kennysarmy Posted May 16, 2017 Posted May 16, 2017 (edited) Been regularly doing the MS updates manually on our Servers recently as, well it just seems easier. But on checking WSUS I've noticed that only a few of my Servers are showing on the console. In comparing a Server which is working as expected with one that is n't I'm seeing errors in the "WindowsUpdate.log" file on the server. working : 2017-05-16 12:33:47:882 740 10b4 EP Got WSUS SimpleTargeting URL: "http://xxx:8530" 2017-05-16 12:33:47:882 740 10b4 IdleTmr WU operation (CAuthorizationCookieWrapper::InitializeSimpleTargetingCookie) started; operation # 8; does use network; is at background priority 2017-05-16 12:33:47:897 740 10b4 PT Initializing simple targeting cookie, clientId = 99e38e4d-d573-4830-a57a-82f5f27f5e7f, target group = Servers, DNS name = fp4.curriculum.local 2017-05-16 12:33:47:897 740 10b4 PT Server URL = http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx 2017-05-16 12:33:48:038 740 10b4 IdleTmr WU operation (CAuthorizationCookieWrapper::InitializeSimpleTargetingCookie, operation # 8) stopped; does use network; is at background priority 2017-05-16 12:33:48:038 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::GetCookie_WithRecovery) started; operation # 9; does use network; is at background priority 2017-05-16 12:33:48:054 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::GetCookie_WithRecovery, operation # 9) stopped; does use network; is at background priority 2017-05-16 12:33:48:085 740 10b4 Agent Reading cached app categories using lifetime 604800 seconds 2017-05-16 12:33:48:085 740 10b4 Agent Read 0 cached app categories 2017-05-16 12:33:48:085 740 10b4 Agent SyncUpdates adding 0 visited app categories 2017-05-16 12:33:49:835 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::SyncUpdates_WithRecover) started; operation # 10; does use network; is at background priority 2017-05-16 12:33:49:835 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::SyncUpdates_WithRecover, operation # 10) stopped; does use network; is at background priority 2017-05-16 12:33:49:851 740 10b4 Agent Reading cached app categories using lifetime 604800 seconds 2017-05-16 12:33:49:851 740 10b4 Agent Read 0 cached app categories 2017-05-16 12:33:49:851 740 10b4 Agent SyncUpdates adding 0 visited app categories 2017-05-16 12:33:49:866 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::SyncUpdates_WithRecover) started; operation # 11; does use network; is at background priority 2017-05-16 12:33:49:897 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::SyncUpdates_WithRecover, operation # 11) stopped; does use network; is at background priority 2017-05-16 12:33:49:913 740 10b4 PT + SyncUpdates round trips: 2 2017-05-16 12:33:52:288 740 10b4 PT +++++++++++ PT: Synchronizing extended update info +++++++++++ 2017-05-16 12:33:52:288 740 10b4 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://xxx:8530/ClientWebService/client.asmx 2017-05-16 12:33:52:304 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::GetExtendedUpdateInfo_WithRecovery) started; operation # 12; does use network; is at background priority 2017-05-16 12:33:52:304 740 10b4 IdleTmr WU operation (CAgentProtocolTalker::GetExtendedUpdateInfo_WithRecovery, operation # 12) stopped; does use network; is at background priority 2017-05-16 12:33:52:616 740 10b4 Agent WARNING: Fail to download eula file http://xxx:8530/Content/13/33D8A4B8183134CA79120BB436C18DDAB713E713.txt with error 0x80246003 2017-05-16 12:33:52:694 740 10b4 Agent * Found 0 updates and 88 categories in search; evaluated appl. rules of 821 out of 1517 deployed entities 2017-05-16 12:33:52:757 740 10b4 Agent Reporting status event with 1 installable, 159 installed, 0 installed pending, 0 failed and 0 downloaded updates 2017-05-16 12:33:52:757 740 10b4 Agent ********* 2017-05-16 