Hello,
This is my first post to the forums. Please forgive me if I'm failing to observe an established convention. I've looked around the documentation and forums and have been unable to find an answer to my bigger question although I think I've run across answers to some of the subcomponents.
I'm running SEC 5.2.0.644 on Windows Server 2008 R2 Standard. Licensed product is Sophos Endpoint Protection - Advanced. This is working properly. The server is a member of our AD domain but is not a DC. It's located on our internal network.
Since we do not allow any outside traffic inbound into our internal network, external clients can't update using that server, and are using the Sophos severs for updates. Since we have an increasing number of external clients, we'd like to provide updates to these clients from our own servers, which would also allow us to to deploy the home client for some of our users who would like to use it.
It seems to me that the easiest way to do this securely would be to set up a second server in a dedicated DMZ, and then have our existing SEC server push product and definition updates to the second server. I'd also like to have the existing SEC server pull client status information from the second server, rather than having the second server push it to the existing server. From there, we could allow inbound traffic from clients into the DMZ and then to the second server. I can't have the DMZ server be a member of the existing internal AD domain.
Am I on the right track here? If so, is there an existing article or post on how to put this together to work in that fashion? Or is there a better way to do this? I would rather avoid putting my existing SEC server in the DMZ.
Thanks for any guidance.
Elisan
This thread was automatically locked due to age.