Hitachi

JP1 Version 12 JP1/IT Desktop Management 2 Overview and System Design Guide


2.24.2 Managing devices connected via the Internet

By using JP1/IT Desktop Management 2, you can keep track of the managed computers taken out of the office by employees working off-site from home or a satellite office without the need to set up a VPN connection.

In this case, you have to set up an Internet gateway server in the demilitarized zone (DMZ) of the corporate network and then connect the server to the management server. Managed computers and the management server are connected to one another via the Internet gateway server. Managed computers and the Internet gateway server are connected to one another via HTTPS.

[Figure]

Important

Note that, when you keep track of computers connected via the Internet, the available functions vary from when a VPN connection is used. For details, see 2.24 Managing devices used outside the company.

Organization of this subsection

(1) Managing connected devices

Devices connected via the Internet are managed as described below.

Prerequisites

The following prerequisites apply to devices managed through Internet connection:

Important

Agentless devices cannot be managed.

Important

Whenever a managed computer is taken out of the company for use, Wake on LAN and the AMT BIOS setting must be disabled to prevent inadvertent activation of the computer.

To manage devices through Internet connection:

In the Agent Configurations view of the Settings module on a managed computer, select Basic settings, and then the Perform HTTPS communication with the higher system via the Internet Gateway check box.

If you enable this setting, the agent communicates with the management server and the relay system via the Internet gateway.

Network connection control

A managed computer used outside the company is not subject to network connection control.

Furthermore, when a managed computer is used outside the company, an IP address that is different from the one managed in the internal network is set. For this reason, if network connection control is performed based on a network control list with IP addresses used for judgment, network connection control for managed computers might not work properly. For this reason, we recommend that you use MAC addresses for judgment when performing network connection control based on a network control list.

Switching the connection destination of managed computers which brings to inside of the company

You can operate the managed computers connect to the management server or the relay system directly when they are brought to inside of the company.

To disable connection to the Internet gateway from managed computers inside of the company, you have to edit both the firewall and proxy server settings. For details, see the description about managing devices used outside the company in the manual JP1/IT Desktop Management 2 Administration Guide.

(2) Precautions for managing devices via Internet connection

You have to observe the following precautions when managing devices via Internet connection:

When communicating with a higher system via the Internet gateway

When managed computers are connected to the internal network

When managed computers are connected to a network outside the company

Switching the connection network of the managed computer

Before the Distribution that Uses Remote Install Manager job to the computer in the internal network environment is completed, if you take the computer out to the Internet environment, the job will be interrupted. The job will resume when the computer reconnected to the internal network environment.

Also, before the Distribution that Uses Remote Install Manager job to the computer in the Internet environment is completed, if you bring the computer back to the internal network environment, the job will also be interrupted. The job will resume when the computer reconnected to the Internet environment.