12:33:52:757 740 10b4 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates Id = 1] 2017-05-16 12:33:52:772 740 10b4 Agent ************* 2017-05-16 12:33:52:772 740 10b4 IdleTmr WU operation (CSearchCall::Init ID 1, operation # 7) stopped; does use network; is at background priority 2017-05-16 12:33:52:772 740 a98 AU >>## RESUMED ## AU: Search for updates [CallId = {73538518-F042-4651-9B80-FDE2060C7D30} ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}] 2017-05-16 12:33:52:772 740 a98 AU # 0 updates detected not working: 2017-05-16 13:04:15:680 776 f90 EP Got WSUS SimpleTargeting URL: "http://xxx:8530" 2017-05-16 13:04:15:680 776 f90 IdleTmr WU operation (CAuthorizationCookieWrapper::InitializeSimpleTargetingCookie) started; operation # 374; does use network; is at background priority 2017-05-16 13:04:15:680 776 f90 PT Initializing simple targeting cookie, clientId = 99e38e4d-d573-4830-a57a-82f5f27f5e7f, target group = Servers, DNS name = fp5.curriculum.local 2017-05-16 13:04:15:680 776 f90 PT Server URL = http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx 2017-05-16 13:04:15:696 776 f90 WS WARNING: Nws Failure: errorCode=0x803d001a 2017-05-16 13:04:15:696 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'. 2017-05-16 13:04:15:696 776 f90 WS WARNING: The server returned HTTP status code '407 (0x197)' with text 'Proxy Authentication Required'. 2017-05-16 13:04:15:696 776 f90 WS WARNING: The proxy requires HTTP authentication scheme 'NTLM'. 2017-05-16 13:04:16:743 776 f90 WS WARNING: Nws Failure: errorCode=0x803d0000 2017-05-16 13:04:16:743 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'. 2017-05-16 13:04:16:743 776 f90 WS WARNING: The content type 'text/html' did not match the expected value 'text/xml'. 2017-05-16 13:04:16:743 776 f90 WS WARNING: MapToSusHResult mapped Nws error 0x803d0000 to 0x80240439 2017-05-16 13:04:16:743 776 f90 WS WARNING: Web service call failed with hr = 80240439. 2017-05-16 13:04:16:743 776 f90 WS WARNING: Current service auth scheme='None'. 2017-05-16 13:04:16:743 776 f90 WS WARNING: Proxy List used: 'xxx:800', Bypass List used: '', Last Proxy used: 'xxx:800', Last auth Schemes used: 'Negotiate (NTLM or Kerberos);'. 2017-05-16 13:04:16:743 776 f90 WS FATAL: OnCallFailure failed with hr=0X80240439 2017-05-16 13:04:16:743 776 f90 WS FATAL: NwsCallWithRetries( Functor(_clientId, _targetGroupName, _dnsName, &_result)) failed with hr=0x80240439 2017-05-16 13:04:16:743 776 f90 IdleTmr WU operation (CAuthorizationCookieWrapper::InitializeSimpleTargetingCookie, operation # 374) stopped; does use network; is at background priority 2017-05-16 13:04:16:743 776 f90 PT WARNING: Failed to initialize Simple Targeting Cookie: 0x80240439 2017-05-16 13:04:16:743 776 f90 PT WARNING: PopulateAuthCookies failed: 0x80240439 2017-05-16 13:04:16:743 776 f90 PT WARNING: RefreshCookie failed: 0x80240439 2017-05-16 13:04:16:743 776 f90 PT WARNING: RefreshPTState failed: 0x80240439 2017-05-16 13:04:16:743 776 f90 PT WARNING: PTError: 0x80240439 2017-05-16 13:04:16:743 776 f90 Report WARNING: Reporter failed to upload events with hr = 80240439. 2017-05-16 13:04:16:743 776 f90 Report WARNING: CSerializationHelper:: InitSerialize failed : 0x80070002 2017-05-16 13:05:44:071 776 e5c AU Currently AUX is enabled - so not show any WU Upgrade notifications. 2017-05-16 13:05:44:102 776 e5c AU WARNING: Failed to get Network Cost info from NLM, assuming network is NOT metered, error = 0x80240037 2017-05-16 13:05:44:164 776 e5c AU WARNING: Failed to get Network Cost info from NLM, assuming network is NOT metered, error = 0x80240037 Anyone any ideas? Edited May 16, 2017 by kennysarmy
Geoff Posted May 16, 2017 Posted May 16, 2017 EULA didn't download WARNING: Fail to download eula file http://xxx:8530/Content/13/33D8A4B81...DAB713E713.txt with error 0x80246003 No EULA clicky no update.
