Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.

SCCM Cloud Management Gateway

1,434 views

Published on

This is slightly customised ppt used in BITPro event by Rajul OS.
Also the actual PPT is available here
https://mms2017.sched.com/event/AUbW/cloud-management-gateway-deep-dive
All credits to Aaron !
#BITPro

Published in: Technology
  • How we discovered the real reason nice guys don't get laid, and a simple "fix" that allows you to gain the upper hand with a girl... without changing your personality or pretending to be someone you're not. learn more... ♣♣♣ http://ishbv.com/unlockher/pdf
       Reply 
    Are you sure you want to  Yes  No
    Your message goes here
  • How to start a wildly profitable 7 figure marketing business and get your first commission check tonight, click here ♥♥♥ https://tinyurl.com/y3ylrovq
       Reply 
    Are you sure you want to  Yes  No
    Your message goes here
  • Stop getting scammed by online, programs that don't even work! ★★★ https://tinyurl.com/y4urott2
       Reply 
    Are you sure you want to  Yes  No
    Your message goes here
  • Get access to 16,000 woodworking plans, Download 50 FREE Plans... ▲▲▲ http://tinyurl.com/yy9yh8fu
       Reply 
    Are you sure you want to  Yes  No
    Your message goes here
  • Just got my check for $500, Sometimes people don't believe me when I tell them about how much you can make taking paid surveys online... So I took a video of myself actually getting paid $500 for paid surveys to finally set the record straight. I'm not going to leave this video up for long, so check it out now before I take it down! ▲▲▲ https://tinyurl.com/make2793amonth
       Reply 
    Are you sure you want to  Yes  No
    Your message goes here
  • Be the first to like this

SCCM Cloud Management Gateway

  1. 1. CLOUD MANAGEMENT GATEWAY Courtesy: Microsoft Corporation
  2. 2. SCENARIO AD CA Windows Update
  3. 3. INTERNET-BASED CLIENT MANAGEMENT AD CA Windows Update AD CA
  4. 4.  Manage traditional clients that roam on the Internet  Without additional infrastructure  Without exposing infrastructure to the Internet  That is easily configured through the Configuration Manager Console  Key features continue to work on the device when not on the corporate network  Software updates  Hardware and software inventory  Endpoint protection  Client notification  Settings  Applications PLAN TO SIMPLIFY
  5. 5. CLOUD MANAGEMENT GATEWAY AD CA Windows Update
  6. 6. CERTIFICATES  Management certificate  “Credentials” between site and Azure  Any certificate including self-signed  Public cert uploaded to Azure, .pfx with private key imports into site  Web Service (server authentication) certificate  Use public certificate provider (Symantec, Thawte)  Wild card certificate is not supported  Root/Subordinate certificate authority  Used by CMG for full chain validation on client PKI certificates  Client certificate
  7. 7. NETWORK PORTS  NO INBOUND PORTS REQUIRED! Source Port Destination Use Service Connection Point 443 Azure Deploy CMG CMG Connection Point 443 CMG CMG channel for first VM CMG Connection Point 10124-10140 CMG CMG channel for additional VM instances Client 443 CMG Client channel
  8. 8. SCALING CMG East US East Asia
  9. 9. PERFORMANCE CONSIDERATIONS  Any Internet-roaming client in the site will use the CMG  Reduce network latency by locating CMG, CMG Connection Point and Site Server in same geographic region  Client to CMG in Azure is not regional aware  For high availability, at least two VM instances and two CMG Connection Points per site  Scale-out by increasing VM instances, which leverages Azure load balancer in front of CMG  CMG does round-robin communication with multiple CMG Connection Points; creating more on-premises roles will distribute load
  10. 10. BEST PRACTICES AND FAQS  Publish Certificate Revocation List (CRL) to Internet  HTTPS is optional on-prem  Supports Azure US Government (Fairfax)  Unsupported features (as of 1710) • Azure Resource Manager • Client deployment using client push • Automatic site assignment • User policies • Application catalog • Full operating system deployment (OSD) • Configuration Manager console • Remote tools • Reporting website • Wake on LAN • Peer cache • On-premises Mobile Device Management • Mac, Linux, and UNIX clients • Task Sequence
  11. 11. TROUBLESHOOTING  Deployment:  CloudMgr.log  CMGSetup.log  Service health  CMGService.log  SMS_CLOUD_PROXYCONNECTOR.log  Client traffic  CMGHttpHandler.log -> CMGService.Log -> SMS_CLOUD_PROXYCONNECTOR.log
  12. 12. REFERENCES CMG Setup video  https://youtu.be/-awTBMdMHFE Product documentation  https://docs.microsoft.com/en-us/sccm/core/clients/manage/manage-clients-internet Cost estimates  https://docs.microsoft.com/en-us/sccm/core/clients/manage/plan-cloud-management- gateway#cost-of-cloud-management-gateway
  13. 13. QUESTIONS?

×