Jump to content

Recommended Posts

Posted

I've checked a few of these but they appear to be clean images. The only thing I did notice is the latest version of Sophos has something called the protection service running, which hits the firewall every few seconds - obviously trying to bypass the proxy. I've disabled that service and theres now no firewall access at all from the test PC.

 

The two errors now seem to be the 'timeout' or 'max server round trip exceeded' types, which suggests a connectivity issues but the clients are connected as a gig to the switches, and the vm is running on a new server with only a couple of other low use vm's. I'm probably going to try removing wsus from the clients next and see if they will pull critical updates direct from MS servers.

Posted
Have you tried temporarily disabling sophos on a client that's playing up? Endpoint security apps have borked WU/WSUS more than once. An examination of the firewall logs may show it blocking stuff at the time the client is trying to update.
Posted

Right, this is getting weirder! Normally our winhttp proxy is set to None, as the clients should hit wsus. But for the sake of it I set one machine to import IE settings (which uses the proxy for all but local addresses) and left it running.

 

Now that machine has connected to WSUS, pulled down a load of updates and seems correct! And looking at the proxy logs it did use the proxy for some microsoft sites (they looked like certificate revocation lists)

 

So I'll try another couple and see if they do the same - it seems that even if winhttp is set to ignore the proxy it still needs to get out for some things?

Posted
Right, this is getting weirder! Normally our winhttp proxy is set to None, as the clients should hit wsus. But for the sake of it I set one machine to import IE settings (which uses the proxy for all but local addresses) and left it running.

 

Now that machine has connected to WSUS, pulled down a load of updates and seems correct! And looking at the proxy logs it did use the proxy for some microsoft sites (they looked like certificate revocation lists)

 

So I'll try another couple and see if they do the same - it seems that even if winhttp is set to ignore the proxy it still needs to get out for some things?

 

This sounds like a problem I had recently.

 

School wanted the free version of MS OneNote 2016 installed onto PCs but it could not connect Online through our proxy setup in Internet Options. I allowed all the necessary websites access through the proxy but it still wouldn't connect online. I then tried importing IE settings into WinHTTP, rebooted the PC and it was then able to connect online and I could use OneNote.

 

Microsoft products ignoring Internet Options connection settings for Online access? good job Microsoft.

Posted
This sounds like a problem I had recently.

 

School wanted the free version of MS OneNote 2016 installed onto PCs but it could not connect Online through our proxy setup in Internet Options. I allowed all the necessary websites access through the proxy but it still wouldn't connect online. I then tried importing IE settings into WinHTTP, rebooted the PC and it was then able to connect online and I could use OneNote.

 

Microsoft products ignoring Internet Options connection settings for Online access? good job Microsoft.

 

Well it hasn't really fixed my problem, I set a GPO to specify our proxy for winhttp (and exclude local addresses) and its only brought a handful online as far as wsus is concerned. I guess I'd be better leaving it for a for days to see if any more pick up.

Posted

Back to square one for me, some clients reporting in, some did once and won't anymore and most just won't report in with either the 80072EE2 error or lots of 0x80244010 if I login and try to run the updates manually.

 

Changing the winhttp proxy hasn't made any difference, it must have just been a fluke on the couple that started working - even they haven't reported in since.

 

Since the only thing I did was VM the WSUS server I'm completely at a loss to understand why WSUS has comprehensively failed on me!

Posted

Hi Sheridan,

 

Not sure how helpful this may be but are you still running windows 7 and windows 10?

 

If you have windows 10 clients I do not think server 2008 can service them and if you are still trying server 2012 / 2012 r2 as your WSUS it must be fully patched and the manual steps completed: https://support.microsoft.com/en-gb/kb/3159706

 

When my clients were still on Windows 8.1 and I was looking to move to Windows 10 but did not do the above steps none of my clients would connect to WSUS - I am not saying this is the same issue as you are having but worth a look and if you are still using 2008 as your WSUS but have Windows 10 clients this could be your problem as I believe to service windows 10 you must be running Server 2012 / 2012 r2

Posted
Hi Sheridan,

 

Not sure how helpful this may be but are you still running windows 7 and windows 10?

 

If you have windows 10 clients I do not think server 2008 can service them and if you are still trying server 2012 / 2012 r2 as your WSUS it must be fully patched and the manual steps completed: https://support.microsoft.com/en-gb/kb/3159706

 

When my clients were still on Windows 8.1 and I was looking to move to Windows 10 but did not do the above steps none of my clients would connect to WSUS - I am not saying this is the same issue as you are having but worth a look and if you are still using 2008 as your WSUS but have Windows 10 clients this could be your problem as I believe to service windows 10 you must be running Server 2012 / 2012 r2

 

I'm running WSUS back on Server 2008 and servicing both W7 and W10 - but only a dozen W10 machines.

 

Now, the oddest part is that ALL of the W10 machines are checking in and updating correctly. Go figure!