kennysarmy Posted May 16, 2017 Author Posted May 16, 2017 EULA didn't download WARNING: Fail to download eula file http://xxx:8530/Content/13/33D8A4B81...DAB713E713.txt with error 0x80246003 No EULA clicky no update. I wonder if something on our Smoothwall could be blocking access....not sure. All the Windows 7 clients are working fine. If I go to a server which is not on WSUS and check for updates I get an error : 80244022 If I then add 10.* to the IE proxy exceptions it then reports all but 3 important updates are available. Do I need to use the tool Proxycfg.exe to configure a proxy server?
kennysarmy Posted May 16, 2017 Author Posted May 16, 2017 I've two domain controllers but with exactly the same settings in IE proxy and both the same results from netsh winhttp show proxy : Direct access (no proxy server). One DC is showing in WSUS and one is n't....
Cache Posted May 16, 2017 Posted May 16, 2017 (edited) Proxy server set using netsh winhttp? Or a proxy server set for the user running Windows Update which doesn't have a bypass exception? 2017-05-16 13:04:15:696 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'. 2017-05-16 13:04:15:696 776 f90 WS WARNING: The server returned HTTP status code '407 (0x197)' with text 'Proxy Authentication Required'. 2017-05-16 13:04:15:696 776 f90 WS WARNING: The proxy requires HTTP authentication scheme 'NTLM'. 2017-05-16 13:04:16:743 776 f90 WS WARNING: Nws Failure: errorCode=0x803d0000 Edit: Just seen your reply above. I'd maybe try old faithful of renaming the softwaredistribution folder, does seem like a proxy server issue, as it's trying to access it over port 800? Failing that, the Windows Update troubleshooter. Just going off this extra line, it hasn't got any bypass options set other than local. Or run Windows Update as administrator after restarting the service with the IE proxy disabled. 2017-05-16 13:04:16:743 776 f90 WS WARNING: Proxy List used: 'xxx:800', Bypass List used: '', Last Proxy used: 'xxx:800', Last auth Schemes used: 'Negotiate (NTLM or Kerberos);'. Edited May 16, 2017 by Cache
kennysarmy Posted May 17, 2017 Author Posted May 17, 2017 Duplicate SUS IDs? Sadly the SusClientId keys are different between the two DC's...so it's not that.
kennysarmy Posted May 17, 2017 Author Posted May 17, 2017 Proxy server set using netsh winhttp? Or a proxy server set for the user running Windows Update which doesn't have a bypass exception? 2017-05-16 13:04:15:696 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'. 2017-05-16 13:04:15:696 776 f90 WS WARNING: The server returned HTTP status code '407 (0x197)' with text 'Proxy Authentication Required'. 2017-05-16 13:04:15:696 776 f90 WS WARNING: The proxy requires HTTP authentication scheme 'NTLM'. 2017-05-16 13:04:16:743 776 f90 WS WARNING: Nws Failure: errorCode=0x803d0000 Edit: Just seen your reply above. I'd maybe try old faithful of renaming the softwaredistribution folder, does seem like a proxy server issue, as it's trying to access it over port 800? Failing that, the Windows Update troubleshooter. Just going off this extra line, it hasn't got any bypass options set other than local. Or run Windows Update as administrator after restarting the service with the IE proxy disabled. 2017-05-16 13:04:16:743 776 f90 WS WARNING: Proxy List used: 'xxx:800', Bypass List used: '', Last Proxy used: 'xxx:800', Last auth Schemes used: 'Negotiate (NTLM or Kerberos);'. The command netsh winhttp show proxy shows the same results for the two DC's - Direct access (no proxy server). Both have the same IE proxy settings in IE - though I'm not sure this is relevant... We have a Smoothwall filtering device on site so the :800 port is referring to that....
