Solved

Symantec Altiris - Local and public IP

Posted on 2012-04-12
5
675 Views
Last Modified: 2012-04-12
Hi,

There is a single Symantec Altiris server serving a single location office. Workstations connect to the Altiris server on the LAN using a local IP.

They would like it configured such that workstations connected to the LAN continue to connect on the local IP, but that when employees are travelling; their laptop workstations will connect to the Altiris server on our of their public IP's.

My question is:
How can we configure the Altiris Clients to look at the local Altiris Server IP first, and when that can't be found (i.e. when out of the office) it tries to connect to the Altiris server on the public IP? (hopefully this change can be pushed out by the Altiris server, rather than manually making a change on every workstation)

I understand it will mean making changes at firewall level to route the traffic accordingly, and that is fine. My question is purely about the Alitiris client configuration.

Thanks,
0
Comment
Question by:Roger Adams
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
5 Comments
 
LVL 26

Assisted Solution

by:Tony Johncock
Tony Johncock earned 250 total points
ID: 37836392
Would it not be easier to get the client to use a publicly resolvable FQDN and then alter internal DNS to point to the internal site when they're on the LAN?
0
 
LVL 11

Accepted Solution

by:
Khandakar Ashfaqur Rahman earned 250 total points
ID: 37837231
Do you have DNS Server?
Put  two A record for your Symantec server.

For an example,
12.12.12.12 is the public IP of your server
192.168.0.2 is private IP

Create two A records into DNS Server like:

symantec            A             12.12.12.12
symantec            A             192.168.0.2

And configure all of your laptops and computers by name not by IP.
0
 
LVL 26

Expert Comment

by:Tony Johncock
ID: 37837266
Why would you do it that way? The DNS would simply round robin, swapping between internal and external addresses when accessed internally.

An alias is a better way forwards:

http://support.microsoft.com/kb/168321

In this case, it'd be a name that matched an externally registered FQDN.
0
 
LVL 26

Expert Comment

by:Tony Johncock
ID: 37837282
Rigan's way would not necessarily work for the reasons I posted above. Is the external FQDN actually accessible whilst internal? If not, clients will fail in 50% of connection attempts.

And even if it is accessible thus - you would have clients going outside of your network onto the public FQDN to communicate with a server that is on the LAN even when the PCs are in the LAN environment.

Use an alias and your clients will only resolve the internal address when in the LAN.
0
 
LVL 26

Expert Comment

by:Tony Johncock
ID: 37837285
Sorry but I believe you've given points for a technically erroneous answer.
0

Featured Post

Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as the high-speed power of the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, you will read about the trends across the human resources departments for the upcoming year. Some of them include improving employee experience, adopting new technologies, using HR software to its full extent, and integrating artifi…
This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question