The Central Management System appliance can act as the DTI source for its managed appliances to download software updates (such as security content, guest images, and system images). In a dual-port configuration, management traffic goes through the SSH port, and DTI traffic goes through the HTTPS port. When the Central Management System appliance is behind a NAT gateway, it has an internal IP address that the managed appliances cannot reach.
In this environment, you must configure and activate an accessible address that the managed appliances will use as the DTI source for software updates. This address is the virtual NAT IP address and port that are mapped to the Central Management System internal IP address and port 443. For details, see Switching to single-port or dual-port Communication in a NAT deployment.
The accessible DTI server address must be configured and activated on each managed appliance. In addition, on managed appliances running a supported release (see note below), a "no override" flag needs to be set to prevent the default Central Management System address from overriding the accessible address.
Important
Any managed appliances behind the same NAT gateway as the Central Management System appliance will use the default Central Management System appliance as their DTI source and require no additional configuration.
An accessible DTI server address is required only in a dual-port configuration. If you change from dual-port to single-port communication, you must remove the "no override" flag and instead set an "override" flag to allow the Central Management System appliance to push the single-port settings to the managed appliance. For details, see Switching to single-port or dual-port communication in a NAT deployment.
Admin access