JDS in DMZ?

franton
Valued Contributor III

We currently have an Apache server sitting in our DMZ acting as a distribution point. It's pretty locked down, but not as much as it could be. JAMF's JDS allows (and insists on) certificate based communications. Sounds ideal!

Is anyone running a JDS as an externally available distribution point?

4 REPLIES 4

stevehahn
Contributor

I'd like to know more about this too. I doubt the network guys will let me put a JDS in our DMZ, so I'm trying to figure out which ports I'd need to open on the firewall in order to have a JDS be externally available.

jwojda
Valued Contributor II

+1

denmoff
Contributor III

@stevehahn][/url I think you just need 443 open for webdav connections. Also, I think the JDS still needs to be pingable for casper admin to mount it.

bvrooman
Valued Contributor

So if I'm understanding this correctly (and my read-through of the relevant portions of the admin guide), I should only need to open port 443 to put a non-root JDS in the DMZ? Will ping need to be open from internal subnets to the DMZ instance?