Client connecting to Relay via VPN

Hi,

At present, as you know, Home Office is a new way to work and Bigfix is very important in this topic
Something that client concern is how we are in applying patches and delivering packages from bigfix across VPN connection
which are the schemes to ensure that Bigfix can complete distribution tasks.
few weeks ago, we made some test to verify that packages are being delivered by bigfix and has been succeeded and we confirm that this occurs.
Ping command are succeeded too from bigfix to laptop across VPN Connection, just we notice that sometimes laptops are not reporting to console as frequently as machines do on bigfix server.

After all this story questions are:

Is something that can be configured in Bigfix to ensure that laptops made a heart beat constantly to report in bigfix console?
Is something in infrastructure that can be implemented (may be a relay or server) in VPN perimeter to ensure communication with workstations connected to VPN?
Is there any parameter (DNS, Gateway) or port that should be enabled to ensure constant communication between bigfix console and endpoint agent?
I comment to you all this, because we notice that some laptops (mainly through a VPN connection) even when they are on the network, bigfix doesn’t recognize from time to time

Regards,
Shaban

There are several recent threads discussing this topic. I suggest reviewing this one and this one.

The nutshell version is that when you have a combination of DMZ and VPN relays with appropriate throttling and policy actions for clients with proper affiliation for DMZ or VPN relay versus internal relays, the system works well. Setting polling and DMZ session persistence are the other important ingredients.

2 Likes

In addition to what JonL posted, I would suggest starting small and simple testing before going on to more complicated scenarios. Verify that all the appropriate ports configured correctly in your infrastructure. Sometimes UDP inbound to a client is disabled intentionally. Then perhaps investigate other more complicated options (throttling, affiliations and seek lists).