Windows Thread, WSUS causing me grief! in Technical; Hi Guys / Gals,
Having some problems with some of our machines and WSUS . We have a WSUS server ...
19th November 2010, 12:49 AM #1
- Rep Power
WSUS causing me grief!
Hi Guys / Gals,
Having some problems with some of our machines and WSUS. We have a WSUS server setup and running on a 2008 R2 server. We tell our machines to use this by group policy. If I do a rsop on the clients, I can see they have picked up this policy. However, looking at our firewall logs I see a lot of clients going out to the net using "ms-update" (Its a Palo Alto firewall so it can identify traffic/apps regardless of destination port).
Looking at the WSUS console, it can see all the machines and has seen them all recently. It reports most of them are 99%. This is fine as I never expect to see them at 100%. Im just a bit confused as to why machines are going out to the net. Is there a difference between windows update and ms-update? I know Microsoft release updates for other vendors / drivers etc. Could this be what the clients are going outside for?
IDG Tech News
19th November 2010, 12:21 PM #2
Windows update is what it says- updates for Windows.
Originally Posted by m1ddy
If you want updates for Office, Silverlight... then Microsoft Update is what's needed.
Your network PCs shouldn't be using either of them without an administrator sat in front of the screen doing it manually.
19th November 2010, 08:45 PM #3
They aren't going out to get the root certificates update are they? I can't remember the exact url, but I know because our proxy needs auth that there are always failures in the event log because it can't contact it.
20th November 2010, 07:23 PM #4
- Rep Power
Surely thats impractical if you have several hundred workstations?
Originally Posted by elsiegee40
20th November 2010, 09:06 PM #5
No elsiegee40 means that you should only be using windows update at home. So use WSUS in an environment with many machines.
21st November 2010, 11:25 AM #6
Have you checked the windows updates logs on the individual machines? Do you have your wsus server setup to download and distribute all updates, service packs etc. mine get their office, windows defender and anything else microsoft from the wsus server.
Just a thought as I typed in the words windows defender, are they going online for windows defender updates?
Or are these laptops that are used at home with a local admin user?
24th November 2010, 01:21 PM #7
I'm at home and about to go to bed, but WSUS has an option to use it just for cataloguing and approving updates. When this is enabled, workstations will still download their updates from the internet whilst reporting back to your WSUS box. Perhaps check this? It's in options somewhere. You only need to configure it on your top-most server, replica servers will pull this down.
25th November 2010, 10:45 AM #8
This is the setting I was thinking of...Hopefully this helps with sorting your issue...
By grahamd22 in forum Wireless Networks
Last Post: 12th March 2010, 01:55 PM
By user20085 in forum Wireless Networks
Last Post: 13th May 2008, 03:40 AM
By contink in forum Coding
Last Post: 7th December 2007, 08:58 PM
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)