One primary site with a remote DP/MP, or two with a CAS server?

Hi
For a new SCCM 2012 environment, we have the following setup:
- HQ site with 1500 PCs/users
- Branch office in a separate AD site, slow WAN link, 120 PCs/users
Now, I'd like to keep the setup simple so my first instinct is to deploy one primary site with a server in the branch office fulfilling the MP/DP/PXE/Update Point roles.
However, the site has a local technician who needs the ability to deploy images to the local machines. Running the console from the branch office to the HQ site is not an option, since consoles (such as ADUC) have very poor performance over the WAN.
This brings me to the option of either a primary HQ site with a branch secondary site (something I'd like to stay away from, since it requires SQL and the technician would still need to connect the console to the primary site anyway!), or 2 primary sites both
connected by a CAS server. For what the technician needs, I think this is overkill, and I don't like the idea of the added complexity, or keeping both sites in-step as far as replication is concerned.
Im leaning towards the 1 primary site, remote MP/DP option, but Im not sure how the technician would image machines without the console. I thought perhaps creating an optional advertisement to a dynamic collection that he could control another way (e.g.
using a registry key), giving him the option to trigger deployments.
Thoughts?

Having a local DP will ensure that all deployments are made locally if the content is distributed.
You'll have to get your content there first, if possible build your DP in your main office and ship it to the remote location after. Otherwise use prestage content. Getting GB of stuff throught that link will otherwise take days.
For your deployment, why does the technician need access to the console  ? Could you deploy to "unknown computers" ?
Benoit Lecours | Blog: System Center Dudes

Similar Messages

  • Capitalization doesn't work as described. One can start with lower case and change to upper, but changing from upper case to any of the other options doesn't work. Is there a way around this or is this just a glitch that needs fixing?

    In Pages capitalization doesn't work as described. One can start with lower case and change to upper, but changing from upper case to any of the other options doesn't work. Is there a way around this or is this just a glitch that needs fixing?

    I think it does work as described, but the description is not very complete. Capitalization does not change any of the characters that you type; what it does is allow some of the lower case characters to display as capitals. If you copy the result and paste it as plain text, you'll see that the lower case characters are still there. It doesn't actually say anywhere that it can make capitals display as lower case, and it can't.
    The obvious way around this is to actually type what you want.
    The more powerful way is to install WordService from Devon Technologies which adds the functionality of Pages' capitalization menu as well a lot of other ones. WordService actually changes the character to the one displayed, and it works in most of the applications on your Mac.

  • Single Primary Site with CAS

    Hello,
    I have a client with a single primary site server and a CAS. It was installed for some reason, doesn't really matter now why.
    They have two options, leave it up or migrate to a new Primary Site server.
    The questions is, if they leave it up (It's not needed or used), what harm will it do?
    Yes, I know it will make the site simpler to manage but other than that? What would compel them to go through the hassle of a migration to a new server?
    Thanks!
    John

    Short answer:  get rid of it.
    There are a host of complications introduced by having a CAS and it should really only be done if the environment demands it (massive device management count for example).
    In addition to patching complication increase and SQL replication monitoring you now have to do:
    1.  Many roles will need to be installed multiple times.  Example WSUS will be required to be installed on the CAS with a secondary on the Primary for proper functionality.
    2.  Some roles will be required on the CAS, some will be required on the Primary site.  If you aren't well-versed in your SCCM this can be a frustrating path of discovery.
    3.  Then there are roles that _can_ be installed in both locations but don't have to be ... like the reporting server.  This one comes down to login policies and if people will ever log directly into the PRI or just CAS box.
    All these architectural complications come before the "why" is asked ... which is usually driven by one of two things:
    1.  In SCCM 2012 RTM, the CAS had to be installed first or you could never use it.  Some clients did this to avoid potential problems.  This requirement has sense changed.
    2.  In 2007, people used to use multiple primaries as security boundaries.  With SQL replication, collections being uniform across all sites, and the general inclusion of RBAC .... this is now moot.
    Basically don't use CAS unless it absolutely fits the company.  It's a lot more pain than just "one more VM".

