Jump to content

Recommended Posts

Posted

I am looking to start using WSUS and wondered what the best practice for installing it is? I currently have two DCs but have read that WSUS shouldn't be installed on a DC. Should I look to purchasing a new computer specifically to host WSUS and if so, what spec should I look at? ICT Direct have some nice Dell Optiplex 790s advertised on their website - would one of these do the job: Core i5 2400 processor, 6GB RAM, 250GB HD.

I have 120 client workstations currently on the network.

 

Any advice greatly appreciated!

 

Thanks

  • Thanks 1
Posted
Don't buy a desktop PC to do a server's job - buy a server. Something like a Microserver, or a cheap ICT Direct deal, will be designed to run 24/7 with RAID etc. WSUS is fairly light on CPU and RAM but heavy on storage (potentially, depending on how you configure it). Mine is virtualised with about 300GB of storage, but if you don't have plans to go that way it may pay to get something like a Microserver which can work as a virtual host perfectly well too.
  • Thanks 2
Posted (edited)

I know it mentions you shouldn't install wsus but some of out primary do not have the luxury of buying multiple servers. Our basic setup for primaries is a hyper v box 12 gb ram 2tb storage and a backup box usually dpm. Hv hosting 2 x dc and a file server. Normally that is all they can afford. Dc02 has Wds/sccm and wsus role. It seems to work and they are happy for what they have on a shoe string budget. Haven't read why you shouldn't have wsus on a dc but it doesn't seem to cause any issues

Once their new budgets come in we would look to upgrading the ram and creating new servers for the individual roles but that always seems to be a fight as they alway prioritise the cash elsewhere.

Edited by dapaulio
  • Thanks 1
Posted
I once had wsus flip out on me when installed on a dc. It was not an issue with being on a dc but wsus locked up after a wsus service update and just would not run properly after that. I was left with a dc and a non functioning wsus system. Couldn't even remove the wsus role.
Posted

I've done all three, DC, member server and a virtual server (member). You should generally put it in a virtual server, especially if you're going to adopt Parent > Child setups in larger environments.

 

Also, the other crucial aspect of WSUS is do not auto-approve Updates of any kind (other than maybe Windows Defender updates). Manually approve updates as and when required. So for example I tested the May 2017 CU update for Windows 10 and then deployed it once I was happy it works.

Posted
We also made use of a cleanup script on the server that runs once a month (middle of the month) and tidies up the WSUS installation and it's related directories/databases. Make a huge difference to our server.

 

Get it here: https://community.spiceworks.com/scripts/show/2998-adamj-clean-wsus

 

This. I haven't got it automated yet, but running the cleanup wizard every few months is recommended. This article got me out of jail after I hadn't run the cleanup wizard for a few years! It covers what you'll need to do in terms of maintenance.

Posted
Also, the other crucial aspect of WSUS is do not auto-approve Updates of any kind (other than maybe Windows Defender updates). Manually approve updates as and when required. So for example I tested the May 2017 CU update for Windows 10 and then deployed it once I was happy it works.

 

I think I've only ever come across an update breaking something once, and that was a pretty obscure error several years ago (I can't remember what it was, but it didn't bork computers in an obvious way). We auto-approve most updates, since I can't imagine I could do any testing that would be comprehensive enough so as to be worth holding up critical or security updates.

Posted
I have my auto approve rules slightly different as i have servers and pc's in different groups- Server only get critical updates approved
Posted
I can't imagine I could do any testing that would be comprehensive enough so as to be worth holding up critical or security updates.

 

You may not, but everyone together may - issues with updates tend to spread across Technet, forums etc a little after they are released. By delaying the deployment of them onto your systems, you're letting others do the testing for you, for free! Due to that, and also to ensure at this time of year that I don't disrupt students doing exams on PCs, I manually deploy everything but definition updates. Not a big job, but it has saved my skin quite a few times.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...