Prerequisites and requirements
Read this section to learn the prerequisites to set up HCL Now MCM deployment.
The following are the pre-requisites to set up the HCL Now hybrid MCM environment:
- Licenses for MDM and/or BigFix Mobile
- Current version of WebUI release installed in the organization’s BigFix environment
-
The following key information of the organization shared with HCL
- TCP/IP Port requirements
- Authenticating Relay
- Authenticating relay is required to
proxy communications between the BigFix MDM cloud infrastructure and the
on-premise BigFix Enterprise server and WebUI. To support MCM deployment,
the Authenticating relay must be an RHEL relay. The following identifying
information for the Authenticating relay needs to be provided as part of the
cloud registration process:
DMZ Relay (FQDN): Auth Relay FQDN - Example: customer.demo.bigfix.com
Secure Registration Pass phrase: Pass phrase for authenticating relay
Deployment Port: Usually 52311
- BigFix agent masthead
BigFix MDM components in the cloud environment need to communicate with the on-prem BigFix environment to do this the BigFix deployment masthead and the associated client settings need to be provided.
At cluster startup, the PlugIn Portal pod establishes persistent connections to this BigFix Relay using the credentials supplied.
Deployment Masthead File: <masthead>.afxm
- Organization Name (for profiles)
-
Organization name of the customer. This shows up in various MDM profiles on the enrolled endpoint and must reflect the name of the organization.
- Apple, Windows and Android push notification credentials
- Organizations have to create a relationship with the OS providers to obtain credentials that allow them to use push notifications. The organization is responsible for providing these credentials to the Hybrid BigFix MDM provider as part of environment setup.
- LDAP Connection information
- At the time of MDM device enrollment, MDM server validates if a user is
authorized to perform an MDM enrollment by authenticating email address of
the enrolling user through LDAP. For this, the BigFix MDM server needs access
to the organization’s LDAP server. The following information is required:
- LDAPS URL
- The Base Distinguished Name (base DN)
- The Bind Distinguished Name (bind DN)
- The bind password
If the organizations LDAP server is not accessible by the Hybrid BigFix MDM server, an LDAPS Proxy may be required in the organization DMZ.
Important: Port 636 TCP proxy access must be available in the target BigFix deployment, and this must be running a Trusted CA signed TLS certificate.
- TCP/IP Port requirements
-
For BigFix to communicate properly with the cloud based BigFix MDM infrastructure the authenticating relay port (52311 by default) needs to be accessible in the DMZ.
Additionally, if the deployment is using a on-prem LDAP proxy port 636 is required to be accessible in the DMZ.