  • Synchronizing Disaster Recovery site with the production server

    Hi All,
    One of the customer is asking the following query:
    "How Disaster recovery site can be synchronized with the production server and how do they switch? Will the web logic server do this for them?"
    This customer is having two sites one live and one a DR (Disaster Recovery) site on different location.
    Can somebody answer my query?
    Thanks in advance.,
    Regards.,
    Naveen

    Firstly
    Is your Datagaurd Physical( Redo Apply) or Logical( SQL apply)?
    Does it have Datagaurd Broker?
    When Datagaurd is setup in your environment - on the primary database( live database) the Datagaurd users LGWR or/and ARCH process to collect redo data and ship this data to standby ( DR site) and the FAL process to provide client-server mechanism for shipping archived logs to standby.
    On standby database, The Datagaurd users RFS process to receive redo records from primary database, the MRP process applies redo information to standby database.
    If the Data Gaurd Broker is enabled, Datagaurd also used DMON process to manage and monitor both primary and standby databases as a unified configuration.
    When there is any connectivity issue to the standby and when connection is re-established, the accumulated archive logs are automatically shipped and apploed to stanby, until stanby is resynchronized with the primary. This process does not require any administrative intervention.
    If there is a very large Archive Gap between the primary and secondary due to some major issue. Then the unshipped archive logs need to be shipped manually from primary to standby and needs to be applied in standby to sync up with primary. For some reason there will also arise rare issues like problem with not applying of archive logs though log shipping is success. So some work arround will solve it.
    Comming to planned /unplanned outages of production site.
    Datagaurd has Failover and Switchover( planned ) methods, These are not automatic, but have to be explicitly initiated by the administrator( So there will be downtime but minimal). Once initiated, Datagaurd automates the processes involved.
    - S K A
    Edited by: user12297346 on Jan 27, 2010 7:13 AM

  • Problem with ONE SINGLE site with WRT610N

    Hello,
    First, sorry for my very poor English
    I have a Linksys WRT610N with firmware  1.00.03 B15 (latest I think)
    Last three days I have trouble connecting to a single website. This site is www.bdgest.com
    I can access all other sites I want, but that one is very difficult to access, very slow with timeouts and error 404 messages.
    When I connect to my modem with a cable, everything is OK. If I connect with a cable or wifi to the Linksys router, the access is weak. The problem is not my PC because I have the same problem with my I-Pod touch.
    I don't made any change to the Linksys configuration.
    Can somebody help me ?

    I found another site that goes weak. www.enviedeseduire.fr 
    The TRACERT informations for both sites are VERY interresting :
    tracert enviedeseduire.fr
    Détermination de l'itinéraire vers enviedeseduire.fr [91.121.76.160] avec un maximum de 30 sauts :
    1 8 ms 1 ms 1 ms 172.16.1.1
    2 14 ms 24 ms 15 ms 10.89.128.1
    3 13 ms 8 ms 11 ms 78.129.127.113
    4 17 ms 17 ms 12 ms 212.68.211.2
    5 16 ms 16 ms 16 ms 212.68.211.29
    6 36 ms 14 ms 22 ms 212.68.211.133
    7 14 ms 11 ms 15 ms 195.219.227.5
    8 14 ms 19 ms 13 ms 195.219.227.14
    9 20 ms 20 ms 16 ms if-10-1-1-0.tcore1.PVU-Paris.as6453.net [80.231.153.69]
    10 21 ms * 27 ms th2-5-6k.fr.eu [213.186.32.245]
    11 * * * Délai d'attente de la demande dépassé.
    12 29 ms 29 ms 105 ms rbx-g1-a9.fr.eu [91.121.215.133]
    13 111 ms 22 ms * rbx-2-6k.fr.eu [213.186.32.234]
    14 * * * Délai d'attente de la demande dépassé.
    15 23 ms 24 ms 22 ms ns25848.ovh.net [91.121.76.160]
    Itinéraire déterminé.
    tracert bdgest.com
    Détermination de l'itinéraire vers bdgest.com [87.98.152.92] avec un maximum de 30 sauts :
    1 7 ms 1 ms 1 ms 172.16.1.1
    2 11 ms 9 ms 11 ms 10.89.128.1
    3 10 ms 12 ms 8 ms 78.129.127.113
    4 18 ms 17 ms 17 ms 212.68.211.2
    5 62 ms 9 ms 13 ms 212.68.211.29
    6 19 ms 11 ms 17 ms 212.68.211.133
    7 13 ms 16 ms 16 ms 195.219.227.5
    8 91 ms 14 ms 15 ms 195.219.228.1
    9 20 ms 21 ms 17 ms if-10-1-1-0.tcore1.PVU-Paris.as6453.net [80.231.153.69]
    10 * * * Délai d'attente de la demande dépassé.
    11 * * * Délai d'attente de la demande dépassé.
    12 30 ms 29 ms 28 ms rbx-g2-a9.fr.eu [91.121.215.151]
    13 38 ms 24 ms 24 ms rbx-s3-6k.fr.eu [213.186.32.166]
    14 22 ms 30 ms 28 ms 87-98-152-92.ovh.net [87.98.152.92]
    Itinéraire déterminé.
    Everything goes wrong after both  if-10-1-1-0.tcore1.PVU-Paris.as6453.net [80.231.153.69]
    Any idea ?

