Symantec Management Platform (Notification Server)

 View Only
  • 1.  Two non SSL NS, one SSL NS in DMZ to SSL Reporting NS

    Posted Nov 18, 2008 04:33 AM
    I need to get some answers to a technical question I have about Altiris Notification Server. Could you get this question and/or me in contact with someone who can answer this?

    I have read the posts in regards to running an NS in the DMZ.

    I do have a question which I need clarification on:
    If I put an NS in the DMZ, allow access to port 443 (SSL) and have the NS Agents communicate via SSL to the NS server in the DMZ.
    The NS server in the DMZ would then forward its information to a central reporting NS. Will the Central Reporting Server NS also need to be SSL enabled?

    How is Inventory Forwarding from one NS to another affected by SSL?

    I would like to create the following scenario:

    DMZ NS SSL enabled -> Central Reporting SSL Enabled
    Lower NS Not SSL enabled -> Central Reporting SSL Enabled
    Lower NS Not SSL enabled -> Central Reporting SSL Enabled

    I would assume that in general it would Inventory Forwarding would not be affected if a lower level NS is using SSL or not to communicate to its agents.


    What are my options here?

    How does an SSL enabled NS forward inventory to a non-SSL enabled NS? Is this even possible?

    Any insights to this would be great...Thank you...


  • 2.  RE: Two non SSL NS, one SSL NS in DMZ to SSL Reporting NS

    Posted Nov 19, 2008 03:24 AM
    I do not think this is possible. The traffic is going to go over whatever port you are sending it on, and the receiving website would have to be on that port. Also, if the traffic is being sent via SSL, the receiving channel would need that as well, although the certificate part is debatable, since you're not contacting the certificate server.


  • 3.  RE: Two non SSL NS, one SSL NS in DMZ to SSL Reporting NS

    Posted Nov 25, 2008 04:59 PM

    I will got the same way as Jim. We have two servers in a DMZ and Altiris had not succeeded "yet" to make them communicating with the NS which is outside the DMZ. It was impossible to find out a way to work with Servers inside the DMZ. Even NetMotion we have tweak is giving some trouble time to time closing port for protection....