<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SCCM management of remote GP Windows clients in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/334261#M84342</link>
    <description>&lt;P&gt;Let us know what you find to fix your issue.&lt;/P&gt;&lt;P&gt;Next week we are also doing Global protect always on connection method &amp;nbsp;for few users to Test it and will see how sccm works&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jun 2020 15:17:23 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2020-06-19T15:17:23Z</dc:date>
    <item>
      <title>SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/318478#M81760</link>
      <description>&lt;P&gt;We just deployed and started using GlobalProtect 5.1.1 to support the work-from-home COVID-19 initiative for thousands of remote workers.&amp;nbsp; Everything is working well but my SCCM guys can't manage any of the remote clients to push patches or software updates.&amp;nbsp; Our internal DNS resolves the host names to the last LAN address of the host, not the IP pool address.&amp;nbsp; The same things happens with Cisco AnyConnect clients.&amp;nbsp; I don't know anything about AD or SCCM.&amp;nbsp; Is SCCM management of remote hosts doable and if so, how are you doing it?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 12:15:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/318478#M81760</guid>
      <dc:creator>pnelson</dc:creator>
      <dc:date>2020-03-25T12:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/318493#M81763</link>
      <description>&lt;P&gt;Yes, this is completely possible. We are doing this today the same as you. All we had to do was create a policy allowing traffic from our "trusted" zone, to the "global protect" zone. There's lists of ports out on the web for the various SCCM functions. For example, for remote control here's the ports required per-microsoft:&lt;/P&gt;&lt;P&gt;1. Port 135 - TCP&lt;/P&gt;&lt;P&gt;2. Port 3389 - TCP&lt;/P&gt;&lt;P&gt;3. Port 2701 - TCP/UDP&lt;/P&gt;&lt;P&gt;4. Port 2702 - TCP/UDP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe patching uses 445 for SMB transfers. So depending on what you want to do there's multiple things you'll have to allow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A couple of other things to keep in mind with AD/SCCM is 1. DNS will take time to update after clients connect. So your techs might have to ask the user for the IP and use this in the remote control client of SCCM. 2. AD Sites and Services, and SCCM boundary groups need to include your VPN ranges for the SCCM clients to check in properly and be managed. This also helps them control which SCCM distribution point serves the patches/apps to clients so you can know where traffic is coming from.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 13:49:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/318493#M81763</guid>
      <dc:creator>ZachBiles</dc:creator>
      <dc:date>2020-03-25T13:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/318537#M81773</link>
      <description>&lt;P&gt;Thanks, Zach.&amp;nbsp; I've allowed the traffic and will have my SCCM guys test.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 17:04:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/318537#M81773</guid>
      <dc:creator>pnelson</dc:creator>
      <dc:date>2020-03-25T17:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/318551#M81776</link>
      <description>&lt;P&gt;Zach, your fix worked!&amp;nbsp; THANKS!&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 17:47:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/318551#M81776</guid>
      <dc:creator>pnelson</dc:creator>
      <dc:date>2020-03-25T17:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/318561#M81778</link>
      <description>&lt;P&gt;Good deal, glad I could help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 18:04:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/318561#M81778</guid>
      <dc:creator>ZachBiles</dc:creator>
      <dc:date>2020-03-25T18:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/330487#M83773</link>
      <description>&lt;P&gt;Hi Nelson, apart from the Palo Rules, anything specific you had to do on SCCM? We released patches over a week ago to a test collection, and the devices which are still "on-prem" received the updates, however the devices (users working from home that are connected via Global Protect) are not receiving the updates. All rules and comms to our sccm server are configured and working. Boundary groups within SCCM are also good. Anything I a missing?&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 10:43:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/330487#M83773</guid>
      <dc:creator>ColonelHawx</dc:creator>
      <dc:date>2020-05-29T10:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/330524#M83780</link>
      <description>&lt;P&gt;ColonelHawx, I had to go to my SCCM and DNS folks to give you a proper answer.&amp;nbsp; SCCM guys say if your boundaries are good that's all you have to do there.&amp;nbsp; My DNS people sent me this:&amp;nbsp; "Because VCUHS.mcvh-vcu.edu [which is the domain of our user PCs] is also used by servers, we don’t allow every device using that domain to register with DNS.&amp;nbsp; I had to add the Global Protect pool to the list of networks that are allowed to register [with our Infoblox DNS servers]."&amp;nbsp; SCCM could not resolve PCs names to IP addresses until this change was made.&amp;nbsp; That made it all work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 14:10:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/330524#M83780</guid>
      <dc:creator>pnelson</dc:creator>
      <dc:date>2020-05-29T14:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/330827#M83836</link>
      <description>&lt;P&gt;Thanks for the reply. Before I create a new Thread for help... Did you configure your GlobalProtect with pre-logon connection method or user-logon? Someone mentioned on a Palo FB forum, that pre-logon should be set for SCCM to work seamlessly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: Are you by any chance seeing any "aged-out" traffic from your GP Client (Source) to SCCM Server (Destination)?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ColonelHawx_0-1591016150266.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25929iFB28FEB566125526/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ColonelHawx_0-1591016150266.png" alt="ColonelHawx_0-1591016150266.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 12:57:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/330827#M83836</guid>
      <dc:creator>ColonelHawx</dc:creator>
      <dc:date>2020-06-01T12:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/333922#M84276</link>
