SCCM 2012 role out to secondary site - what network links do I need

I'm just doing the SCCM design for a service provider and I'm struggling to understand what connections I need to  secondary SCCM sites. There are 10 sites which have about 1000 computers per site. Do I need dedicated links into each
sites and do they need to be VPNs? What do I ask the network manager for?
Louis
 

Note that secondary sites are *not* gateways for client traffic. Clients must still be able to communicate with an MP in the primary site. Thus, generally secondary sites are a terrible option for segregated networks. Secondary sites are designed for remote
locations where there are no explicit traffic restrictions, just bandwidth limitations.
As for dedicated links, not sure what you mean there. As long as the traffic can traverse the network, per the ports in the link posted by dekac, ConfigMgr (like all applications) doesn't care or even know about how that traffic gets from point A to point
B.
Jason | http://blog.configmgrftw.com | @jasonsandys

Similar Messages

  • SCCM 2012 - Change Distribution Point's Site System Properties Site Code

    Hello All,
    I'm hoping someone can help me out. Here's what I have and here's what I'm trying to do.
    SCCM 2012 R1 
    Each of our offices has a Windows 7 SP1 Ent PC that is a distribution point for that office's 10-20 machines. A number of these offices and their DPs were setup prior to me setting up a number of Secondary Site Servers. So right now, these DPs' site codes
    are the primary site server's. I'd like to change these to one of the Secondary Site Servers.
    When I go to the Site System properties of one of these Win7 distribution points, the Site Code is grayed out.
    So, the question is, how can I change one of these DPs' site codes?
    Thanks in advance to whomever helps!!
    Bill

    That's a strange reason for using Secondary Sites. How many clients are you managing? Have you good WAN links?
    Gerry Hampson | Blog:
    www.gerryhampsoncm.blogspot.ie | LinkedIn:
    Gerry Hampson | Twitter:
    @gerryhampson

  • SCCM 2012 client push occurs from site server or from distribution point?

    I would like to set up client push in SCCM 2012 and I have a remote site with about 80 workstations that I would like to deploy the clients to using client push, but this remote site is VERY slow, as in less than 3Mbps slow. There is a remote DP located
    at this site and I wanted to know if the remote workstations will be hammering my Site Server across the WAN (or MP I guess since the MP role is i installed on the Site Server) to request the client installation, or do the clients just request the client from
    the Site Server or MP and then the client downloads to the remote DP and then the workstations install the SCCM 2012 client from the local DP at the remote site?
    I just do NOT want the WAN link to become overwhelmed with workstation requests to install the client and have the Site Server have to respond to each and every workstation and download the SCCM 2012 client to each system over this slow WAN link. 
    How does the client push process actually work?
    Thank you

    The initial files will come from the primary site server. The rest (the biggest part) will come of the distribution point. See for a good read (even though it's more about secondary sites), this post of Jason:
    http://blog.configmgrftw.com/secondary-sites-and-boundary-groups/
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • CCMSETUP not updating on SCCM 2012 SP1 CU3/CU4 primary site

