Asked by:
Solutions for SUP in untrusted forest ?

Question
-
we have two domains and the dmz is untrusted (atm around 150 systems)
before we had two primary sccm 2007 sites + central site with replication based on sender adresses - worked perfectly.
now because of sql replication we cant place a primary site system in the untrusted domain.
only standalone primary site would be possible but then we have no central reporting.
so we deployed primary site with additional dp and mp in untrusted forest like microsoft prefers for cross forest deployment.
now we want to deploy software updates to our dmz servers like before and here is the showstopper because sccm does not allow two sup in one site.
possible solutions ?
1. wait for sp1 because it allows multiple sups per site. really ? release ?
2. set all dmz clients / servers to internet-based and deploy certificates. not really !
3. install local wsus on "site server" in untrusted domain and manage patches outside sccm ? is fep 2012 pattern update possible without sccm ?
4. open internal primary site wsus for dmz systems so that they can check catalog through firewall but update from their local dp. rights problem on wus webserver ?
what would u prefer and why does microsoft canceled the option to connect untrusted domains like before (sql replication could be handled imo).
thx in advance
Tuesday, October 16, 2012 1:41 PM
All replies
-
You already mentioned 4 valid solutions; I'd prefer #4.
SQL replication needs Kerberos authentication. No trust -> no Kerberos.Torsten Meringer | http://www.mssccmfaq.de
Tuesday, October 16, 2012 1:52 PM -
1. wait for sp1 because it allows multiple sups per site. really ? release ?
Anoop C Nair - @anoopmannur :: MY Site: www.AnoopCNair.com :: FaceBook: ConfigMgr(SCCM) Page :: Linkedin: Linkedin<
Tuesday, October 16, 2012 1:55 PM -
i would prefer #4 too until sp1 is released but can the untrusted client access the "internal" wsus catalog ?
what account does the untrusted sccm agent use to connec to the internal sup ?
i need a workaround - can't wait till q1 2013.
- Edited by ITEvolution Tuesday, October 16, 2012 2:51 PM
Tuesday, October 16, 2012 2:29 PM -
Yes. WSUS requires no authentication for downloading the catalog -- it's completely anonymous to my knowledge.
Jason | http://blog.configmgrftw.com
Tuesday, October 16, 2012 2:50 PM -
I have just implemented #4 in a similar environment - works and only involves a FW change.
Kent Agerlund | My blogs: blog.coretech.dk/kea and SCUG.dk/ | Twitter: @Agerlund | Linkedin: Kent Agerlund | Mastering ConfigMgr 2012 The Fundamentals
Tuesday, October 16, 2012 4:20 PM