1.3 Satellite Requirements

A is a managed device that can perform some of the roles that a ZENworks Primary Server normally performs, including authentication, information collection, content distribution, and imaging. A Satellite can be any managed Windows, Macintosh or Linux device (server or workstation), but not a Primary Server.

The following sections contain more information:

1.3.1 Windows Device Performing Satellite Roles

In addition to their usual functions, Windows devices can be used as satellites. Make sure that when you use these managed devices for satellites, they are capable of performing the satellite functions.

A Windows device performing satellite roles must meet the minimum requirements of a Windows managed device listed in Section 1.2.1, Windows Managed Device Requirements with the following exceptions:

  • Windows Embedded XP is not a supported workstation operating system for Satellite devices.

  • Satellite devices require additional TCP and UDP ports to be open.

The following table lists the additional TCP and UDP ports that must be open on a Satellite device:

Table 1-4 Additional Ports Required for a Managed Device Performing Satellite Roles

Item

Requirements

Additional Details

Firewall Settings: TCP Ports

80

If you plan to use AdminStudio ZENworks Edition, it requires that the Primary Server is using port 80.

 

443

Port 443 is used for CASA authentication. Opening this port allows ZENworks 11 to manage devices outside of the firewall. It is a good practice to make sure that the network is configured to always allow communication on this port between the ZENworks Server and ZENworks Agents on managed devices.

998

Used by Preboot Server (novell-pbserv).

The Preboot Server (novell-pbserv) is used only with ZENworks Configuration Management.

Firewall Settings: UDP Ports

67

Used by proxy DHCP when it is not running on the same device as the DHCP server.

 

69

Used by the Imaging TFTP, but will not work across firewall because it opens random UDP port for each PXE device.

The Imaging TFTP is used only with ZENworks Configuration Management.

 

997

Used by the Imaging Server for multicasting.

The Imaging Server is used only with ZENworks Configuration Management.

 

4011

Used for proxy DHCP when it is running on the same device as the DHCP server. Make sure that the firewall is configured to allow the broadcast traffic to the proxy DHCP service.

 

13331

Used by the zmgpreboot policy, but will not work across firewall because it opens random UDP port for each PXE device.

The zmgpreboot policy is used only with ZENworks Configuration Management.

1.3.2 Linux Device Performing Satellite Roles

A Linux device performing satellite roles must meet the minimum requirements of a Linux managed device listed in Section 1.2.2, Linux Managed Device Requirements.

The following table lists the additional TCP and UDP ports that must be open on a Satellite device:

Table 1-5 Linux Device Performing Satellite Roles Requirements

Item

Requirements

Additional Details

TCP Ports

80

80 is for Tomcat non-secure port.

If the server is running other services on ports 80 and 443, such as Apache, or are used by OES2, the installation program asks you for new ports to use.

 

998

Used by Preboot Server (novell-pbserv).

The Preboot Server (novell-pbserv) is used only with ZENworks Configuration Management.

 

7628

Used by the Adaptive Agent.

 

8005

Used by Tomcat to listen to shutdown requests. This is a local port, and cannot be accessed remotely.

 

8009

Used by Tomcat AJP connector.

UDP Ports

67

Used by proxy DHCP when it is not running on the same device as the DHCP server.

 

69

Used by the Imaging TFTP, but will not work across firewall because it opens random UDP port for each PXE device.

The Imaging TFTP is used only with ZENworks Configuration Management.

 

997

Used by the Imaging Server for multicasting.

The Imaging Server is used only with ZENworks Configuration Management.

 

4011

Used for proxy DHCP when it is running on the same device as the DHCP server. Make sure that the firewall is configured to allow the broadcast traffic to the proxy DHCP service.

 

13331

Used by the zmgpreboot policy, but will not work across firewall because it opens random UDP port for each PXE device.

The zmgpreboot policy is used only with ZENworks Configuration Management.