  • Entered username for site with wrong case. Because spelling is correct Firefox keeps changing entry to what I entered 1st time. I cannot log in.

    In this case I entered harkdog, but my username is HarkDog. I can no longer enter anything other than harkdog in the username field - including the one I just used to set up an account in FireFox Help. I may type HarkDog, but harkdog is automatically entered.

    Please do the following.<br><br>
    #Click the orange Firefox button, then click Options | Options | Privacy.<br><br>
    #In the History menu, use the dropdown menu to change the setting to "Use custom settings for history".<br><br>
    #Underneath that, remove the checkmark from "Remember search and form history".<br><br>
    #In the same menu, click the "Show Cookies" button.<br><br>
    #Find the site where the problem occurs and delete the cookie for it.<br><br>
    #Click OK to close the menu.<br><br>
    #Click the orange Firefox button and go to History, then "Clear Recent History".<br><br>
    #In the menu at the top, change the setting to "Everything".<br><br>
    #Click the arrow immediately underneath that one and remove the checkmark from "Browsing and Download History", "Cookies" and "Site Preferences", leaving only "Cache" and "Active Logins" checkmarked.<br><br>
    #Click the "Clear Now" button (''it might take a minute or two to clear'')<br><br>
    #Close Firefox and restart it again.<br>
    If you want Firefox to retain your nick when you change it, go back to the menu in step 3 and replace the checkmark.<br><br>
    If this suggestion resolves the problem for you, please click the '''Solved it''' button next to this post after you log in into the forum. This will help others searching for a solution to the same problem.
    Thanks.

  • Can any one help me with this chat server

    The code below is of a client and server but the problem is that the msg can be sent only from the server and not the client I want that whenever a msg is sent from the server the control for writing the msg should go on to the client n den vise versa n should continue till the connection is terminated..plz help me....!
    CoDES
    for client
    import java.io.BufferedReader;
    import java.io.IOException;
    import java.io.InputStreamReader;
    import java.net.InetAddress;
    import java.net.Socket;
    import java.net.UnknownHostException;
    class client {
    public static void main(String[] args) throws IOException {
    Socket s =null;
    BufferedReader b=null;
    try{
    s=new Socket( InetAddress.getLocalHost(),98);
    b=new BufferedReader(new InputStreamReader(s.getInputStream()));
    catch(UnknownHostException u) {
    System.err.println("i dont know host");
    System.exit(0);
    String inp;
    while((inp=b.readLine())!=null){
    System.out.println(inp);
    b.close();
    s.close();
    FOR SERVER$
    import java.io.BufferedReader;
    import java.io.IOException;
    import java.io.InputStreamReader;
    import java.io.PrintWriter;
    import java.net.ServerSocket;
    import java.net.Socket;
    import java.nio.channels.ServerSocketChannel;
    public class server {
    public static void main(String[] args) throws IOException {
    ServerSocket s1=null;
    try{
    s1=new ServerSocket(98);
    }catch(IOException u1)
    System.err.println("could not find port 98");
    System.exit(1);
    Socket c=null;
    try{
    c=s1.accept();
    System.out.println("connection from"+c);
    catch(IOException e)
    System.out.println("accept failed");
    System.exit(1);
    PrintWriter out=new PrintWriter(c.getOutputStream(),true);
    BufferedReader in=new BufferedReader(new InputStreamReader(c.getInputStream()));
    String I;
    BufferedReader sin=new BufferedReader(new InputStreamReader(System.in));
    System.out.println("i am ready to type now");
    while((I=sin.readLine())!=null) {
    out.println(I);
    out.close();
    sin.close();
    c.close();
    s1.close();
    }