    I have a SCCM 2012 SP1 CU3 primary site and i can't upgrade the local installed SCCM Client.
    The error I get in ccmsetup.log is:
    <![LOG[MSI: Setup was unable to register the CCM_Service_HostingConfiguration endpoint
    The error code is 80041002]LOG]!><time="15:44:22.408-60" date="02-08-2014" component="ccmsetup" context="" type="3" thread="2496" file="msiutil.cpp:300">
    <![LOG[MSI: Action 15:44:22: Rollback. Rolling back action:]LOG]!><time="15:44:22.562-60" date="02-08-2014" component="ccmsetup" context="" type="0" thread="2496" file="msiutil.cpp:314">
    <![LOG[File C:\windows\ccmsetup\{59A0EA77-D28C-4286-83A6-04BB57B9CDD6}\client.msi installation failed. Error text: ExitCode: 1603
    Action: CcmRegisterHostingConfiguration.
    ErrorMessages:
    Setup was unable to register the CCM_Service_HostingConfiguration endpoint
    The error code is 80041002
    ]LOG]!><time="15:45:00.798-60" date="02-08-2014" component="ccmsetup" context="" type="3" thread="2496" file="msiutil.cpp:872">
    <![LOG[Client installation has failed too many times. Ccmsetup will now abort.]LOG]!><time="15:45:00.830-60" date="02-08-2014" component="ccmsetup" context="" type="3" thread="2496" file="ccmsetup.cpp:7941">
    <![LOG[Successfully deleted the ccmsetup service]LOG]!><time="15:45:05.831-60" date="02-08-2014" component="ccmsetup" context="" type="1" thread="2496" file="ccmsetup.cpp:3320">
    <![LOG[InstallFromManifest failed 0x80070643]LOG]!><time="15:45:05.831-60" date="02-08-2014" component="ccmsetup" context="" type="3" thread="2496" file="ccmsetup.cpp:7086">
    <![LOG[CcmSetup failed with error code 0x80070643]LOG]!><time="15:45:05.832-60" date="02-08-2014" component="ccmsetup" context="" type="1" thread="2324" file="ccmsetup.cpp:10544">
    I have this on my primary and secondary servers as well.
    Is upgrading to R2 recommended and will that solve this issue ?
    When googling to this issue i found that there is a solution for this: remove MP, upgrade Client, install MP.
    But this is my primary and secondary and on secondary i am not allowed to remove the MP. It is hardcoded enabled.

    Try the following steps to specify the hotfix when installing the client.
    1. Open an elevated command prompt.
    2. Run a command line similar to the following – if CU3 has already been installed, the MSP file below should be on the site server, in the
    \\servername\SMS_SITE\Client\hotfix folder:
    \ccmsetup.exe PATCH=\Configmgr2012ac-sp1-kb2882125-x64.msp 
    Juke Chou
    TechNet Community Support

  • SCCM 2012 Database Replication Monitor Child Site Details Empty

    We have a Secondary site for which no data will show up under Monitoring/Database Replication/Replication Status/Child Site.  It just states "No items found." as seen in the attached pic.  All other secondary sites show various configuration parameters,
    etc. on the Child Site tab.  What is blocking CM 12 from getting this information for this particular child site?  Any ideas?  Something firewall or access related maybe?

    was there any solution to this? I am having the same issue with the same version of Config Manager.

  • OSD: TS deployed to Vista SCCM 2012 client, reboots then doesn't find network drivers

    Hi,
    We deploy SCCM 2012 client to a SCCM 2007 Vista pc.
    We then deploy a task sequence to install Windows 7.
    Everything works fine on a vm, it reboots in winpe then starts the task sequence. On a laptop however, it does not work. F8 shows it does not get an ip address, it seems as if no network adaptor is recognized.
    However, the same task sequence works fine on the same laptop when pxe booting + I added the driver to winpe. Didn’t help. Please advise.
    J.
    Jan Hoedt

    I think I know what the root cause is, but not how to solve it.
    In diskpart, I can see 3 volumes:
    *Volume 0 = D-drive, DVD-rom,
    *Volume 1 = no drive letter, partition of 400 GB
    *Volume 2 = C-drive, label "Configuratio", type "removable" 4 GB
    It should install to the 400 GB drive but it seems that its installing to the removable drive.
    Not sure what that is since there is no USB attached. Probably it is the winpe temporarely mounted(?)
    The behaviour I have is described
    here and is also referring to USB.
    => I guess I have to tell the temporarely mounted drive to be f.e. Z when installing in full OS.
    Any idea howto do this?
    J.
    Jan Hoedt

  • SCCM 2012 deploy windows 7: how to manage network/server load?

     Hi,
    Hypotetically, if you would deploy Windows 7 to hundreds of pc’s at once, how could you manage that, regarding organizing the deploy, regarding network/server load? F.e. you deploy to a collection which has 500 pc’s, users can select when
    to load the OS (Windows XP, we deploy the SCCM 2012 client, they can choose when to install)
     *How can you be sure network is not overloaded?
    *Can you limit in SCCM 2012 bandwith usage?
    Please advise.
    J.
    Jan Hoedt

