hi, I've got some design questions around IBCM. We're planning to setup IBCM for customer in 2 DMZ locations (Americas / Europe). Current thinking would be to have 1 MP; 2x DP's in each of the DMZ. Our exisiting configuration consist of 1 CAS and 3x Primary sites (120,000 end points) (SCCM 2010 SP1 CU2) will be upgrading to R2 next month.
here are some questions I have
- I know that the MP need to have Public DNS name, I guess this is also needed for the DP's in the DMZ otherwise the clients will not be able to connect to these?
- do I need to create new SCCM site for each DMZ, or can the DMZ MP's be joined to the existing site for that region?
-DP, When installing the DP role, I guess no boundaries can be assigned, when Internet Clients request for Content the clients will get list of DP's and will select first the http(s) enabled DP's vs. http DP's is that correct?
- SUP, do I need to install Full WSUS or is the WSUS console sufficient enough for installing the SUP Role ? Is there any issue/problem with adding the SUP Role alongside to the MP or DP? Current thinking is that we will have max. 10,000 clients globally configured for IBCM, so I don't think should be any issue from performance point of view.
- Clients? Currently all our clients are installed as "Intranet" clients, to make them IBCM aware is it necessary to do full re-install of the SCCM Client, and then pass along the MP and Cert info, or can this be done with registry tweak? The client certs will be deployed using AD.