    What you need is to have two loops running at the same time. One for receiving messages and other for waiting user input. This can be done by using separate threads.
    For example after client has made connection to server, start a new thread that runs loop for receiving messages from the socket and printing them to System.out. Then in the default thread start loop for reading users input. The server could have similar structure.
    So, what I think you are looking for are threads.

  • Can we assign 2 IPs for a SCCM 2012 primary site server and use 1 IP for communicating with its 2 DPs and 2nd one for communicating with its upper hierarchy CAS which is in a different .Domain

    Hi,
    Can we assign 2 IPs for a SCCM 2012 primary site server and use 1 Ip for communicating with its 2 DPs and 2nd one for communicating with its upper hierarchy CAS . ?
    Scenario: We are building 1 SCCM 2012 primary site and 2 DPs in one domain . In future this will attach to a CAS server which is in different domain. Can we assign  2 IPs in Primary site server , one IP will use to communicate with its 2 DPs and second
    IP for communicating with the CAS server which is in a different domain.? 
    Details: 
    1)Server : Windows 2012 R2 Std , VM environment .2) SCCM : SCCM 2012 R2 .3)SQL: SQL 2012 Std
    Thanks
    Rajesh Vasudevan

    First, it's not possible. You cannot attach a primary site to an existing CAS.
    Primary sites in 2012 are *not* the same as primary sites in 2007 and a CAS is 2012 is completely different from a central primary site in 2007.
    CASes cannot manage clients. Also, primary sites are *not* used for delegation in 2012. As Torsten points out, multiple primary sites are used for scale-out (in terms of client count) only. Placing primary sites for different organizational units provides
    no functional differences but does add complexity, latency, and additional failure points.
    Thus, as the others have pointed out, your premise for doing this is completely incorrect. What are your actual business goals?
    As for the IP Addressing, that depends upon your networking infrastructure. There is no way to configure ConfigMgr to use different interfaces for different types of traffic. You could potentially manipulate the routing tables in Windows but that's asking
    for trouble IMO.
    Jason | http://blog.configmgrftw.com | @jasonsandys

  • Delegating administration for several primary sites

    Hi everybody again!
    Could you tell me, can one primary site admin help out in managing clients to other primary site admin. I've noticed that altought i granted him access to that site collection he could see only it's count not members....

    I understand that deployment will bring up to all of these collections members.....but i won't see them in collections, it will not be able to use remote tools, resource explorer and etc....How should we work with other site collection members till we can't
    see them?)))) I thought that RBA model makes users to work (i mean visibility of that computer resources) with any resources in hierarchy not in primary site only...
    Torsten, you've made discuss about that here:
    http://social.technet.microsoft.com/Forums/en-US/49894f4a-ccb4-462b-b58a-6718889c73fb/need-clarification-about-collection-resources-in-sccm-2012-compared-to-2007?forum=configmanagerapps
       

  • Using a custom certificate store for SCCM 2012 clients and primary site server

    I have read what seems to be all the pki related documentation out there for SCCM 2012. I have a PKI infrastructure up and running issueing certificates with an offline root through group policy autoenrollment. The problem that i'm faced with is we are migrating
    from SCCM 2007 that was in native mode and we chose not to use the CA that we used for the old SCCM environment. When the clients attempt to communicate with the M.P. it runs through all of the different certificates and adds a tremendous amount of overhead
    to the M.P. We will have ten's of thousands of clients by migration end. Could someone please point me to a document that goes over how to leverage a custom certificate store that I could then tell the new 2012 environment to use? I know that it's in there,
    I've seen it in the console. The setup is one primary site server with SQL on box and the pki I just mentioned as well as the old 2007 environment that is still live.
    I read that you can try and use SAN as a method of identifying the new certs but I haven't found a good document covering exactly how that works. Any info you could provide I would be very grateful for. Thanks.

