agorts Posted July 18, 2011 Report Share Posted July 18, 2011 Καλησπέρα, Έχω εγκαταστήσει το SCE2010 και έχω προσθέσει αρκετούς clients (μέσω της διαδικασίας "Discover")... Προσπαθώ να κάνω "Discover" ένα MS ISA 2006 server αλλά δεν τα έχω καταφέρει... Μου βγάζει πρόβλημα "Discovery failed"... Έχω βάλει στον ISA, 2 firewall rules (ISA -> SCEServer & SCEServer -> ISA) που επιτρέπει όλο το outbound αλλά δεν διορθώθηκε... Έχετε καμιά ιδέα? Ευχαριστώ Link to comment Share on other sites More sharing options...
klag Posted July 18, 2011 Report Share Posted July 18, 2011 έχω την υποψία ότι έχει να κάνει με τα Local policy firewall Rules του ISA και όχι με τα Firewall που ανοίγεις εσύ. Παλιότερα σε έναν SBS που ήθελα να στείλω DPM Agent δεν γινόταν και έκανα αυτά που λέει το άρθρο και όλα ήταν ΟΚ. Θεωρώ ότι πρέπει να κάνεις κάτι παρόμοιο (μην σου πω ότι ΄νομίζω ότι πρέπει να κάνεις ακριβώς το ίδιο) Δες λίγο το άρθρο και πες μας http://www.eggheadcafe.com/software/aspnet/29364454/agent-install-on-sbs2003-premium.aspx Can you make sure that configuration changes made to ISA Firewall are as per steps given below 1. Open the ISA MMC 2. Click on Firewall Policy 3. Click View>Show System Policy Rules to see the system policies 4. Disable System Policy Rule number 2 ("Allow remote management from selected computers using MMC") 5. Double click System Policy Rule number 22 ("Allow RPC from ISA server to trusted servers") 6. In the System Policy Editor dialog, uncheck the "Enforce Strict RPC Compliance" checkbox 7. Click View>Show System Policy Rules to hide the system policies 8. Select the first firewall policy rule 9. On the action menu, select New>Access Rule 10. Name the rule "DPM" and click next 11. Choose "Allow" and click next 12. Choose "All outbound traffic" and click next 13. On the access rule sources page, click the "Add" button to open the 14. In the "Add Network Entities" dialog, click New>Computer to open the 15. On the "New Computer Rule Element" dialog, Enter the name of the DPM server and enter its IP address, and click OK 16. In the "Add Network Entities" dialog, expand computers and double-click the new DPM entry. If you want to be able to manage the ISA server using RDP Or the MMC consoles from other systems in your organization, you can add those specific systems here as well by repeating steps 14-16 for each system. 17. In the "Add Network Entities" dialog, expand networks and double-click the Localhost entry 18. Click "Close" to close the "Add Network Entities" dialog 19. You should now have, at minimum, the DPM server and Localhost in the Access Rule Sources page. Click next 20. In the access rule destinations page, click the "Add" button to open the "Add Network Entities" dialog 21. In the "Add Network Entities" dialog, expand computers and double-click the new DPM entry. 22. In the "Add Network Entities" dialog, expand networks and double-click the Localhost entry 23. Click "Close" to close the "Add Network Entities" dialog 24. You should now have the DPM server and Localhost in the Access Rule Destinations page. Click next 25. Leave the default User Set selected and click next 26. Click Finish 27. Ensure that your new rule, "DPM", is at the TOP of the list of Firewall policies. This ensures it will be matched before any other rule for traffic to and from the DPM server. 28. Right click the DPM rule and select properties to open the "DPM Properties" dialog 29. Click the Protocols tab. In this tab, click the "Filtering" button and then click "Configure RPC Protocol" to open the "Configure RPC Protocol Policy" dialog. 30. In the Configure RPC Protocol Policy" dialog, uncheck the "Enforce strict RPC compliance" checkbox and then click OK to close the dialog. 31. Click OK to close the "DPM Properties" dialog 32. Near the top of the ISA console, click the "Apply" button to apply the changes to the ISA server If the configuration that made was a per above given steps, revert the configurations and check if atleast protected server is unblocked. Let me know the result ω Link to comment Share on other sites More sharing options...
agorts Posted July 19, 2011 Author Report Share Posted July 19, 2011 Τα έκανα ακριβώς έτσι... αλλά συνεχίζει να μην γίνεται discover... Bλέπω τα σχετικά logs στον ISA... αλλά κανένα δεν γίνεται blocked! Link to comment Share on other sites More sharing options...
Miss Marple Posted July 19, 2011 Report Share Posted July 19, 2011 Καλησπέρα agorts, Υπάρχει περίπτωση να έχεις κλειστό το File & Printer Sharing στην εσωτερική κάρτα δικτύου του ISA? Αν ναι, ενεργοποίησέ το, ξαναδοκίμασε και ενημέρωσέ μας. Link to comment Share on other sites More sharing options...
agorts Posted July 19, 2011 Author Report Share Posted July 19, 2011 Καλησπέρα Miss Marple, Πράγματι ήταν κλειστό... το ενεργοποίησα και το discover ολοκληρώθηκε! και η εγκατάσταση του SCEClient ολοκληρώθηκε... Ευχαριστώ Link to comment Share on other sites More sharing options...
agorts Posted July 19, 2011 Author Report Share Posted July 19, 2011 Όταν επιλέξω τον ISA και πατήσω κάποιο από τα 3 "Performance" links (CPU Performance, Processor Queue Length, Memory Usage) στο παράθυρο που βγαίνει δεν υπάρχει κάνένας counter! Τι μπορεί να είναι? Link to comment Share on other sites More sharing options...
klag Posted July 19, 2011 Report Share Posted July 19, 2011 έπαιξε μόνο με αυτό που είπε η Miss Murple? δηλαδή αν ξεκάνεις τα προηγούμενα συνεχίζει και παίζει? Link to comment Share on other sites More sharing options...
agorts Posted July 19, 2011 Author Report Share Posted July 19, 2011 έπαιξε μόνο με αυτό που είπε η Miss Murple? δηλαδή αν ξεκάνεις τα προηγούμενα συνεχίζει και παίζει? Δεν είχα το χρόνο για να κάνω δοκιμές... οπότε σίγουρα έπαιξε "αθροιστικά", αφού έίχα κάνει τις ρυθμίσεις... επειδή έχω και άλλο ISA server, θα το επιβεβαιώσω όταν βάλω και αυτόν... για να ξέρουμε σίγουρα... Link to comment Share on other sites More sharing options...
Recommended Posts