You are looking guidance on how to properly install and configure Cloud-Enabled Management (CEM) in IT Management Suite (ITMS) 8.7 and 8.8 to allow managed endpoints to communicate securely over the Internet.
Common reported symptoms include:
Internet-based agents not reporting to the Notification Server
Internet Gateway not appearing as “Online”
Agents failing to switch from intranet to cloud communication
Certificate or IIS binding errors
ITMS 8.7.x and 8.8.x
Cloud-Enabled Management (CEM) enables managed endpoints to securely communicate with the Notification Server (NS) over the Internet using the Internet Gateway (IG).
In ITMS 8.7 and 8.8, proper CEM configuration requires:
Valid public SSL certificates
Proper IIS configuration
Internet Gateway installation and registration
Correct agent policy assignment
Open firewall ports
Misconfiguration of any of these components commonly prevents cloud-based agent communication.
Most CEM deployment failures are caused by one or more of the following:
Incorrect or missing SSL certificate bindings in IIS
Internet Gateway not properly registered with the Notification Server
Firewall blocking required HTTPS traffic (default 443)
Cloud-Enabled Management policy not applied to agents
Expired or revoked CEM certificates
Setting up and configuring your environment for Cloud-enabled Management requires some pre-work and preparation on the network side of things. The main documents that you should start with are:
Cloud-enabled Management for ITMS
About Cloud-Enabled Management
Cloud Enabled Management (CEM) High Level Implementation Guide
The general guidance for configuration sequence is as below:
Important: Always configure components based on your network needs.
Ensure:
Public DNS name resolves externally
Port 443 is open externally
Valid public SSL certificate installed
Server meets ITMS 8.7 / 8.8 requirements
In the SMP Console, go to:
Settings > Notification Server > Cloud-enabled Management
Download the Internet Gateway installation package.
Install on a dedicated server in the DMZ.
During installation, provide:
Notification Server FQDN
Certificate information
On the Internet Gateway server:
Symantec Internet Gateway Service = Running
Check logs:
C:\ProgramData\Symantec\SMP\Logs\
Select Default Web Site
Click Bindings
Ensure HTTPS binding:
Port 443
Correct public certificate assigned
Status reporting
Go to:
Manage > Policies > Agents/Plug-ins > Cloud-enabled Management Settings
Edit the Default Cloud-Enabled Management Settings Policy.
Enable:
Allow cloud communication
Assign policy to appropriate target.
Navigate to:
Settings > Notification Server > Cloud-enabled Management
Generate Offline Package
Install on endpoint manually
| Symptom | Log Location | Likely Cause | Action |
|---|---|---|---|
| IG not Online | a.log | Registration failure | Re-run IG configuration |
| Agent not switching | agent.log | Policy not applied | Check policy targeting |
| 403 IIS error | IIS logs | Certificate binding issue | Verify HTTPS binding |
| Certificate revoked | agent.log | Expired certificate | Revoke and regenerate |
Revoke CEM certificate if compromised
Back up Internet Gateway configuration
View site server certificates
Configure F5 BIG-IP LTM if load balancing traffic
Review CEM reports
| Component | Path |
|---|---|
| Notification Server | C:\ProgramData\Symantec\SMP\Logs |
| Internet Gateway | C:\ProgramData\Symantec\SMP\Logs |
| Agent | C:\ProgramData\Symantec\SMA\Logs |
Agent appears in console as Internet-connected
IG shows Online
Policies update successfully
Inventory uploads complete
Other follow-up topics that can assist you to configure your CEM implementation:
Preparing Your Environment for Cloud-enabled Management
Setting up Cloud-Enabled Management
Configuring the Cloud-Enabled Management Agent IIS Website Settings
About Preparing the Internet Gateway Computer
Downloading and Running the Internet Gateway Installation Package
Configuring the Internet Gateway
Enabling the Internet Gateway Status Reporting
Configuring Sites and Site Servers to Serve Cloud-enabled Agents
Configuring the Cloud-Enabled Management Settings Policy
Generating and Installing the Cloud-Enabled Management Offline Package
Cloud-Enabled Management Troubleshooting and Maintenance Tasks
Revoking a Cloud-enabled Management certificate
Viewing the site server certificates
Forcing the Symantec Management Agent to use a specified Internet gateway
Backing up and restoring an Internet gateway
Viewing Cloud-enabled Management reports