mbrunt Posted April 17, 2010 Posted April 17, 2010 Our XServe is in the same physical location as our 50 mac clients, and also on the same VLAN as them. Was told that was the only way to apply preferences via WGM and to NetInstall. Howevere, we are now starting to get a few macs dotted about campus and not on the same VLAN, ideally I would like to be able to use WGM to apply preferences to these macs and to netinstall them when needed. When you bind these macs to open directory using directory utility it will bind, but you have to physically type in the server name, rather than it auto appearing in the drop down if the client was on the same vlan as the server. Even when it binds to the server no preferences will apply to it, and WGM cannot see the client. I've managed to get netinstall to work over vlans so im happy about this, but the wgm and the binding issue remains. I could create a mac vlan and put all macs onto this, but i really see that as being defeated and a last option. I would love to be able to move the xserve into our server room, rather than being housed locally in the mac suite. Any ideas welcome!
DMcCoy Posted April 22, 2010 Posted April 22, 2010 Are the bound clients showing up correctly in WGM and are they added to the managed group? It will work across vlans as we do so here. 10.5 or 10.6?
mbrunt Posted April 22, 2010 Author Posted April 22, 2010 Thanks for replying D, the clients are bound to ad and od correctly. In WGM the clients that are not on the same vlan do not show up at all.
nicklec Posted April 22, 2010 Posted April 22, 2010 How exactly are you using VLANs? The server just needs to be a member of both?
DMcCoy Posted April 22, 2010 Posted April 22, 2010 Are you adding the address manually to the client or actually performing the bind function while adding it? Bound machines should show up in the computer list in WGM (at least 3 times in fact, short name, dns name and local kdc name). They will no show on the ... add option as it scans the local subnet.
mbrunt Posted April 22, 2010 Author Posted April 22, 2010 How exactly are you using VLANs? The server just needs to be a member of both? The xserve and imac clients are both on the same vlan. Main servers are on a different VLAN, and each location of college is also on its own VLAN.
mbrunt Posted April 22, 2010 Author Posted April 22, 2010 Are you adding the address manually to the client or actually performing the bind function while adding it? Bound machines should show up in the computer list in WGM (at least 3 times in fact, short name, dns name and local kdc name). They will no show on the ... add option as it scans the local subnet. On the client i've bound it to AD and OD, and then on the server i open up WGM and it does not appear no matter if i use the plus button or the ... button.
DMcCoy Posted April 22, 2010 Posted April 22, 2010 Within the OD settings on the client, on the connection page is a bind button. This will create an account on the OD server for the machine which can then be added to the groups.
mbrunt Posted April 22, 2010 Author Posted April 22, 2010 Within the OD settings on the client, on the connection page is a bind button. This will create an account on the OD server for the machine which can then be added to the groups. I'm sorry I dont understand, the client is already bound to OD.Where is this settings page your talking of?
nicklec Posted April 22, 2010 Posted April 22, 2010 Just to confirm as it doesn't sound like a software problem: Are all the servers in VLANs of machines they need to communicate with?
mbrunt Posted April 22, 2010 Author Posted April 22, 2010 No, the xserve is on the same vlan as the majority of macs, however theres a few elsewhere that are not. Is apples solution to basically put multiple network cards in for each vlan?
nicklec Posted April 22, 2010 Posted April 22, 2010 Are you using vlan tagging? If not then you just need to correct your vlan setup so that each device can actually reach each other... it doesn't sound like anything to do with 'apple' - just a networking problem.
DMcCoy Posted April 22, 2010 Posted April 22, 2010 I'm sorry I dont understand, the client is already bound to OD.Where is this settings page your talking of? There are two options with OD, you can point it at the server "binding it to OD" AND you can use a special bind option during/after the OD settings are entered. The bind option within the OD settings creates an account, much like windows joining the domain. If you simply point it at the OD server then it doesn't get added to the directory and will only show up in the same subnet as the server while powered on. On the open directory settings on the client Directory utility -> Ldapv3 -> Edit -> Connection -> bind
mbrunt Posted April 23, 2010 Author Posted April 23, 2010 (edited) There are two options with OD, you can point it at the server "binding it to OD" AND you can use a special bind option during/after the OD settings are entered. The bind option within the OD settings creates an account, much like windows joining the domain. If you simply point it at the OD server then it doesn't get added to the directory and will only show up in the same subnet as the server while powered on. On the open directory settings on the client Directory utility -> Ldapv3 -> Edit -> Connection -> bind Right ok, I can now see this client in wgm and add it to a group of computers. However, when a user logs on they get any user preferences i've applied (however the dock doesnt appear correctly, it still has stuff in there that ive told it not to have) - but any machine based settings dont apply - for example ive told it display a message at logon, but this doesnt appear. Thanks Edited April 23, 2010 by mbrunt
DMcCoy Posted April 23, 2010 Posted April 23, 2010 Which entry did you add to the group? I think the short name has the mac address on it while the fqdn doesn't. You can see which on it is as it is listed in the account information in wgm. The reason getting the one with the mac address on is because that's what it uses to see if it has to apply any preferences, which is why using multiple vlans means you have to bind as the mac address is not know to the server for other vlans.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now