kennysarmy Posted May 17, 2017 Author Posted May 17, 2017 Proxy server set using netsh winhttp? Or a proxy server set for the user running Windows Update which doesn't have a bypass exception? 2017-05-16 13:04:15:696 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'. 2017-05-16 13:04:15:696 776 f90 WS WARNING: The server returned HTTP status code '407 (0x197)' with text 'Proxy Authentication Required'. 2017-05-16 13:04:15:696 776 f90 WS WARNING: The proxy requires HTTP authentication scheme 'NTLM'. 2017-05-16 13:04:16:743 776 f90 WS WARNING: Nws Failure: errorCode=0x803d0000 Edit: Just seen your reply above. I'd maybe try old faithful of renaming the softwaredistribution folder, does seem like a proxy server issue, as it's trying to access it over port 800? Failing that, the Windows Update troubleshooter. Just going off this extra line, it hasn't got any bypass options set other than local. Or run Windows Update as administrator after restarting the service with the IE proxy disabled. 2017-05-16 13:04:16:743 776 f90 WS WARNING: Proxy List used: 'xxx:800', Bypass List used: '', Last Proxy used: 'xxx:800', Last auth Schemes used: 'Negotiate (NTLM or Kerberos);'. Following the Windows Update Troublshooted I get to step 6! Make sure the WSUS server is reachable from the client! So I attempt to browse to : http://ServerIP:8350/iuident.cab and I get This page can’t be displayed - BUT - I am getting this on every single client on the domain - even all the Windows 7 PC's who are working fine in WSUS...so should I be too worried about this?
3s-gtech Posted May 17, 2017 Posted May 17, 2017 Hmmm. Windows Firewall enabled or blocking that port on that server (maybe a GPO differs between them?)
kennysarmy Posted May 17, 2017 Author Posted May 17, 2017 Hmmm. Windows Firewall enabled or blocking that port on that server (maybe a GPO differs between them?) Windows firewall disabled on both and they are both in the same OU and I've checked the WSUS policy is applying! I'm starting to believe this is not a client issue....and something is up with the WSUS Server preventing it from logging the requests & information from certain Servers...
Cache Posted May 17, 2017 Posted May 17, 2017 So I attempt to browse to : http://ServerIP:8350/iuident.cab and I get This page can’t be displayed - BUT - I am getting this on every single client on the domain - even all the Windows 7 PC's who are working fine in WSUS...so should I be too worried about this? Tried on ours and it tries to download the cab file, you might have mixed the port number up though - it should be 8530. Might also be worth trying wuauclt /resetauthorization /detectnow
kennysarmy Posted May 18, 2017 Author Posted May 18, 2017 Tried on ours and it tries to download the cab file, you might have mixed the port number up though - it should be 8530. Might also be worth trying wuauclt /resetauthorization /detectnow
kennysarmy Posted May 18, 2017 Author Posted May 18, 2017 If I browse to the server in IE - so there is connectivity...
kennysarmy Posted May 18, 2017 Author Posted May 18, 2017 I know absolutely nothing about IIS but I've had a look around on the WSUS Server and if I point a browser to : http://WSUSIP:8530/selfupdate/iuident.cab I can see the file to download....
kennysarmy Posted May 18, 2017 Author Posted May 18, 2017 I wonder if it's worth spinning up another VM and setting up a new WSUS Server initially just for my Servers, changing the group policies to point the Servers at this new WSUS and see if I get the same issues...
