Client Management Suite

 View Only
  • 1.  Error in generating Cloud Based Agent "Failed to generate package. Https NS base URL must be used Internet-based Client Management agent. The agent package cannot be correctly created"

    Posted Nov 14, 2014 01:32 AM

    Hi All,

    While generating Cloud Based Altiris Agent package  in Symantec 7.5 error shows  " Failed to generate package. Https NS base URL must be used Internet-based Client Management agent. The agent package cannot be correctly created"

    Help required.

    Regards



  • 2.  RE: Error in generating Cloud Based Agent "Failed to generate package. Https NS base URL must be used Internet-based Client Management agent. The agent package cannot be correctly created"

    Broadcom Employee
    Posted Nov 14, 2014 05:32 AM

    Hi!

    Your Notification Server is running through HTTP or HTTPs?

    • CEM requires that Notification Server must work through HTTPs.

    You will need enable SSL in IIS for your NS Server and set HTTPs binding withing Web Site | Restart Altiris Services and W3WP.

    Note: If your clients are currently communicating with NS through HTTP, then they could lose connection to NS due SSL Handshake failure..., depending on what certificate will be used | Self-Signed or Internal MS CA.

    You can try to use "Agen Install" page to re-install Symantec Agent with enabled "Install certificates" to reconfigure all managed endpoints to work through HTTPs.

    Thanks,

    IP.



  • 3.  RE: Error in generating Cloud Based Agent "Failed to generate package. Https NS base URL must be used Internet-based Client Management agent. The agent package cannot be correctly created"

    Posted Nov 21, 2014 12:33 AM

    Hi , thanks for help.

    However the issue resolved by doing some settings (HTTP to HTTPS)at Agent install page .

    Would like to share scenario like -

     

    Existing NS \DB and Task server with 8000 clients in LAN

    Newly installed Gateway in DMZ and 300 clients on internet without any VPN or  LAN connectivty.

    Now  -we would to achieve 

    1.Existing clients from LAN  should be able to communicate with NS server via HTTP and without using gateway server when connected in network . 

    Existign agent should be work without any SSL certificate etc.

    2.CEM agents when connected to internet -should be able to connect to NS server via gateway server.

    if connected in  LAN - should be connected directly without using gateway server.

     

    Please suggest is it  possible ?

     

    Regards

     



  • 4.  RE: Error in generating Cloud Based Agent "Failed to generate package. Https NS base URL must be used Internet-based Client Management agent. The agent package cannot be correctly created"

    Broadcom Employee
    Posted Nov 26, 2014 08:31 AM

    Summary how to work SMA and Site Servers through HTTP or HTTPs with SMP 7.5 SP1 HF4

    1. You have installed SMP 7.5 SP1 on IIS Web Site where HTTP and HTTPs bindings are set

    2. Create a CEM Web Site

    CEM_Site1.jpg

    3. Open IIS Management ⇒ click on Web Site where SMP is installed ⇒ open "SSL Settings" and uncheck "Require SSL" ⇒ restart Altiris Services on SMP Server.

    IIS_SSLSite.jpg

    • Pay attention that if previouslly you had HTTPs enabled, then after applying this setting for IIS SMP Web Site -> "Agent Install" page will contains URL only for HTTP and "Targeted Agent Settings" policies will also have HTTP SMP Server URL.

    PushInstall.jpg

    4. In such environment, where you have HTTP and HTTPs enabled communication protocols for managed endpoints and Site Server(s) with SMP Server, you need to configure correct SMA "Targeted Agent Settings", where each managed endpoint and Site Server machine will receive correct URL for communication with SMP.

    For example, create custom Targeted Agent Settings for different type of managed endpoints, Site Server(s) to work only through required HTTP or HTTPs protocols with SMP Server:

    Targeted Settings only for Site Server(s) which will work through HTTP with SMP

    HTTP_Settings_Agent.jpg

    Targeted Settings only for CEM clients, which will work through HTTPs with SMP because CEM requires HTTPs and will doesn't work through HTTP.

    CEM_HTTPS_Settings.jpg

     

    5. Also pay attention to Package Server settings for packages codebases publishing

    PS_Publishes.jpg

    6. If CEM clients, which currently are in internet but there LAN connection appears ⇒ SMA should automatically detect this change and switch from CEM mode to LAN and will doesn't communicate through CEM Gateway, while LAN mode is available and works.

    Thanks,

    IP.



  • 5.  RE: Error in generating Cloud Based Agent "Failed to generate package. Https NS base URL must be used Internet-based Client Management agent. The agent package cannot be correctly created"

    Posted Feb 19, 2015 04:45 PM

    hi Igor

    got quesion slightly related i guees:

    the site server assigned to internet site can be also part of internal LAN site and serve both traffics https for CeM based clients and http LAN/VPN ones ( no need for dedicated site server while enabling CeM mode ) ?

     



  • 6.  RE: Error in generating Cloud Based Agent "Failed to generate package. Https NS base URL must be used Internet-based Client Management agent. The agent package cannot be correctly created"

    Broadcom Employee
    Posted Feb 20, 2015 11:39 AM

    Hi callend,

    you mean about what type of Site Server? Task Server or Package Server?

    Thanks,

    IP.



  • 7.  RE: Error in generating Cloud Based Agent "Failed to generate package. Https NS base URL must be used Internet-based Client Management agent. The agent package cannot be correctly created"

    Posted Feb 23, 2015 05:08 AM

    hi Igor

    Both: Task & Package Server. 

    Basically I would like to understand if I need additional dedicated  host with Package Server assigned to Internet Site

    OR

    I can use one of existing Site Servers ( with Package Server & Task Server active) associated with some LAN site to be member of both - original LAN site and internet site.

     

     

     



  • 8.  RE: Error in generating Cloud Based Agent "Failed to generate package. Https NS base URL must be used Internet-based Client Management agent. The agent package cannot be correctly created"

    Broadcom Employee
    Posted Feb 25, 2015 11:49 AM

    I think that you can use PS and TS for both as LAN server and Internet server to serve CEM and Intranet clients, just pay attention that you have all required settings done correctly, like:

    • "Targeted Agent Settings" for managed intranet/CEM endpoints and for Site Servers
    • HTTP and HTTPs bindings for Site Servers
    • Appropriate Site Servers are added in CEM Gateway
    • Correct settings on Site Server Management page, such as Site(s)/Subnets, Site assignments and manual assignments per Site(Site Server(s)).

    Amount of Site Servers depends on how much managed endpoints you're going to serve per single TS and PS. User Guide/Admin Guide should contain information about current limitations, etc.

    Thanks,

    IP.