      <description>&lt;P&gt;Bump&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2020 20:25:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/333922#M84276</guid>
      <dc:creator>ColonelHawx</dc:creator>
      <dc:date>2020-06-17T20:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/334023#M84302</link>
      <description>&lt;P&gt;Sorry, ColonelHawx, did not see your previous post.&amp;nbsp; Connection Method is "On-demand (Manual user initiated connection)."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 10:13:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/334023#M84302</guid>
      <dc:creator>pnelson</dc:creator>
      <dc:date>2020-06-18T10:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/334030#M84303</link>
      <description>&lt;P&gt;Thanks for this info... It def helps... So we have the EXACT same setting applied. But what really baffles me is that we just tested by deploying a VM within the same subnet as our GP Clients &amp;amp; Primary SCCM server and it worked and received ALL applications and software deployments. But the GP Clients are still not getting it. Can I ask what Version of SCCM you are on? 1910 or 2002? Also, is there anything specific you had done/applied on your Palo GP Config? Our clients are using a /22 range and below is a snapshot of a device using Global Protect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ColonelHawx_0-1592475866637.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26241iFFDEBDE4A0FADFA2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ColonelHawx_0-1592475866637.png" alt="ColonelHawx_0-1592475866637.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ColonelHawx_1-1592475949055.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26242iEDE9F227CC1DF093/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ColonelHawx_1-1592475949055.png" alt="ColonelHawx_1-1592475949055.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 10:26:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/334030#M84303</guid>
      <dc:creator>ColonelHawx</dc:creator>
      <dc:date>2020-06-18T10:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/334031#M84304</link>
      <description>&lt;P&gt;SCCM version is 1910.&amp;nbsp; Your GP settings look pretty much the same although we're set up so that our users have to be in a particular AD group.&amp;nbsp; In the HIP profile we specify that the clients must be members of the domain.&amp;nbsp; I'm not seeing any material difference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 11:23:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/334031#M84304</guid>
      <dc:creator>pnelson</dc:creator>
      <dc:date>2020-06-18T11:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/334036#M84307</link>
      <description>&lt;P&gt;Thanks for the help Pete... Yeah we are also using HIP profiles with clients being member of the Domain, having AV etc etc... Will try to figure out whats going on...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 11:44:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/334036#M84307</guid>
      <dc:creator>ColonelHawx</dc:creator>
      <dc:date>2020-06-18T11:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/334261#M84342</link>
      <description>&lt;P&gt;Let us know what you find to fix your issue.&lt;/P&gt;&lt;P&gt;Next week we are also doing Global protect always on connection method &amp;nbsp;for few users to Test it and will see how sccm works&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 15:17:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/334261#M84342</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-06-19T15:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/338939#M85180</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why we require Group Policy&lt;BR /&gt;For various tasks such as communicating with Active Directory Discovery, Remote administration and WMI connectivity, we require these policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are 3 types of settings we require:&lt;/P&gt;
&lt;P&gt;- To Ping Client Workstations (By default this communication is blocked if Firewall is enabled)&lt;BR /&gt;- To connect to Clients Admin$ Share&lt;BR /&gt;- To connect to clients WMI ( as SCCM heavily relies on WMI repository to store all policies, deployments and other tasks)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Default Behavior of client ( before creating Group Policy)&lt;BR /&gt;a. By default, we cannot ping the client workstations in case the firewall is enabled. Even though the machine is switched on and connected on the same network, we will not receive the Ping response.&lt;/P&gt;
&lt;P&gt;b. We are not able to connect to the admin$ share of the client (ie clients “c:\windows” directory). This is required for various tasks including SCCM client push installation was setup files over the network copies under client’s c:\windows directory.&lt;/P&gt;
&lt;P&gt;c. Inbound remote administration is disabled by default, which means we cannot connect to clients WMI repository remotely. This is mandatory to install SCCM client and to download and save several SCCM policies, deployments &amp;amp; tasks. If we try connecting to clients WMI by using wettest (inbuilt tool on Windows), we will get error “0x800706ba“&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advance&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lavanya Sreepada&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 21:24:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/338939#M85180</guid>
      <dc:creator>lavanyasreepada</dc:creator>
      <dc:date>2020-07-16T21:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: SCCM management of remote GP Windows clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/351295#M87056</link>
      <description>&lt;P&gt;We had the same issues reported as the others here.&amp;nbsp; We were able to get past most issues with the solution presented from the OP.. additionally we had to move from subnets within the Boundary groups to IP ranges.&amp;nbsp; This was a change for us from how AnyConnect was configured, but this seemed to fix our inability to see updates as well as TS's and packages.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We still however don't have a solution for our techs inability to Remote Control or RDP consistently.&amp;nbsp; I know this has something to do with DNS resolution not happening properly or timely enough.. does anyone have information that might assist with this issue or tips for our server admin team on replication timing?.. Thanks in advance!!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 21:41:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sccm-management-of-remote-gp-windows-clients/m-p/351295#M87056</guid>
      <dc:creator>Jerzystransfer</dc:creator>
      <dc:date>2020-09-22T21:41:17Z</dc:date>
    </item>
  </channel>
</rss>