kennysarmy Posted May 18, 2017 Author Posted May 18, 2017 # Solarwinds® Diagnostic Tool for the WSUS Agent # 18/05/2017 Machine state User rights: User has administrator rights Update service status: Running Background Intelligent Transfer service status: Running OS Version: Windows 7 Professional Service Pack 1 Windows update agent version: 7.6.7601.23735 (WU Agent is OK) Windows Update Agent configuration settings Automatic Update: Enabled Options: Scheduled (Every day at 3:00 AM) Use WSUS Server: Enabled Windows Update Server: http://10.107.93.9:8530 Windows Update Status Server: http://10.107.93.9:8530 WSUS URLs are identical: Identical WSUS URL is valid: Valid URL WSUS Server Connectivity clientwebservice/client.asmx: OK simpleauthwebservice/simpleauth.asmx: OK content: Error: Forbidden (Incorrect proxy client configuration - use settings tab to test proxy configuration settings; may also be caused by misconfigured SSL implementation or access rights on WSUS server) selfupdate/iuident.cab: OK iuident.cab: Error: NotFound (Omitting required port suffix on URL to access WSUS installed to port 8530 or resource is unreachable) This was from a PC which is showing in WSUS OK And below from a Server NOT showing in WSUS # Solarwinds® Diagnostic Tool for the WSUS Agent # 18/05/2017 Machine state User rights: User has administrator rights Update service status: Running Background Intelligent Transfer service status: Running OS Version: Windows Server 2012 R2 Standard Windows update agent version: 7.9.9600.18628 (WU Agent is OK) Windows Update Agent configuration settings Automatic Update: Enabled Options: Automatically download and notify of installation Use WSUS Server: Enabled Windows Update Server: http://10.107.93.9:8530 Windows Update Status Server: http://10.107.93.9:8530 WSUS URLs are identical: Identical WSUS URL is valid: Valid URL WSUS Server Connectivity clientwebservice/client.asmx: OK simpleauthwebservice/simpleauth.asmx: OK content: Error: Forbidden (Incorrect proxy client configuration - use settings tab to test proxy configuration settings; may also be caused by misconfigured SSL implementation or access rights on WSUS server) selfupdate/iuident.cab: OK iuident.cab: Error: NotFound (Omitting required port suffix on URL to access WSUS installed to port 8530 or resource is unreachable)
kennysarmy Posted May 19, 2017 Author Posted May 19, 2017 I wonder if it's worth spinning up another VM and setting up a new WSUS Server initially just for my Servers, changing the group policies to point the Servers at this new WSUS and see if I get the same issues... So I took a physical server (our ex vRanger Server) that was turned off a few weeks ago after an upgrade to VEEAM and I installed WSUS! I left yesterday thinking even that was n't working as I put "itself" in a new WSUSTEST OU (set a new group policy to point it at the new WSUS) and even that was n't appearing on the WSUS console - WELL - I've come in this morning and it's appeared in the new group and has reported in and all looks fine. I'm going to APPROVE a few more updates and check they get seen and install OK. Maybe next week I will move over one of the "live" servers and point it at this new WSUS and see if it also appears!
kennysarmy Posted December 10, 2020 Author Posted December 10, 2020 I'll turn SSL on anyway - nothing to lose
DGardiner Posted December 10, 2020 Posted December 10, 2020 2017-05-16 13:04:15:680 776 f90 PT Server URL = http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx 2017-05-16 13:04:15:696 776 f90 WS WARNING: Nws Failure: errorCode=0x803d001a 2017-05-16 13:04:15:696 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'. 2017-05-16 13:04:15:696 776 f90 WS WARNING: The server returned HTTP status code '407 (0x197)' with text 'Proxy Authentication Required'. 2017-05-16 13:04:15:696 776 f90 WS WARNING: The proxy requires HTTP authentication scheme 'NTLM'. 2017-05-16 13:04:16:743 776 f90 WS WARNING: Nws Failure: errorCode=0x803d0000 2017-05-16 13:04:16:743 776 f90 WS WARNING: There was an error communicating with the endpoint at 'http://xxx:8530/SimpleAuthWebService/SimpleAuth.asmx'. 2017-05-16 13:04:16:743 776 f90 WS WARNING: The content type 'text/html' did not match the expected value 'text/xml'. is the WSUS server ip in the Guardian > Exceptions > destination exceptions on the smoothwall. the 407 sounds like the smoothwall is trying to get authentication from it? assuming this isnt wsus trying to authenticate. if you replace the ip with fqdn does it work? check your smoothwalls live log and see if you can spot the browsing to the base IIS directory in the logs, AFAIK the smoothwall wont serve pages from ports unless explicitly told to (80/443 by default) - ideally you would make the smoothwall not serve the internal content though 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now