Some Tips/Checks to Install SCOM 2007/2012 Agent on Untrusted Domains

Some Tips/Checks to Install SCOM 2007/2012 Agent on Untrusted Domains

Here some useful tips and checks to run DMZ agent on SCOM 2012 and SCOM 2007

- Have MOMcertImport from support tools of SCOM CD

- Have a C.A with capacity to issue certificates with propierty Enhanced Key Usage Server Authentication (1.3.6.1.5.5.7.3.1) and Client Authentication (1.3.6.1.5.5.7.3.2), you can use IPsec client templeate and Ipsec server templates

- Open TCP 5723 port between agent and RMS , from agent to RMS

- Check that client and server had root certificates from C.A on machine account

- Check that the name resolution is OK from RMS and from Agent ( you can use host file)

- Agent "must" be installed on the RMS management group, default management group apears on system center console title.

- Run MomCertImport to install the issued certificate in the agent and in the RMS

- Verify if certficate is installed on this resgister key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Operations Manager\3.0\Machine Settings

Detailed informatión about DMZ agent config in http://www.stranger.nl/files/DMZ_server_monitoring_with_SCOM_2007.pdf is still valid to SCOM 2012.
Leave a Comment
  • Please add 7 and 4 and type the answer here:
  • Post
Wiki - Revision Comment List(Revision Comment)
Sort by: Published Date | Most Recent | Most Useful
Comments
  • Richard Mueller edited Revision 1. Comment: Removed (en-US) from title, modified title casing

  • Patris_70 edited Original. Comment: added en-US tag and title

Page 1 of 1 (2 items)
Wikis - Comment List
Sort by: Published Date | Most Recent | Most Useful
Posting comments is temporarily disabled until 10:00am PST on Saturday, December 14th. Thank you for your patience.
Comments
  • Patris_70 edited Original. Comment: added en-US tag and title

  • Richard Mueller edited Revision 1. Comment: Removed (en-US) from title, modified title casing

Page 1 of 1 (2 items)