    You need to be as local as possible. You can host a deployment point role on a client OS such as windows 7 so you could temporarily setup one machine hosting OS images and then rebuild it last as well.
    On a 100MB LAN with DP's hosted in a datacenter (not on subnet) we get to about 75 machines building at once before we see TFTP timeouts on PXE booting due to load on the local network. I would get your build as quick as possible and then do them in increasing
    block sizes whilst monitoring the network and server load.
    To speed up builds you could...
    Build and capture to get a WIM file with most apps and updates in it.
    Change the TFTPBlockSize registry settings on the DP's (If PXE booting) to as high as it will go
    Host WIM files on your DP's with the Package share settings configured and enable the "Access content directly..." option in the Apply Operating System part of your task sequence.
    Hope this helps.
    Shaun

  • Network times out on my Windows 7 Lenovo when trying to load IOS 5 on my iPad 2 what network settings do I need to change?

    When I try to upgrade my iPad 2 to IOS. 5 on my Lenovo PC it says the connection had timed out. I have disconnected the firewall and check the connection through the troubleshooting guide on the PC. Can someone tell me what network settings I need to change to make this work? Also iTunes is also up to date on this PC. If I cannot get this to work is there another way I can do a direct update to my iPad?  Thanks so much

    Try temporarily turning off all your firewall and antivirus software until the download has completed.
    An alternative is to try downloading the update via a browser : https://discussions.apple.com/message/16703914#16703914

  • SCCM 2012 Replication between Central Admin Site and all Primary Sites is failing

    Let me start by saying I have made a mistake and now I am paying for it and attempting to fix it. All of our SCCM servers are virtual and exist on an ESX environment. The mistake I made is I restored our Central Admin Site from a backup without also
    restoring the two Primary Sites at the same time. Now the databases between the sites simply refuse to synchronize. I can run the Replication Link Analyzer until I'm blue in the face and even though the data gets replicated once, the replication immediately
    breaks and fails after that.
    Regrettably I no longer have access to backups that would take me back to a point where the three servers were happy. The problem there is our ESX administrator only keeps a limited number of backups per server (we have in excess of 180 virtual servers in
    our ESX environment) and the backups from a point in time where they worked is no longer available.
    As I have said I have tried running the Replication Link Analyzer many times. I have also tried going into the SQL server console and running the stored procedure spDrsSendReplicationInvalid.
    Can anyone provide me with any assistance on how best to restore replication between the Central Admin server and the two Primary servers?

    http://blogs.msdn.com/b/scstr/archive/2012/05/31/how_2d00_to_2d00_site_2d00_server_2d00_recovery_2d00_central_2d00_or_2d00_primary.aspx
    Just an addition: the option called "Recover central administration site:
    Then specify the FQDN of a
    Reference primary site" is the one to try first.
    Torsten Meringer | http://www.mssccmfaq.de

  • SCCM 2012 roles on 2008 storage server

    Hi all,
        hopefully a fairly quick one for those in know.
    Is installing a DP supported on 2003 and 2008 storage server?
    In the supported config document @
    http://technet.microsoft.com/en-ca/library/gg682077.aspx - storage server is listed as a supported client, but not listed as all in the site systems area.

    Yes that should be Fine.
    The following table specifies the operating systems that can support multi-function site system roles.
    Operating system
    System architecture
    Distribution point<sup>3</sup>
    Management point
    Windows Vista
    Business Edition (SP1)
    Enterprise Edition (SP1)
    Ultimate Edition (without service pack, or with SP1)
    x64
    √<sup>1, 2</sup>
    Not supported
    Windows 7
    Professional (without service pack, or with SP1)
    Enterprise Editions (without service pack, or with SP1)
    Ultimate Editions (without service pack, or with SP1)
    x86, x64
    √<sup>1, 2</sup>
    Not supported
    Windows Server 2003 R2
    Standard Edition
    Enterprise Edition
    x86, x64
    √<sup>2</sup>
    Not supported
    Windows Server 2003
    Standard Edition (SP2)
    Enterprise Edition (SP2)
    Datacenter Edition (SP2)
    x86, x64
    √<sup>2</sup>
    Not supported
    Windows Server 2003
    Web Edition (SP2)
    Storage Server Edition (SP2)
    x86
    √<sup>2</sup>
    Not supported
    Windows Server 2008
    Standard Edition (SP2)
    Enterprise Edition (SP2)
    Datacenter Edition (SP2)
    x64
    √<sup>2</sup>

