Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

PENDING Second Primary site, or other ideas.. need help : (

  • Thread starter Thread starter cru22
  • Start date Start date
  • Replies Replies 4
  • Views Views 2K

cru22

Member
Messages
5
Reaction score
1
Points
1
Here is my situation - I have 2 data centers, both have network connectivity, HOWEVER, each dc's network is broken into various zones based on environment. For security reasons, some environments cannot talk to others. The management zones in each dc can talk to each other, however as stated not all zones in one dc can talk to the management zone in the other. This makes it hard to have one site server since not all servers would be able to communicate back.

This brings me to my issue. I setup a secondary site thinking that would overcome my obstacle as the clients would have a mp to reach to and a dp. However the clients obviously cannot be assigned to a secondary site. I can push the client out, it installs, but will not register as a valid client in sccm. I am getting the black x, or not even registering at all as having a client. Ive watched the logs install and it comes down to the secondary site that I have set in the boundary group "Attempting to assign client to R01 site that does not match assignment requirements" per the logs - which makes sense since its a Secondary site.

So in a scenario where there is limited network connectivity between certain zones, though the respective management zones can fully communicate - what is the best way to set this up? Having two primary sites??
 
If the management zones between both DC can talk then what is the problem? One primary site is all you need.
 
Because the other zones - take one of the production zones - cannot communicate over the necessary ports to the primary site server. Essentially what has happened is that the client installs, can finds the site, however cannot register itself with the primary site server
 
There are really only three ports that are needed port 80/443, 8530/8531 and 10123. So.... Talk to the team about opening those ports.
 
There are really only three ports that are needed port 80/443, 8530/8531 and 10123. So.... Talk to the team about opening those ports.

crap... I think its 10123 for client notification. I'll get with them and check it out...
 
Back
Top