The provisioning server address can be a split DNS that resolves differently depending on whether the host on which the agent is installed is operating inside or outside your company’s internal network. When the agent is inside the network, the DNS resolves to the internal Endpoint Security (HX) server; when the agent is outside the network, the DNS resolves to the DMZ server.
Admin or fe_services access
A split DNS set up to resolve to your internal Endpoint Security (HX) server when the agent is inside the network and to the DMZ server when the agent is outside the network.
Using the Web UI, enable both your primary Endpoint Security (HX) server and your DMZ server for provisioning. See Designating the Endpoint Security server as a provisioning server using the Web UI and Designating and enabling a DMZ server as a provisioning server.
In the Web UI, select Appliance Settings on the Admin menu. The Agent Versions page appears.
Select the Server Addresses tab.
Enter the DNS name or IP address and click Add.
If the endpoints in your environment have xAgent software versions earlier than version 20 installed, select Set as Primary to designate the DNS as the provisioning server. This will deselect any other appliance on the Server Addresses page as the primary server.
If the endpoints in your environment have xAgent software version 20 or later installed, select Enable Provisioning to designate the DNS server as a provisioning server.
Click Save.