    Windows Server 2008 R2
    Standard Edition (without service pack, or with SP1) 
    Enterprise Edition(without service pack, or with SP1)
    Datacenter Edition (SP1)
    x64


    <sup>1</sup> Distribution
    points on this operating system are not supported for PXE.
    <sup>2</sup> Distribution
    points on this operating system version do not support Multicast.
    <sup>3</sup> Unlike
    other site system roles, distribution points are supported on some 32-bit operating systems. Distribution points also support several different configurations that each have different requirements and in some cases support installation not only on servers,
    but on client operating systems. For more information about the options available for distribution points, see Prerequisites
    for Content Management in Configuration Manager in the Deploying
    Software and Operating Systems in System Center 2012 Configuration Managerguide.

  • HT4972 What network settings do I need to set in order to update my older IPAD.  I has IOS 4.3.3

    I am trying to update my IPAD from iOS 4.3.3 to 5.  I get an error message that I have to reset my network settings?  Where do I do this and to what settings?

    Settings>General>Reset>Reset Network Settings. All that does is make you start from scratch meaning that you will have to join all of your WiFi  networks again, enter passwords, etc. I'm not sure that I've ever heard of this error but it has been years since I was running iOS 4.3.3.
    Anyway, that is where resetting network settings can be found.

  • SCCM 2012 Secondary site some client's are scan hardware inventory for more than 30 days

    Hi, 
    In our SCCM 2012 environment we have secondary site configured which connected with 8500 computers, on those 5500 machines scanning hardware inventory and send latest inventory details to Secondary Site Management Point, but remaing 3000 machines are not
    sending latest hardware inventory for more than 30 days. I verified clients log  found it is generating report on inventory agent.log however it is not available with secondary site Management Point.
    Are anyone experienced this issue, please share your thought how to fix this issue.
    Thanks in advance. 
    Madhan

    Yes i did verify but the client isn't listed on both log files. Also i couldn't open IIS log because of it size has more than 800MB. currently this site has connected with 8500 machines do you think these many clients are supported by secondary site server. 
    If you can't open the IIS log then how do you know that the Client's IP is not listed within them?
    5000 is the max for a secondary site. You will need to secondary sites at this location.
    http://technet.microsoft.com/en-us/library/gg682077.aspx#BKMK_SupConfigClientNumbers
    Garth Jones | My blogs: Enhansoft and
    Old Blog site | Twitter:
    @GarthMJ

  • Uninstall and Reinstall Secondary Site Management Point Role

    Dear Brothers,
    I have an issue with one of my SCCM 2012 Sp1 with CU3 Secondary Site Server which the client failed to install on the actual server due to a client issue observed in the CCMSetup.log.
    Observation Regarding the issue:
    Issue Detail No1.
    SCCM Client is not installing to my Secondary Site Server with site code (XYZ), after all the site server are also clients in SCCM hierarchy so it self needs SCCM Client as well. 
    CCMSetup.log:
    "Error 25150. Setup was unable to register the CCM_Service_HostingConfiguration endpoint" when you try to install the client agent in Configuration Manager"
    According to http://support.microsoft.com/kb/2905359
    the solution is to :
    1. Uninstall the management point role. 
    2. Reinstall the client agent on the management point computer. 
    3. Reinstall the management point role.
    Issue Detail No 2.
    When I am trying to uninstall the Management Point Role via SCCM Console as part of the solution posted on the above KB Article, unfortunately the delete or uninstall option is been greyed out.
    Now a lot of discussion on the topic "Can not remove management point role is greyed out "under this thread
    http://social.technet.microsoft.com/Forums/en-US/1a039893-4a65-4dc9-9feb-e6f09ea1fc0b/can-not-remove-management-point-remove-role-is-greyd-out?forum=configmanagerdeployment
    However on the last comment of the above thread from"Trana010"
    stated a tool or a command
    C:\program files\Microsoft Configuration Manager\bin\x64\rolesetup.exe /deinstall /siteserver:(sec server name) SMSMP
    0
    Which I never tried yet, and also cannot find a reliable KB supporting the command "rolesetup.exe".
    Questions:
    1. What is the best way to uninstall/Reinstall the management point on secondary site considering the above issue details?
    2. Should I installed CU4 directly instead? Maybe it will resolved the issue even though it is not related to the current case
    Regards,