Posted (edited)

It may be worth looking at these:

 

https://blogs.technet.microsoft.com/wsus/2016/01/22/for-those-on-wsus-3-0-sp2-or-sbs-2011/

 

https://blogs.technet.microsoft.com/wsus/2016/09/15/update-on-wsus-3-0-sp2-end-of-life/

 

Another good place to look would be on Steve Henry TechNet profile (https://social.technet.microsoft.com/Profile/Steve%2bHenry%2b%5BMSFT%5D/activity) as he has written the above - works at Microsoft and deals with WSUS.

 

I hope you do not think that I am trying to push you to WSUS via server 2012 / 2012 r2 or even 2016 but if you are planning on Windows 10 you might have better luck with WSUS on server 2012 r2 full patched with the manual steps completed - link again: https://support.microsoft.com/en-gb/kb/3159706 but I do understand that you have already tried WSUS on server 2012 so again sorry if this is not helpful.

Edited by abaxter2
Posted
The 4010 is a "better" error to have as it is typically transient and almost expected if you deleted the softwaredistribution folder with the typical "nuke and pave" client reset script. Have you run WU (hitting your WSUS server) several times on a 4010 machine manually - even though it fails, it should be building a cache and adding to it at each failure?
Posted

Well I've reopened the 2012 WSUS server and pointed a limite set of client to that. So far 2 have reported in - one working and one not yet reported!

 

The second one is the 4010 error so I'll have to give it some time first!

Posted

Having the same issues here, WSUS and the reporting to and from the clients has been on and off, taking an age for clients to report back to the console.

Some report and update fine, others just sit there with "Not yet reported".

Any advice would be apreciated!

Posted
I'm still in the same boat, back with WSUS on 2012 - about 2/3 have reported in, the others not. Exactly the same PCs and image in this case as I've limited the WSUS to just a specific OU. I'm still looking at it on and off but I'm awaiting some inspiration at the moment!
Posted
I'm still in the same boat, back with WSUS on 2012 - about 2/3 have reported in, the others not. Exactly the same PCs and image in this case as I've limited the WSUS to just a specific OU. I'm still looking at it on and off but I'm awaiting some inspiration at the moment!

 

Compare installed update lists on functioning and not for KB3145739 presence.

Posted
Sorry if this is no use but have you checked that your firewall is not blocking connections to your wsus on hyper v / VM? I know that symantec endpoint block traffic with the default rule
Posted
Compare installed update lists on functioning and not for KB3145739 presence.

 

Uninstalled this yesterday as a test on one client, still no update from this client.

Posted (edited)
Sorry if this is no use but have you checked that your firewall is not blocking connections to your wsus on hyper v / VM? I know that symantec endpoint block traffic with the default rule

 

Our PCs have a firewall rule to allow access on port 8530 to internal servers, and even testing with the firewall switched off seemed to make no difference.

 

Is KB3145739 known to break wsus at the client end then?

 

We have also noticed the ones that did check in to the new WSUS server a few days ago haven't checked in since! They are show clean logs apart from the error "WARNING: Cached cookie has expired or new PID is available" which crops up every time they connect.

Edited by Sheridan
Posted
Our PCs have a firewall rule to allow access on port 8530 to internal servers, and even testing with the firewall switched off seemed to make no difference.

 

Is KB3145739 known to break wsus at the client end then?

 

We have also noticed the ones that did check in to the new WSUS server a few days ago haven't checked in since! They are show clean logs apart from the error "WARNING: Cached cookie has expired or new PID is available" which crops up every time they connect.

 

Is that aso with the firewall off on the hyper v / VM host? or just on the clients? Also sorry if this is real low level but is there a firewall rule in place to allow access to the ip address and not just the port?

Posted
Is that aso with the firewall off on the hyper v / VM host? or just on the clients? Also sorry if this is real low level but is there a firewall rule in place to allow access to the ip address and not just the port?

 

Basically yes to all! Firewall ports opne 8530/1 for server and clients for entire subnet.

Posted
Im not sure its a FW issue as we have ones that are updating correctly upto today, just few and far between though!, where as a few months ago the entire fleet would have reported in by now (switched on PC`s of course)
Posted
Im not sure its a FW issue as we have ones that are updating correctly upto today, just few and far between though!, where as a few months ago the entire fleet would have reported in by now (switched on PC`s of course)

 

Exactly the same here. Can't see a pattern on the ones that are working to the ones that aren't.

Posted

@Sheridan -- sorry, should have been more explicit. The ABSENCE of that update has been known to cause long searches.

 

Does your SERVER have KB3148812, KB3159706, both, or none installed? - and are the test OU machines 7, 10, or a mix?

Posted
@Sheridan -- sorry, should have been more explicit. The ABSENCE of that update has been known to cause long searches.

 

Does your SERVER have KB3148812, KB3159706, both, or none installed? - and are the test OU machines 7, 10, or a mix?

 

Our Server has neither of these updates

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...