question

ddevi-8560 avatar image
0 Votes"
ddevi-8560 asked Crystal-MSFT commented

SCOM 2016 Gateway server scenario

Planning to deploy SCOM 2016, we already have SCOM 2012 where we have a gateway server deployed for a different site say ab.com. But I do see ab.com domain is trusted and see some servers from ab.com reporting directly to management servers.

Moving to new SCOM infra, do we need to deploy gateway? as we have trust created in AD, can we have all servers in ab.com domain report directly to management server itself.

SCOM infra is in Azure private cloud and there is a ping delay of 23 ms between SCOM management servers and servers at site ab.com.

Please advise.

msc-operations-manager
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

AndrewTabar-3601 avatar image
0 Votes"
AndrewTabar-3601 answered

Our management servers are hosted in the US (Las Vegas). We have gateways for our trusted domains in EU (Amsterdam) and AP (Hyderabad and Taipei) to reduce the traffic going across our WAN; they compress traffic by about 50%. Having gateways in these remote sites also reduces the firewall rules needed since only the gateway(s) in the remote sites are communicating with the management servers.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Crystal-MSFT avatar image
0 Votes"
Crystal-MSFT answered Crystal-MSFT commented

@ddevi-8560, In general, Gateway servers are used to enable agent-management of computers that are outside the Kerberos trust boundary of management groups, such as in a domain that is not trusted.

When there are trusts between the two domains. we can report to the management server directly. But it seems the network connection is not so good. There are some delay. If the Kerberos negotiate can be done within 20 seconds, on my point of view, we can report to the management server directly without deploying Gateway server. If not, adding a Gateway server can be a workaround for our situation.

Hope it can help.



If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


· 3
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@ddevi-8560, Hope things are going well. I am writing to see if there's anything unclear of my previous reply. If there's anything else we can help, feel free to let us know.

0 Votes 0 ·

Thanks for an answer. I am just looking if deploying a gateway in the site would be beneficial in any way like in terms of network bandwidth consumption or streamlining.... kindly advise.

0 Votes 0 ·

@ddevi-8560, Thanks for the reply. Yes, Gateway offers compression when send data between agents and Management server. But at them same time, the agents behind the Gateway will take longer to get configuration. We can also take them into consideration.

0 Votes 0 ·
ddevi-8560 avatar image
0 Votes"
ddevi-8560 answered Crystal-MSFT commented

Thank you both! it answers my questions!!

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@ddevi-8560,Thanks for the response. I am glad the information can help. If there's anything else we can discuss together, feel free to post in our Q&A.

Thanks for the time and have a nice day!

0 Votes 0 ·