Prerequisites and requirements

Read this section to learn the prerequisites to set up HCL Now MCM deployment.

The following are the pre-requisites to set up the HCL Now hybrid MCM environment:

Authenticating Relay
Authenticating relay is required to proxy communications between the BigFix MDM cloud infrastructure and the on-premise BigFix Enterprise server and WebUI. To support MCM deployment, the Authenticating relay must be an RHEL relay. The following identifying information for the Authenticating relay needs to be provided as part of the cloud registration process:

DMZ Relay (FQDN): Auth Relay FQDN - Example: customer.demo.bigfix.com

Secure Registration Pass phrase: Pass phrase for authenticating relay

Deployment Port: Usually 52311

BigFix agent masthead

BigFix MDM components in the cloud environment need to communicate with the on-prem BigFix environment to do this the BigFix deployment masthead and the associated client settings need to be provided.

At cluster startup, the PlugIn Portal pod establishes persistent connections to this BigFix Relay using the credentials supplied.

Deployment Masthead File: <masthead>.afxm
Organization Name (for profiles)

Organization name of the customer. This shows up in various MDM profiles on the enrolled endpoint and must reflect the name of the organization.

Apple, Windows and Android push notification credentials
Organizations have to create a relationship with the OS providers to obtain credentials that allow them to use push notifications. The organization is responsible for providing these credentials to the Hybrid BigFix MDM provider as part of environment setup.

Organizations need to obtain and provide their own Apple Push notification certificate, WNS credentials for Windows, and Google credentials for Android and share the information with HCL. This information must include the following:

LDAP Connection information
At the time of MDM device enrollment, MDM server validates if a user is authorized to perform an MDM enrollment by authenticating email address of the enrolling user through LDAP. For this, the BigFix MDM server needs access to the organization’s LDAP server. The following information is required:
  • LDAPS URL
  • The Base Distinguished Name (base DN)
  • The Bind Distinguished Name (bind DN)
  • The bind password

If the organizations LDAP server is not accessible by the Hybrid BigFix MDM server, an LDAPS Proxy may be required in the organization DMZ.

Important: Port 636 TCP proxy access must be available in the target BigFix deployment, and this must be running a Trusted CA signed TLS certificate.
TCP/IP Port requirements

For BigFix to communicate properly with the cloud based BigFix MDM infrastructure the authenticating relay port (52311 by default) needs to be accessible in the DMZ.

Additionally, if the deployment is using a on-prem LDAP proxy port 636 is required to be accessible in the DMZ.