Monday, November 25, 2013

SCOM DMZ agent

Nowadays, there are a lot of great articles about this topic and we think that is not necessary to write a step-by-step article explaining how to run a Windows agent on the DMZ or out of the domain of SCOM server.

Here are some great examples of these articles explaining how to deploy a DMZ agent:
http://pkjayan.wordpress.com/2010/05/17/agent-managed-untrusted-servers-step-by-step-guide/
http://blogs.technet.com/b/stefan_stranger/archive/2012/04/17/monitoring-non-domain-members-with-om-2012.aspx

There are even some homemade scripts to deploy the agents like this one: http://systemscentre.blogspot.com.es/2012/03/scom-dmzworkgroup-agent-deployment.html

We are going to revise a check list to avoid some typical problems.
  • Have MOMcertImport from support tools of SCOM CD 
  • Have a C.A with capacity to issue certificates with property Enhanced Key Usage Server Authentication (1.3.6.1.5.5.7.3.1) and Client Authentication (1.3.6.1.5.5.7.3.2), you can use IPsec client template and Ipsec server templates 
  • Open TCP 5723 port between agent and RMS , from agent to RMS 
  • Check that client and server had root certificates from C.A on machine account 
  • Check that the name resolution is OK from RMS and from Agent (you can use host file) 
  • Agent "must" be installed on the RMS management group, default management group appears on system center console title. 
  • Run MomCertImport to install the issued certificate in the agent and in the RMS 
  • Verify if certficate is installed on this resgister key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Operations Manager\3.0\Machine Settings 

We wrote this check list long time ago in the MSDN wiki: http://social.technet.microsoft.com/wiki/contents/articles/12170.some-tipschecks-to-install-scom-20072012-agent-on-untrusted-domains.aspx

Recently we have experienced some problems in DMZ agents because the name of the SCOM RMS registered in the DMZ agent configuration is different form the name of the certificate, to solve this you have to follow the steps in this url:
https://geertbaeten.wordpress.com/2013/07/08/scom-agent-or-gateway-certificate-issue/

No comments:

Post a Comment