    Jason, thank you for your reply. I'm getting the impression that you have never been in the situation where you had to deal with 2 different PKI environments. Let me state that I understand what your saying about trust. We have to configure the trusted root
    CA via GPO. That simply isn't enough, and I have a valid example to backup this claim. When the new clients got the advertisement and began the ccmsetup process I used the /pki switch among others. What the client end up doing was selecting a certificate that
    had the longest validity period which was issued by our old CA. It checked the authentication chain, found it to be valid and selected it for communication. At that point the installation failed, period, no caveats as you say. The reason the install failed
    because the new PKI infrastructure is integrated into the new environment, and the old is not. So when you said " that
    are trusted and they can use *any* cert that is trusted because at the end of the day, there is no
    difference between two valid certs that have the same purpose as long as they are trusted. "
    that is not correct. Both certs are trusted, and use the same certificate template, but only one certificate would allow the install to complete successfully.
    Once I started using the CCMCERTISSUERS
    switch the client install went swimmingly. The only reason I'm still debating this point is because someone might read this thread see your comments and assume "well I've got my new PKI configured as a trusted root CA, I should be all set" and their
    deployment will fail, just as my pilot did.
    About Intune I'm looking forward to doing a POC in the lab i built with my Note 3. I'm hoping it goes well as I really want to have our MDM migrated into ConfigMgr... I think the
    biggest obstacle outside of selling it to management will be the actual device migration from the current MDM solution. From what I understand of the enrollment process manual install and config is the only path forward.
    Thanks Jason for your post and discussion.

  • SCCM Primary Site installation fails

    Hello!
    In my organization we have two domain/forests. DomainA.local and DomainB.local
    in one forest (DomainA.local) we have sccm 2012 sp1 CAS site. with dedicated database server on sql 2012 sp1 cu5
    in other forest (DomainB.local) we want to setup primary site on sccm 2012 sp1 with dedicated database server on sql 2012 sp1 cu5
    forests have trust both sided.
    all installation accounts have administrative rights on all SC servers. in both domains.
    when i try to install SCCM 2012 primary site in the hierarchy,
    i receiving the errors:
    INFO: Created SQL Server machine certificate for Server [S-SCDB-02.DomainB.local] successfully.
      ERROR: Failed to open certificate store (HRESULT=0x35)    Configuration Manager Setup    9/3/2013 11:56:19 AM    3268 (0x0CC4)
    ERROR: Failed to write S-SCDB-02.DomainB.local SQL Server certificate to store (TrustedPeople) on site server (S-SCDB-01.DomainA.local).
    ERROR: Failed to write certificate of primary site's SQL Server [S-SCDB-02.DomainB.local] to CAS SQL Server [S-SCDB-01.DomainA.local].
    Install user from domainB.local has administrative rights on S-SCDB-01.DomainA.local and sysadmin rights in sql server.
    Also, it has full administrator role on CAS.Of course, it has administrative rights on primary site server and sql server S-SCDB-02.DomainB.local and sysadmin rights.
    WHY????

    >Taking a step back: why? Are you using a CAS and multiple primary sites at all? Do you have 100,000+ clients to manage?
    we need CAS due to our network infrastructure.
    thank you for you help.
    we solved problem today.
    it was need to open "windows" ports on the firewall between SCCM Primary Site server and CAS SQL server to give SCCM
    primary site installation process the ability to install the primary site's sql-server's self-signed certificate to CAS sql-server trusted people local store.
    i did not remember this point in deploying documentation((((

  • Customer reference has two identical primary site uses

    This customer reference has two identical primary site uses
    defined in RA_CUSTOMERS_INTERFACE. Please update the SITE_USE_CODE
    field or the PRIMARY_SITE_USE_FLAG so that only one primary site use exists per customer and site use code.
    Thanks in advance

    Check Note: 181622.1 - Customer Interface Imports Multiple Shiptos For A Customer With No Site Use Code
    https://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=181622.1

  • SCCM 2007 - All clients from primary site have vanished from central site collections

