We are investigating switching from our locally hosted JSS to the cloud solution and are trying to work out the best way to handle distribution points.
Or initial plan was to have one external-facing (the goal being HTTPS access only) and one internal-facing but, based on our discussion with our TAM, the JSS would need read/write access to both, which would mean enabling AFP or SMB through our firewall.
How are others handling this? Any tips and tricks to keeping it secure while still giving the cloud JSS the access it needs?
