<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Cross Forest Support in ConfigMgr 2012 Part 2: Forest Discovery, Publishing, and Client Push Installation.</title><link>http://blogs.technet.com/b/neilp/archive/2012/08/21/cross-forest-support-in-configmgr-2012-part-2-forest-discovery-publishing-and-client-push-installation.aspx</link><description>Intro - 
 In the previous &amp;lsquo;simple&amp;rsquo; example the assumption was that a very small group of known clients would be managed. Because of this, relying on basic &amp;lsquo;manual&amp;rsquo; client installation and location lookup mechanisms (manually specified</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Cross Forest Support in ConfigMgr 2012 Part 2: Forest Discovery, Publishing, and Client Push Installation.</title><link>http://blogs.technet.com/b/neilp/archive/2012/08/21/cross-forest-support-in-configmgr-2012-part-2-forest-discovery-publishing-and-client-push-installation.aspx#3567932</link><pubDate>Fri, 19 Apr 2013 16:23:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3567932</guid><dc:creator>Ben</dc:creator><description>&lt;p&gt;Neil. Thank you for the documentation. What would be your recommendations or best practice to manage the following scenario&lt;/p&gt;
&lt;p&gt;I have 4 DMZ no trust relationship in different forest. I want to have only one site server sitting in my corporate network because it is managing three domains (trusted each other). In each DMZ I have 40 and max 270 clients. Can I manage these DMZ clients by opening ports 80/443/8351to my site server? Do I need PKI cert? If yes, how do I setup? Or do I have to put DP/MP/SUP in each DMZ? I prefer the first option to the second one. I might get new DMZ in the near feature and don’t want to add MP\DP for each DMZ created.&lt;/p&gt;
&lt;p&gt;Thank you&lt;/p&gt;
&lt;p&gt;Ben&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3567932" width="1" height="1"&gt;</description></item><item><title>re: Cross Forest Support in ConfigMgr 2012 Part 2: Forest Discovery, Publishing, and Client Push Installation.</title><link>http://blogs.technet.com/b/neilp/archive/2012/08/21/cross-forest-support-in-configmgr-2012-part-2-forest-discovery-publishing-and-client-push-installation.aspx#3562572</link><pubDate>Tue, 02 Apr 2013 01:20:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3562572</guid><dc:creator>Phil Crawford</dc:creator><description>&lt;p&gt;Neil,&lt;/p&gt;
&lt;p&gt;What is missing from both the Cross-Forest planning document and from the above example, is the requirement for the site server which is doing discovery to be able to communicate directly to the DCs in the untrusted forest using LDAP. I have been fighting my security team over this. It appears to need both UDP in both directions and TCP with DC-end at 389 plus, in our environment, 49155.&lt;/p&gt;
&lt;p&gt;It would be really nice if I could get this documented at Microsoft. (I have 2 untrusted forests to manage for servers. No problem with discovery on Test but blocked on Dev.)&lt;/p&gt;
&lt;p&gt;It would have been so much simpler for myself had there been discovery VIA the MP/DP server on the domain. ? an extra Communication Point role for this purpose??&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3562572" width="1" height="1"&gt;</description></item><item><title>re: Cross Forest Support in ConfigMgr 2012 Part 2: Forest Discovery, Publishing, and Client Push Installation.</title><link>http://blogs.technet.com/b/neilp/archive/2012/08/21/cross-forest-support-in-configmgr-2012-part-2-forest-discovery-publishing-and-client-push-installation.aspx#3560941</link><pubDate>Mon, 25 Mar 2013 23:32:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3560941</guid><dc:creator>Joachim83</dc:creator><description>&lt;p&gt;Thanks for the quick reply. I started a topic of this issue where you can find some more detailed information if you are interested: &lt;a rel="nofollow" target="_new" href="http://www.windows-noob.com/forums/index.php?/topic/7815-discovery-not-working-for-untrusted-forest-with-win2012-and-sccm12-sp1/"&gt;www.windows-noob.com/.../index.php&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I though it was caused by a 2012 forest functional level, but when I reinstalled and made all forests and domains 2008R2 level, the same error message appears on two different untrusted domains I created.