myITforum.com Community Forum myITforum.com Community Forum

Home  Forums  Blogs  Live Support chat  Search Articles  Wiki  FAQ  Email Lists  Register  Login  My Profile  Inbox  Address Book  My Subscription  My Forums 

Photo Gallery  Member List  Search  Calendars  FAQ  Ticket List  Log Out

All Forums RSS Feed Subscription:


  


Rollout plan - wanted your thoughts

 
View related threads: (in this forum | in all forums)

Logged in as: Guest
  Printable Version
All Forums >> [Management Products] >> System Center Products >> System Center Configuration Manager >> Rollout plan - wanted your thoughts Page: [1]
Login
Message << Older Topic   Newer Topic >>
Rollout plan - wanted your thoughts - 9/24/2008 9:24:36 AM   
wbracken


Posts: 1036
Score: 22
Joined: 4/12/2002
From: St. Louis
Status: offline
So here's my layout today with SMS 2003:

1 Primary site server/DP at Corporate
6 Secondary sites/DP's across the US
Aprox 4000 clients
Using SMS 2003 OSD Feature Pack/BDD 2.5 for imaging at each site.
AD Schema is extended
Site Boundaries are soley based on AD sites
Discovery Methods - AD System Group Discovery, Heartbeat Discovery (All software distros are via machines in AD Groups)
Client install is handled mostly by the OSD process, however I also have a SMS Client Health machine startup script that will install/repair the SMS Client if missing or malfunctioning.  Client push is NOT enabled.

SCCM-
What I already have in place:
I installed a new SMS 2003 server, attached it to my primary as a child, let all objects replicate.  I then broke the parent/child relationship, ran some scripts to re-create folder structures, move eveything back into place, etc.  I then upgraded this server to SCCM (SP1/R2).
Both servers are effectively production at this point.  I have a specific subnet that I have added to the boundaries of the SCCM server that I have been using for the past few weeks to test application deployment and OS deployment.  Everything is just about where I want it so I am getting close to rolling this out.

My question comes in overlapping boundaries.  Right now I effectivly have an overlapping boundary already since my current "test" subnet is within the IP boundaires of my corporate AD Site.  This subnet is defined directly in SCCM boundaries and the AD site is the current boundary of my SMS 2003 server.  Since I dont have any Client Push enabled this has not been an issue. 

I would like to add ALL the corporate subnets to my SCCM Site boundaries so I can being full scale client upgrade testing before rolling this out to the remote sites.  See any reason why this would be a problem?  I sure cant think of any but would love to hear others thoughts on it.

Once its been tested I will then create new DP shares on the remote SMS servers and replicate all the packages to the new DP from SCCM.  I would then a site at a time:
Decommision the SMS Secondary site/DP.
Install a PXE Service Point
Setup the IP Helpers
A modified machine startup script to swing the clients over to the new SCCM Site code.

The end structure would be a Primary SCCM server at Corporate with DP's only at the remote sites.  Bandwidth at this point is not an issue.  We can live with DP's only for the time being.  Once ALL servers/clients have been rolled to SCCM I will then go back to each remote site and rebuild the server from the ground up (OS as well) and install a Secondary Site along with all the other roles resulting in a final config that mirrors my current SMS infrastructure..

Thoughts? 



_____________________________

William Bracken

Visit my new Blog
http://wbracken.wordpress.com/
Post #: 1
RE: Rollout plan - wanted your thoughts - 9/24/2008 12:30:26 PM   
nickmo

 

Posts: 32
Score: 0
Joined: 8/25/2008
Status: offline
Is your primary objective to simply test the SCCM client upgrade?  Or the entire process of upgrading individual sites?  I like what you're doing and plan to do something very similar when we upgrade to SCCM in the next couple of months.

I'm surprised there is not a conflict with clients on your test subnet.  I guess it's logical though since the the client has a different management point.

Side note - have you developed and tested your OSD/Task Sequence transition before you begin cutting over to SCCM?  Will you also be using MDT 2008?

_____________________________

nick

(in reply to wbracken)
Post #: 2
RE: Rollout plan - wanted your thoughts - 9/24/2008 12:54:03 PM   
tmiller


Posts: 665
Score: 18
Joined: 7/29/2003
From: Iowa
Status: offline
What I did to mitigate overlapping boundaries was to manipulate the permissions on the AD objects that SCCM published.  I made it so that only a certain security group had read access to all the objects that SCCM created in the Systems Management container in AD.  Then, for machines I was testing SCCM with, I added the comptuer account to the security group.  I also added a deny for that scurity group on the objects for the production SMS server.

I imagine that this is totally unsupported by MS, but it does work.  With this plan you can have the same boundaries defined for both the 2003 server and the 2007 test server.  The clients in the security group will see only SCCM and the other machine will continue to see only SMS. 

(in reply to nickmo)
Post #: 3
RE: Rollout plan - wanted your thoughts - 9/24/2008 1:53:37 PM   
wbracken


Posts: 1036
Score: 22
Joined: 4/12/2002
From: St. Louis
Status: offline
quote:

ORIGINAL: nickmo

Is your primary objective to simply test the SCCM client upgrade?  Or the entire process of upgrading individual sites?  I like what you're doing and plan to do something very similar when we upgrade to SCCM in the next couple of months.

I'm surprised there is not a conflict with clients on your test subnet.  I guess it's logical though since the the client has a different management point.

Side note - have you developed and tested your OSD/Task Sequence transition before you begin cutting over to SCCM?  Will you also be using MDT 2008?


This is for a complete rollout.  I am "pretty sure" the reason I dont have conflicts with my overlapping boundaries is that I am not doing any client push and my site assigment is explicit (Versus AUTO).  I even have SCCM Client machines on subnets that are not defined in SCCM yet.  The only thing they cannot do at the moment is find their DP since the DP resides in the subnet that is defined.  So the handfull of test machines that are not on the SCCM subnet still report to the SCCM server properly with inventory, policies, etc.  So am 98% sure this wont be an issue.

To answer your other question, yes I have fully developed and tested my OSD/Task Sequence process (using small bits of MDT 2008).  I am also going to continue using the PXEFilter that comes with MDT as teh out of teh box "Unknown Computer" support with R2 does not provide me with the flexability I get with the PXEFilter.vbs (For instance, I modified it to auto clear the last PXE advert so i dont have to go into the console aeverytime I want to PXE boot image a machine)

Thanks for the input!

_____________________________

William Bracken

Visit my new Blog
http://wbracken.wordpress.com/

(in reply to nickmo)
Post #: 4
Page:   [1]
All Forums >> [Management Products] >> System Center Products >> System Center Configuration Manager >> Rollout plan - wanted your thoughts Page: [1]
Jump to:





New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts



  
Forum Software © ASPPlayground.NET Advanced Edition 2.4.5 ANSI

0.234