What is the best Solution to install MID in the client network?

Sandeep _1
Tera Contributor

What is the best suggestion to install MID in the client network. Is it behind the firewall or outside the firewall? If there is a firewall between MID server and target host, what ports should be open for Discovery? 

2 ACCEPTED SOLUTIONS

AJ-TechTrek
Giga Sage
Giga Sage

Hi @Sandeep _1 

 

(1) If  Interfacing INFRA is On Prem -- Place Mid Server at On Prem and in Closet or Same VLAN.

(2) If Interfacing INFRA is on some cloud -- Place Mid Server at On same cloud  and in Closet or Same network.

Purpose here is to make sure less network hops for packets which will boost the performance.

Details are below.

Best practice around MID Server host selection

 The MID server host is the foundation to which your discoveries will be executed from and should be the only task that this host should provide within your environment or environments.  As of the Istanbul of Service Now

Best practice around MID Server host selection

  1. Virtual Host
    1. 8Gb RAM
    2. 40Gb Disk Allocation
    3. Multi Core/CPU share
    4. Ensure that the virtual environment has capacity to provide for allocation
  2. Operating System
    1. Current Windows Server OS (64 bit)
    2. Provisioned to customers local policies around patches and security
  3. Network
    1. 100MB or greater connection
    2. External internet access on port 443 to your service-now instance
    3. All ports and protocol access to targets within your environment

 It’s all about location

 MIDServer host placement is key to any successful discovery deployment.  The best practice is summed up in a simple statement.  Place your MIDServers as close to the targets that has the most available bandwidth between it and what you are looking to discover.  Deploying a MIDServers in Kansas to discover your Datacenter in Singapore is not the best idea.  By keeping your MIDServer close to targets helps you get the most out of the local resources.

 Items to consider around MIDServer placement include

  1. Available bandwidth
  2. Geographic location
  3. IP access to targets (DMZs)

 How many?

There are three simple rules to determining how many midservers you will need to deploy.

  1. The number of targets you are looking to discover and how often you want to discover them
  2. You want to have midservers at minimum the continent level when looking at a global deployment
  3. Being that the mid communicates outbound only it’s a best practice to place midservers inside secure zones other than opening up many security rules to allow access.

Please appreciate the efforts of community contributors by marking appropriate response as Mark my Answer Helpful or Accept Solution this may help other community users to follow correct solution in future.

 

Thanks

AJ

View solution in original post

Rahul Priyadars
Tera Sage
Tera Sage

Hi Sandeep

 

Long Story Short ...Since Mid Server Needs Internet so i would place my Mid Server in DMZ of My N/W. Many times when you place Mid Server with InterNet Enabled Security team do not like it or Approve it 😞 .

 

From DMZ to Actual Infrastructure - :Ports needs to be Opened based on Source IP (Mid Server Here) for . Since discovery touches many kind of Infrastructure so here is the comprehensive list here from Discovery Stand point.

This list is Super set and you may need less ports opened based on Discovery needs.

 

One Special PORT Needs for Windows WMI Discovery-- WMI discovery Start at Port 135 but later communications happened on higher ports and those also needs to be Opened.

 

49152-65535 for both TCP and UDP.

 

Regards

RP

View solution in original post

10 REPLIES 10

I understand all what you mean and what community is used for  :-).

Pattern Decoded :-0

 

Regards

RP