SQL Replication for IBCM (Full Version)

All Forums >> [Management Products] >> System Center Products >> System Center Configuration Manager



Message


egabrielson205 -> SQL Replication for IBCM (10/6/2008 3:28:22 PM)

I am setting up an infrastructure for IBCM and had a question regarding the replicated DB.  We are utilizing the scenario with the site server in the intranet and replicated DB in the DMZ with the MP/DP, SUP and FSP.  I am not well versed in SQL replication so I am not certain which publication type to use.  It would seem that transactional publication with updatable subscriptions is the ticket but I am concerned that this may not work.  The  firewall is configured to only allow outbound traffic to the DMZ servers and the site role servers are configured to accept only site server initiated communications.

So, I ask the folks in the know - which is correct/best publication type to use in this situation?

Thanks for your time.




sthompson260 -> RE: SQL Replication for IBCM (10/6/2008 5:43:29 PM)

If you choose this path, you'd set up the subscription in the DMZ as a standard pull subscription, daily update frequency. The main downside about using replication; it is difficult to make this site more secure... more secure, place a site server in the DMZ.




egabrielson205 -> RE: SQL Replication for IBCM (10/6/2008 6:25:15 PM)

Hmmm, based on the documentation on Technet:  http://technet.microsoft.com/en-us/library/bb693824.aspx the site server residing on the intranet side with a replicated DB in the perimeter network is the most secure as it keeps the site server completely free of Internet traffic and prohibits any traffic from the perimeter (DMZ) to the enterprise.  We've worked with our premier support a bit and they concurred this is the method we should use to be most secure.  How is placing the site server in the DMZ more secure?  I'm open to any suggestions so I am truly just asking for clarification not doubting your opinion.  [:)]

Thank you for the response.




sthompson260 -> RE: SQL Replication for IBCM (10/7/2008 6:58:52 PM)

This is most likely an "it depends" scenario, as you can make sites very secure by following best practices:
http://technet.microsoft.com/en-us/library/bb681065.aspx
http://technet.microsoft.com/en-us/library/bb694127.aspx

I'm not going to give you advice contrary to premier support, since ultimately you need to call them for support. Here are some points to consider:

What I do not like about using SQL Server replication?
- increases complexity for setup
- makes changes to your ConfigMgr table schema
- makes recovery far more complex

Further, if you are going to use replication, you need a license for SQL Server on your replica, it might as well be another site (imo).

In case you missed my link in the last email, here's how you'd configure SQL Server replication:
http://technet.microsoft.com/en-us/library/bb693697.aspx

Do you have a PKI infrastructure all setup?

Let us know which path you choose, and how it works out for you?




Page: [1]

Valid CSS!




Forum Software © ASPPlayground.NET Advanced Edition 2.4.5 ANSI
0.171875