ParallelsU61
Bit poster
Hi from France.
The documentation tells that we have to allow incoming connections to PMM Agent.
My first question is : why (is it a requirement) ? And more subtle, my second question is : when (does it become a requirement) ?
For the first question, my wish would be that only ascending connections from the client to the proxy occur.
I have to admit that with a MDM managing Mac, this is possible due to the APNs centerpiece. OK.
But for the second question, I need to know when allowing incoming connections becomes a requirement. Explanation.
In my workflow, I have a Configuration Item (configuration profile created with Profile Manager) that starts the Firewall without explicitely allowing connections to PMM Agent (default configuration of the Firewall).
We should not have to do this setting if the binary was signed (like the McAfee Agent for example).
Then as soon as my Mac is enrolled in PMM, a package containing multiple scripts is planned to install silently and you guessed it, one of these scripts is responsible to configure the Firewall so incoming connections are allowed to the PMM Agent (and possibly other pieces of non-signed software).
So it is a 2 steps configuration.
The reason I asked this question is that in my actual implementation, the packages are hardly installed on the Macs (Baseline installation is ok). Waiting an hour does not make the trick, clicking on the "Connect" button almost constantly drives to a time out (but sometime it works). The beginning of an explanation could be that the Firewall needs to allow incoming connections to the PMM Agent as soon as the Mac is enrolled. But because I don't know why the Proxy may need to contact the Agent to "push" a package (even if the Agent pulls the package), I don't want to find a solution to implement the incoming connections authorization in the Profile Manager configuration profile (I tried to install the PMM Agent temporarily on the Mac but the Profile Manager GUI does not show the PMA Agent as an application to be added to the Firewall exceptions).
Best regards.
The documentation tells that we have to allow incoming connections to PMM Agent.
My first question is : why (is it a requirement) ? And more subtle, my second question is : when (does it become a requirement) ?
For the first question, my wish would be that only ascending connections from the client to the proxy occur.
I have to admit that with a MDM managing Mac, this is possible due to the APNs centerpiece. OK.
But for the second question, I need to know when allowing incoming connections becomes a requirement. Explanation.
In my workflow, I have a Configuration Item (configuration profile created with Profile Manager) that starts the Firewall without explicitely allowing connections to PMM Agent (default configuration of the Firewall).
We should not have to do this setting if the binary was signed (like the McAfee Agent for example).
Then as soon as my Mac is enrolled in PMM, a package containing multiple scripts is planned to install silently and you guessed it, one of these scripts is responsible to configure the Firewall so incoming connections are allowed to the PMM Agent (and possibly other pieces of non-signed software).
So it is a 2 steps configuration.
The reason I asked this question is that in my actual implementation, the packages are hardly installed on the Macs (Baseline installation is ok). Waiting an hour does not make the trick, clicking on the "Connect" button almost constantly drives to a time out (but sometime it works). The beginning of an explanation could be that the Firewall needs to allow incoming connections to the PMM Agent as soon as the Mac is enrolled. But because I don't know why the Proxy may need to contact the Agent to "push" a package (even if the Agent pulls the package), I don't want to find a solution to implement the incoming connections authorization in the Profile Manager configuration profile (I tried to install the PMM Agent temporarily on the Mac but the Profile Manager GUI does not show the PMA Agent as an application to be added to the Firewall exceptions).
Best regards.