Hi,
I've been reading documentation and community posts all day but I'm still not sure what the recommended approach is. I'm setting up an environment where I need to cater for devices which are frequently taken off-site, servers in the DMZ and internal LAN clients.
Info
- Management Server (and SUM): Internal LAN
- Message Relay (and SUM): DMZ
- Internal devices: Update and report to the management server directly. I see no reason to use the MR for this, unless I see performance issues later on.
- DMZ devices: Update from SUM on the MR (smb) and report via the MR. No secondary (as no Internet access and different mrinit.conf files internally).
- Laptops/Mobile devices: Update from SUM on the MR (HTTP) and report via the MR. Secondary update location would be Sophos. Disable location roaming.
Questions
- Using the configuration above, I will lose the ability to 'protect' laptop/mobile devices from the SEC unless I specify a 'initial install location' (but that's ok, as it would need to use the same credentials as my primary update location, which is HTTP). Is this correct?
- Any other comments/improvements on the above?
Cheers for any help.
This thread was automatically locked due to age.