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3560941" width="1" height="1"&gt;</description></item><item><title>re: Cross Forest Support in ConfigMgr 2012 Part 2: Forest Discovery, Publishing, and Client Push Installation.</title><link>http://blogs.technet.com/b/neilp/archive/2012/08/21/cross-forest-support-in-configmgr-2012-part-2-forest-discovery-publishing-and-client-push-installation.aspx#3560576</link><pubDate>Sat, 23 Mar 2013 19:56:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3560576</guid><dc:creator>Neil Peterson</dc:creator><description>&lt;p&gt;Sorry Joachim - I&amp;#39;ve tried to replicate the issue in my lab by fudging both the connection account and the target LDAP path, but neither produce the same error. Doing some quick research on E_ADS_CANT_CONCERT_DATATYPE produces several results but nothing that stick out. I would consider opening up a case on this if you cannot get yourself get it resolved.&lt;/p&gt;
&lt;p&gt;thanks.&lt;/p&gt;
&lt;p&gt;neilp&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3560576" width="1" height="1"&gt;</description></item><item><title>re: Cross Forest Support in ConfigMgr 2012 Part 2: Forest Discovery, Publishing, and Client Push Installation.</title><link>http://blogs.technet.com/b/neilp/archive/2012/08/21/cross-forest-support-in-configmgr-2012-part-2-forest-discovery-publishing-and-client-push-installation.aspx#3560569</link><pubDate>Sat, 23 Mar 2013 17:52:23 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3560569</guid><dc:creator>Joachim83</dc:creator><description>&lt;p&gt;Hi, I followed this guide and added a untrusted 2012 forest, but and all connection tests are successful, However when I run the the discovery jobs they all give the samme error:&lt;/p&gt;
&lt;p&gt;Active Directory System Discovery Agent failed to bind to container LDAP://DC=VESSEL1,DC=LOCAL. Error: E_ADS_CANT_CONVERT_DATATYPE.&lt;/p&gt;
&lt;p&gt;Any idea what the problem is?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3560569" width="1" height="1"&gt;</description></item><item><title>re: Cross Forest Support in ConfigMgr 2012 Part 2: Forest Discovery, Publishing, and Client Push Installation.</title><link>http://blogs.technet.com/b/neilp/archive/2012/08/21/cross-forest-support-in-configmgr-2012-part-2-forest-discovery-publishing-and-client-push-installation.aspx#3555751</link><pubDate>Fri, 01 Mar 2013 03:23:15 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3555751</guid><dc:creator>Phil Crawford</dc:creator><description>&lt;p&gt;Great Info. But, what about connection requirements for LDAP to non-trusted forest. Specifically, does the site server in this scenario need LDAP connectivity, including high ports, to the DC&amp;#39;s of the non-trusted forest?&lt;/p&gt;
&lt;p&gt;Info in this article is being used to design our multi-forest implementation.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3555751" width="1" height="1"&gt;</description></item><item><title>re: Cross Forest Support in ConfigMgr 2012 Part 2: Forest Discovery, Publishing, and Client Push Installation.</title><link>http://blogs.technet.com/b/neilp/archive/2012/08/21/cross-forest-support-in-configmgr-2012-part-2-forest-discovery-publishing-and-client-push-installation.aspx#3550494</link><pubDate>Tue, 05 Feb 2013 17:21:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3550494</guid><dc:creator>Bryan Nettles</dc:creator><description>&lt;p&gt;-edit- Will be using this article to help plan a deployment in my environment.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3550494" width="1" height="1"&gt;</description></item><item><title>re: Cross Forest Support in ConfigMgr 2012 Part 2: Forest Discovery, Publishing, and Client Push Installation.</title><link>http://blogs.technet.com/b/neilp/archive/2012/08/21/cross-forest-support-in-configmgr-2012-part-2-forest-discovery-publishing-and-client-push-installation.aspx#3550493</link><pubDate>Tue, 05 Feb 2013 17:21:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3550493</guid><dc:creator>Bryan Nettles</dc:creator><description>&lt;p&gt;Great info. Will be using to plan a deployment in my environment.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3550493" width="1" height="1"&gt;</description></item></channel></rss>