Hello everybody,
Newbie in here and I really need help from this great community.
We're in the process to evaluate the possibility to publish our JSS in the DMZ.
My environment is set up as follow:
- JSS 9.7 on a Win2012R2 vm hosted on hyper-v (internal.mycompany.com)
- 3 distribution points across the offices (geographically far one from each other).
- 1 SUS (internalsus.mycompany.com)
Everything now is working great but we would like to move our JSS to the DMZ in order to be reachable (policies and packages) by our Mac laptop clients from everywhere (external to our LAN).
What would be the best way to achieve our task and access/managing everything with external.mycompany.com?
We’re following this guide
and as far as I understood we should place in the DMZ a second and “limited” JSS server + another DP.
The database would continue to rely on our internal JSS server, accessed only by the JSS in the DMZ. Apart issuing a new SSL certificate, correctly register our DNS and set up the HTTPS DP, what should we take care of?
We found the complete list of ports used by Casper. Is there anything else we should be aware of related to the security topic?
The JSS server in the DMZ will be behind a load balancer: any advice?
And lastly, how can I manage to reach my SUS? Do we have to move it to DMZ as well?
Forgive me whether I'm not clear enough...actually I'm very confused!
Thanks in advance for your suggestions.
Cheers,
Jack
