mhudson
Posts: 539
Score: 12 Joined: 4/1/2007 From: College Station, TX Status: offline
|
We have our laptops, home computers, and some individual computer sites (2 computers) using IBC. We have clients assigned to our central site. This is because we don't have the 1000's that you have. It is best not to for reporting, stress of the central site since it is already dealing with all the other primary sites. But this is all up to your HW, Internet, and structure. We have our WSUS and reporting on the same site. Just need to watch ports and setup WSUS on the alterative ports. Again load is a factor based on your enviroment. We don't have our Internet Based MP in our DMZ just because of the structure of our network. I know from others that if you have a MP in your DMZ you need to watch your ports and possibles the Certificate signing since you need to do some extra work for the DMZ. This also depends on how you have the MP setup. Just to let you know our laptops run in Interet only mode when out in the field. If they connect via vpn then the client knows this and switches to Intranet Only. Note: We have ALL public IP addresses for every computer on our network even VPN, we are in Higher Education. The setting up was a bit at first but the client is smart. My computer patched after I turned on my laptop in the airport 100's of miles away, very quickly. No lag.
_____________________________
Matthew Hudson http://sms-hints-tricks.blogspot.com/ http://www.sccm-tools.com
|