    Hi all,
    we have a SCCM 2007 R2 setup with one central site, one Primary Site (A) with a secondary site hanging off it and another Primary Site (B). Suddenly all the clients from the Primary Site A (and also it's Secondary Site) have vanished from the central
    site. All the clients are still present when we check Collections from the admin console on Primary Site A site server - they have simply disappeared when we check Collections from the Central Site admin console.
    Can anyone provide any info on a good starting point for troubleshooting this issue? As a sidenote, we can still push packages out to the Primary Site A distribution point and both the Primary and Central site can communicate/ping each other.
    Any help/info would be much appreciated!
    Thanks

    Check the
    site replication on central site, is that SQL is working fine, and also see the
    inbox folder in central site, might be there is backlog and those DDR files are
    not processing, and after maintenance they got deleted.<o:p></o:p>
    please run
    the heartbeat discovery by hour or day, and once the clients will sent all the
    DDR files then they will appears again.<o:p></o:p>
    Sharad Singh | My blogs: SharadTech | Twitter:
    @SinghSharaad | | Please remember to click “Mark as Answer” on the post that helps you.This can be beneficial to other community members reading the thread.

  • Logical Standby & Primary site Time Diiference

    Hi,
    I have the one primary site over RAC configuration and one Logical standby
    Site.We have configured the Logical standby for archived files. We would like to
    know, how can we compute the time difference between Primary Site and Logical
    Site ex. IF suppose some SCN XYZ is applying on logical standby site so when
    the same SCN (XYZ) generate (time) on the primary site. We need exact time
    difference between Primary site and Logical Site.
    If there is any query or other method pls suggest to find out this information.
    Thanks, Dewan

    Hi,
    From memory, I use this:SELECT
         TO_CHAR(MIN(TIME),'YYYY-MM-DD HH24:MI:SS') OLDEST,
         TO_CHAR(MAX(TIME),'YYYY-MM-DD HH24:MI:SS') NEWEST,
         MAX(TIME)-MIN(TIME) DELTA FROM
    SELECT L.SEQUENCE# SEQ, L.FIRST_TIME TIME,
        (CASE WHEN L.NEXT_CHANGE# < P.READ_SCN THEN 'YES'
              WHEN L.FIRST_CHANGE# < P.APPLIED_SCN THEN 'CURRENT'
              ELSE 'NO' END) APPLIED
      FROM DBA_LOGSTDBY_LOG L, DBA_LOGSTDBY_PROGRESS P
      ORDER BY SEQUENCE#
    WHERE APPLIED != 'YES';Regards,
    Yoann.
    PS: This does not work for Archived Redo Logs not yet sent to Logical Standby:
    Message was edited by:
    Yoann Mainguy

  • Clients getting updates from Primary Site~~~SCCM 2012 R2

    Hi Guys,
    I have one Primary site and 3 DP, And there are lots of branch and we have enable branch Cache using GP.
    But i have observed some of my clients not getting updates from respective DP they are directly coming on primary site  for updates. In my environment ADR is running for updates.  
    My boundaries groups and boundaries correctly configured .
     Thanks

    boundary  active site wise setup...
    In  client
    LocationServices.log DP details not showing .

Maybe you are looking for

  • Purchase register

    Hi, Can anybody tell me why purchase register report is needed in business.? What is similar type of report availbale in R/3 and BI ? Thanks and Regards Anil Patil

  • Blue screen of death what does it mean????

    Hi. Pc normally runs like a dream, no problems, no hanging and no errors. Today I was recording a family video to dvd (fr AVI file on pc) When i came back to the pc i had the blue screen of death , with the error  saying "Bad_Exhandle"           0x00

  • Outlook 2007 Calendar Monitoring: track send event for recurring meetings

    Hi, I'm working on an Outlook 2007, VSTO 2010, .NET 3.5 add-in which monitors AppointmentItem objects changed on the user's calendar. Specifically I'm tracking the send event of the currently selected appointment in the calendar view. Currently my ad

  • Project manager can't find my songs

    I have well over 100 song files on one of two internal sata drives in my mac pro. "SATA A" has my sample libraries. "SATA B" contains all my song files and audio recordings. I want to use project manager to help identify what samples I have used with

  • Creating a hyperlink in a form to send to an email

    I'm pretty new at using Adobe Acrobat 9 Standard and I'm trying to make a form to put on my company's website.  I want to create a hyperlink that will submit the form to my email once a client has fill it out.  I have been testing it and sending the