Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

SOLVED SCCM Client agent install fails on specific subnets

Status
Not open for further replies.

InTheValley

New Member
Messages
3
Reaction score
0
Points
1
Here's a little background:
We have installed and configured SCCM 2016 version 1702 which was then upgraded to version 1802. We have configured Active Directory Forest Discovery and enabled the feature to automatically create Active Directory site boundaries when they are discovered. We have also enable the feature to automatically create IP address range boundaries for IP subnets when they are discovered. SCCM detected and created boundaries for all our virtual machines that reside at our data center which are 3 specific subnet IP address ranges. The vm which SCCM resides on happens to be within one of the subnets successfully detected. SCCM did not however detect any other subnet ranges or create any other boundaries automatically. Our system discovery method is also enabled and it could discover all our workstations within Active Directory. Although these workstations have been detected we have been unable to install the client from either the workstation manually or by pushing from SCCM. We have however been able to install the client to the virtual machines that SCCM detected and created boundary groups for.

We have manually created boundaries IP address ranges for a few of our workstations and attempted to push the client but it continued to fail. We have ensured that firewall is turned off on the workstations and SCCM to eliminate that factor. We have also set the group policy that allows inbound and outbound traffic specific to SCCM. The Client push installation account has been provisioned and we have ensured that it is a local administrator for our workstations.

Attached are the log files from both SCCM and from the client.

Any suggestions on how to get push the client to these workstations in subnets other than our data center (where the client installation succeeds) would be much appreciated! Thanks.
 

Attachments

"We have manually created boundaries IP address ranges for a few of our workstations and attempted to push the client but it continued to fail" - After this step did you create a boundary group and assigned a valid distribution point server ?.
 
Yes, I forgot to mention that also. We have created a boundary group and assigned these specific boundaries to it and then set that boundary group to be assigned to our one-and-only site which has most roles (we have a stand-alone primary site design).
 
Check in Administration > Site Configuration > Servers and Site System Roles in the bottom pane right click on Distribution Point and click Properties. Then go the Boundary Groups tab and make sure the boundary you have created and assigned to a boundary group, has been added to this distribution point.

2018-10-09_1837.png
 
Thanks for your reply Phil. We just barely resolved the issue before you sent that. The root of the issue didn't have to do with the boundaries like we thought but with our firewall. We dug deep into the logs and eventually had a light bulb moment when we tried to hit an html page that the distribution point has and a message from our firewall appeared. The web content filtering was dropping the packets sent to clients during the client install causing it to fail. Once we turned off the web content filtering a client installation happened without issue. We definitely looked at the firewall plenty of times but didn't catch this until the end. Lesson learned!
 
Status
Not open for further replies.

Forum statistics

Threads
7,157
Messages
27,935
Members
18,237
Latest member
Causal

Latest posts

Back
Top