    Well, it's by design that you can't remove a management point on a secondary site, so I can imagine that that's why there is nothing "official" written on that subject. I think there are three things you can do:
    Try to run the command line (which is probably unsupported)
    Submit a CSS call
    Upgrade to CU4 and assume the problem is gone.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude
    Dear Peter,
    I end up shooting a case with CSS, he guided me and share that this issue is very common.
    The reason is that it requires CU3 upgrade (Configmgr2012ac-sp1-kb2882125-x64.msp) to be installed with the SCCM Client installation (The same time) via command line in an elevated permission.
    Follow the solution provided by Microsoft Support:
    CCMSetup.exe /forceinstall SMSSITECODE=XYZ CCMENABLELOGGING=TRUE CCMLOGLEVEL=0 PATCH=C:\Configmgr2012ac-sp1-kb2882125-x64.msp
    It seems the Client Push provided by SCCM 2012 Sp1 Infra, that includes your Hotfix under the "Hotfix" folder under the client source folder somehow doesn't work with this issue, that's why the work around is to help the ccmsetup to grab the Hotfix with
    by providing the path for the hotfix instead of relying to take the hotfix for the hotfix folder.
    Overall peter thanks for your suggestion. And also to Mr. Jason Sandys opening the option for an R2 upgrade, I will look into the KB for this to plan for implementation. 
    Regards,

  • Huge Sized download taking place at port 8530 between clients and WSUS\SUP of secondary site

    Hi Guy's
    Need a solution to the issue, the SCCM 2012 clients under a secondary site { Secondary site with SUP\WSUS } are downloading 200Mb + data at port 8530. This seems quite abnormal.
    Need to know answer of below
    1- Actual size of catalog what clients should download or path where on WSUS is stored
    2- How to restrict a huge sized download between WSUS and CM 2012 client
    This is not the case where clients are directly reporting to Primary size.
    Regards
    Sushain Kapoor
    Regards Sushain KApoor

    Hi Jason
    Just a little clarity, will the client download information for a particular product or all the products selected in wsus.
    Eg: Windows 7 systems will download the catalog information of Windows 7 only against selections made in WSUS. Or it will download the windows XP and windows vista and other product information also. This particular question i am asking as i see only 300
    updates as found in windowsupdate.log and not the thousands synced in WSUS
    Is the update metadata exported using the wsusutil.exe the actual catalog size what clients are downloading
    Regards Sushain KApoor

  • SCCM 2012 SP1 - Multiple SUP - common WSUS DB

    Hello,
    Is it supported / recommend to share a common WSUS DB for multiple WSUS / SUP roles ?
    If yes, how to perform a clean deployment of additional SUP dealing with additional KB requirements.Following article explains the problem but the solution looks very complex: http://scug.be/sccm/2012/10/03/configmgr-2012-sp1-installing-multiple-software-update-points-per-single-primary-site-and-use-a-single-shared-wsus-database-on-your-sql-cluster/
    I tried to test this procedure in my test environment but it broken WSUS and now refuse to sync with Microsoft (can't establish SSL connection).
    I have not been able to find any official Microsoft setup guide for this ?
    As an alternative, is it possible to sync additional SUP as downstream servers with the first one. I ask for this because I use SCUP, and I don't want to maintain multiple WSUS environment.
    Regards.

    Hi.
    We have the same problem with our WSUS 3.0 SP2 installation, when I install WSUS on an SCCM 2012 server in the "Secondary Site".
    That server is in a different domain (one way Trust); but I have Logged On to that server with an specific account from the Top Domain that has Owner rights on the excisting DB). The Installation connect's succcesfully to the DB, and on the
    Next Window I get the error "The existing DB is not compatible with this version of Windows Server Update Services 3.0 SP2"
    The first two Wsus Installations  in the "Top" domain worked just fine.
    Anyone an idea?

Maybe you are looking for