in the local group policy myself it doesn't do anything.  If I run the "windows updates" cycle from the Windows Update client (NOT
    ConfigMgr) it seems to connect and sync with the SUP (WindowsUpdate.log) but ConfigMgr does not appear to recognize the SUP and doesn't point the clients to connect to it and upload the results.  
    Any Ideas how to force my clients to connect to the internet facing (IBCM) SUP to scan for required updates?  Anybody deploy a internet SUP lately that can provide some guidance?  Thank you very much

    Check the log file(s) on the Internet facing site system. The easiest method to check the sync status is by going to the monitoring workspace in the console and then look at the
    Software Update Point Synchronization Status node.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • How to assign clients to alternate management point

    Hi Guys
    Does anyone know how to reassign clients to another management point on the same site.
    We have 3 seperate locations connected by a vpn, our main site has a primary site server with the management point role and the other 2 locations are just distribution and management point servers.
    I have built another distribution /management point server as the primary server site location as i want to take some of the roles of the primary site server as its overloaded, all my clients at this site are already assigned to the primary site server management
    point but want to assign them to the new distibution/management point at the same site.
    Was going to uninstall the management point role of the primary site server so that just my new server would have this role at this location, if i do this will the cleints automatically assign themself to the only available management point at this site
    or will they break.

    The clients always request a list of available MPs. If you deinstall a MP it will not be on that list anymore, so the clients will automatically go to another available MP.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • Boundary Group for site assignment, shall I add My "Management Point" as a "Site System Server" in "References"

    Hi,
    We have an flat singel site.
    Boundary Group for site assignment, shall I add My "Management Point" as a "Site System Server" in "References"
    /SaiTech

    Yes - if it's also a DP?
    The servers are added as content location servers for this boundary group. Only servers that have a distribution point or state migration point installed on them are available.
    Gerry Hampson | Blog:
    www.gerryhampsoncm.blogspot.ie | LinkedIn:
    Gerry Hampson | Twitter:
    @gerryhampson

Maybe you are looking for

  • Macbook pro retina and Fullscreen mode freeze

    Hi I cant get fullscreen playing in FCP 7 on Macbook pro retina mid 2012 running 10.8.3mountain lion It wil show only a stil image and not play the video live. This happens on the macbook, and on external monitor, in all display settings available in

  • Running ME2M in the background - display variant

    Hello all, I try to run ME2M (purchasing report) in the background and receive the result with specific display variant. Does anybody know how I can tell the system to show the results with specific fields, not all of them ? Thanks, Isaac

  • Jdbc to rfc to jdbc scenario is not working

    Hi... We have done the JDBC to RFC to JDBC scenario using BPM, it was working fine in the last month. now we started testing the same scenario, that is not working. In SXMB_MONI it is showing only sender data is successful, it is not showing any RFC

  • My Macbook Pro won't open Photoshop CS6 ever since I installed OS X Mavericks. What should I do?

    Also, I haven't seen any updates for OS X Mavericks on the app store, though maybe I'm wrong? I'm just really frustrated and disappointed with this update and would be willing to even uninstall it if I knew how.

  • Firefox tries to download same file every time I open it

    I have downloaded a virus from depositfiles.com and after the download finished my antivirus program have deleted the file, but now every time I start firefox my eset smart security pop up with the message that firefox again tries to download this vi