newpersn Posted July 20, 2017 Posted July 20, 2017 (edited) Trying to set up WSUS on Server 2016 and its not finding any updates after 2015.... (wtf??) So my question to you. WSUS or Not? (If other please post below what you using) Edited July 20, 2017 by newpersn
Davit2005 Posted July 21, 2017 Posted July 21, 2017 (edited) WSUS, I know it can be buggy to setup. With so many options when it comes to installing updates on Domain machines with GPO why bother with anything else. Even though I have no WSUS at home I have the GPO setup so at least I can choose when the PC updates. Edited July 21, 2017 by Davit2005 1
jthompson Posted July 21, 2017 Posted July 21, 2017 WSUS lets us enforce deadlines for updates to ensure that they get applied and not perpetually postponed by end users. It also let's us turn that off when machines are being used for exams. I'm not sure that's possible without WSUS. 1
3s-gtech Posted July 21, 2017 Posted July 21, 2017 Without WSUS, our internet connection would frequently max out (which happens to all of the schools on our WAN who don't use WSUS, which then affects us anyway). 1
newpersn Posted July 21, 2017 Author Posted July 21, 2017 Rebuilt it again.. Under a new name. seem to picking up the updates and downloading them... 64gb to download so far to catch up again.
Jehanzeb Posted August 1, 2017 Posted August 1, 2017 How would you setup WSUS in virtual environment please? We have very limited amount of Windows 7 and 10 machines but when it comes to updates it drags the entire network down. We are already using Mac Caching server for iOS and Mac updates and I'd like to do the same for Windows. Will be using Windows server 2016 in virtual environment. Any guidance will be highly appreciated. Kindest regards J.
newpersn Posted August 1, 2017 Author Posted August 1, 2017 Easy enough. Install 2016 >domain join Add wsus role. Set path during install. Once roll installed configure what products you need updates for (windows 7, 10 server 2012 etc....) Let the server sync (will take up to an hour to sync depending on how much you selected) Change your Group Poilcy windows update location to point at your new server. (Posted via app) 1
newpersn Posted August 1, 2017 Author Posted August 1, 2017 Forgot to add: once updates have sync you can approve updates to send to the computers to update. Once updates have been approved it will download the update to the sever.
free780 Posted August 2, 2017 Posted August 2, 2017 Digging deeper you can create a test and production target group. This can be pushed out via group policy. Test new updates to the Test target group first then to the production target group. Make sure your servers only reboot at night.
jthompson Posted August 2, 2017 Posted August 2, 2017 I've just this week been building a new WSUS installation after the existing one completely broke on me. On the first attempt at building a new WSUS server I made the mistake of approvaling all critical and security updates after the initial sync. It was then wanting to download 279GB of updates, which would have taken more than a month at the rate it was going. I scrapped that and started again, this time only approving updates with a status of 'Needed' by clients. Only about 30GB of updates now needed to be downloaded, which it managed in about a day. I'm going to wait for 30 days or more and then run the cleanup wizard to decline all those unneeded updates, before going anywhere near automatic approval rules (which is the ultimate aim).
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now