Altiris Deployment Server 6.9 SP1 - Managing clients in other domains without trust.
Hi,
I hope you can help me on this issue.
We are getting more than 200 mchines into our DS. These machines are in another domain. There is no trust between the two domains. DS and NS Ports were opened in the firewall. Acouble of these machines have installed the Aclient on them by manual means and partly by deploying them with another deployment tool. Wee casn see the clients on our console, but management is still imposible. As far as I know Aclients must not be a part of the domain of the network in ordr to be managed, however, copying files (like the NS Agent Installation Package) and installing these agents on those machines is not working.
Does anybody have an idea how to ensure that client management (Via Aclient) in another domain works well?
The domain join of the client is scheduled but it will take more than 2 month to be done..Therefore, clients must be managed now..
Thank you for your appreciated help.
Comments
Domain Service Account
Have you tried putting a domain service account that has rights to that domain in DS? Tools ---> Options. Then click on Domain Accounts. If you can get an account that has access to that domain in there, it may solve your issue.
Brian Hawver
Systems Engineer
Yaskawa America, Inc.
Connect Etiquette: "Mark as Solution" those posts which resolve your problem, and give a thumbs up to useful comments, articles and downloads.
bhawver, Thanks. The service
bhawver,
Thanks. The service user you meant should be a user of a parent or trusted domain. This is here, unfortunately, not the case.
Despite of this I have entered the Domain Admin Account for that domain on our Ds:
Domainxyz\username, pwd
However, this issue persists. No copy jobs are possible..:'Logon Failure: Unknown user name or bad password'
Any ideas..?
Thanks.
Specify user in job
What about modifying the job to run as a specified user? Unfortunately, this will mean you will have to have two sets of jobs (one for your domain, one for theirs). For a copy file to job, you would click on the advanced options button and specify the user that you want. Just about every task should have this option. Most tasks will allow the task/job to run as a system user though.
Another option would be to establish a trust between the two domains and grant your ds admin accounts rights to their domain and workstations.
Brian Hawver
Systems Engineer
Yaskawa America, Inc.
Connect Etiquette: "Mark as Solution" those posts which resolve your problem, and give a thumbs up to useful comments, articles and downloads.
Share permissions
Have you by any chance changed the share permissions on the eXpress share on your DS server? By default the permissions are Everyone, but I know that some people change those permissions :)
Are all the Aclient's the correct version? The reason I ask is because I am just thinking if one or more of them are older versions, they should be upgraded automatically... does that happen? Of course the auto upgrade Aclient should be enabled :)
________________
/mlogan
Connect Etiquette: Please "Mark as Solution" those posts which resolve your problem, and give a thumbs up to useful comments, articles and downloads!
I had tried the option
I had tried the option bhawver suggested but without success. The permissions of the express share are as mlogan described. All clients have the same Aclient version 6.9.366. A Domain trust was made yesterday.I will check and inform you about the status.
Thanks.
I use an install user created
I use an install user created in each domain with the same username and password. Then create jobs without specifiring domain.
Aclients change their status
Thank you for your advice. Meanwhile both domains are trusted. But it did not really improve.
The installation user will be added to all Admin Local group on the remote clients.
However, despite of trust an issue is still persistent:
The Aclient changes its status from activ to inaktiv (greyed out) each time a 'Get Inventory' jobor a send basic inventory or any other job. This makes the clients unmanageable. The Aclient service is still online though. When rstarting the service we receive an Access Denied message. But this is another story.
Any idea why the Aclients change their status as descibed?
Thanks.
Firewall
The firewall was the culprit. After correctly configuring the firewall between the main and the remote site, the issue was resolved.
Would you like to reply?
Login or Register to post your comment.