advanced infrastructures in system center configuration manager 2012 r2 jason sandys @jasonsandys...

31

Upload: derek-perry

Post on 22-Dec-2015

250 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally
Page 2: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Advanced InfrastructuresIn System Center Configuration Manager 2012 R2

Jason [email protected]

Wally Mead@wally_meadwww.cireson.com

Page 3: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Best practices are guidelines allowing

newbies to NOT think about everything.

@damienkatz

Page 4: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

1 != 2

2007 != 2012

ConfigMgr 2007 != ConfigMgr 2012

ConfigrMgr 2007 Sites != ConfigMgr 2012 Sites

Page 5: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

To CAS or Not to CAS

Page 6: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Central Administration Sites

The Good

• Lots of managed clients

• Distributed Content

The Bad

• Does not provide high availability, redundancy, or site resiliency

The Ugly

• SQL Replication

• Administrative Latency

Page 7: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

CAS Scenarios

More than 100,000 managed Windows* clients

CAS

Geographically separated locations No CAS. Use secondary sites (if needed) and remote distribution points

Internal politics and whining Be the technical expert!

* See http://technet.microsoft.com/en-us/library/gg682077.aspx#BKMK_SupConfigClientNumbers

Page 8: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Remote Location

Fringe Scenario 1: Multiple locations, each with 10,000+ managed Windows clients

Secondary Site 2Secondary Site 1Primary Site

Page 9: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Fringe Scenario 2: Remote Content Creators

DP2

DP1

Primary Site

Page 10: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Fringe Scenario 2: Remote Content Creators

Primary Site 2

Primary Site 1

CAS

Page 11: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Nation B

Nation A

Fringe Scenario 3: National Politics

Primary Site 2

Primary Site 1

CAS

Distributed Views:• Some/most client

data not replicated to CAS

• Console and Reports dynamically query DB at primary site for info as needed

Page 12: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Remote Locations

Page 13: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Secondary Sites

YesProvide location aware,local site roles

Schedule and throttle client to (primary site) MPcommunication

No

Are resilient Manage clients

A managed client must be able to communicate with an MP in its assigned primary site.

Page 14: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Primary Site

Remote Location: Option 1, No Remote Infrastructure

MP

DP

WSUS

Content

*

* State & Status Messages, Hardware and Software Inventory

Update Catalog

Page 15: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Primary Site

Remote Location: Option 2, Remote DP only

MP

DP WSUS

DPPrimary Site Server

*

* State & Status Messages, Hardware and Software Inventory

Page 16: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Primary Site

Seco

nd

ary

Sit

e

Remote Location: Option 3, Remote Secondary

MP

DP WSUS

MP

DP

WSUS

Primary SiteServer

* Registration

*

Page 17: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

The Choice: DP vs Secondary Site

DPSecondary Site

Clients

Available Bandwidth

Page 18: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Site Role Placement and Client Location

Wally Mead
Not sure that the '(of Site Roles)' means anything to me in this title.
Page 19: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Multiple (Client Facing) Site Roles Within a Single Primary Site

Yes

High Availability Cross-forest

No*

Remote locations Segregated Networks

* The “No’s” on this slide are only applicable to MPs

Page 20: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

High Availability -- Not

CAS

Primary Site 1 Primary Site 2

Page 21: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

High Availability

MP DP WSUS

Primary Site Server

MP DP WSUS

Page 22: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Client Selection (within a Primary Site)

•Respects HTTPS/HTTP, forests, and domains•Random•3 failures leads to failoverMP• Respects HTTPS/HTTP, boundaries, subnets,

and fallback• Random within boundary group• 8-hour failover

DP• First installed• Respects forests• 3 failures leads to failover – no automatic

failback

SUP

Page 23: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Management Point Location Times

At client agent startup

Network change detected

Every 25 hours

Page 24: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

DMZs and Segregated Networks

Page 25: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Segregated Network: Option 1

Primary Site

MP

DP

WSUS

Content

*

* State & Status Messages, Hardware and Software Inventory

Update Catalog

TCP 80/443

TCP 80/443

TCP 8530/8531(80/443)

Page 26: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Secondary Sites are not Gateways

Primary Site

Seco

nd

ary

Sit

e

MP

DP WSUS

MP

DP

WSUS

Primary SiteServer

* Registration

* MP*

Requires R2 CU3

Page 27: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Primary Site

Dom

ain

or

Fore

st B

Dom

ain

or

Fore

st A

Segregated Network: Option 2a

DB

DP WSUS

MP

DP

WSUS

Primary SiteServer

MP

Page 28: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Primary Site

Segregated Network: Option 2b

DB

DP WSUS

MP

DP

WSUS

Primary SiteServer

MP

Page 29: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Multiple Hierarchies

Page 30: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

Multiple Hierarchies

Yes

Test, Dev, Lab Legal or National Politics

No

Administrative segregation Client segregation

Page 31: Advanced Infrastructures In System Center Configuration Manager 2012 R2 Jason Sandys @JasonSandys blog.configmgrftw.com  m Wally

EvaluationsPlease provide session feedback by clicking the Eval button in the scheduler app. One lucky winner will get a free ticket to the next MMS!

Platinum Sponsors

Gold Sponsors

Visit all of our sponsors in the expo area and online!