PyROm Posted February 11, 2020 Posted February 11, 2020 I was wondering if people allow school owned laptops, which connect over VPN, to grab updates off their WSUS server. I`m in two minds, blocking them from getting updates over VPN saves a lot of bandwidth (were stuck on 100mb internet connection at the moment) and they should be bringing their laptop in every day, at which point it will get updates. However over the 6 weeks holiday they wont get any updates for 6 weeks, so might be better allowing them access and suffering the slower connection.
FN-GM Posted February 11, 2020 Posted February 11, 2020 Would it use up all the bandwidth? During the evening you won't have much on the inside of the network using it. Plus it will be limited by the connection speeds at home. 1
CHiLL Posted February 11, 2020 Posted February 11, 2020 I allow Windows Updates over our VPN (though we have a 200Mb connection). Chances are that when your staff are connected via the VPN, it's outside of the normal hours so won't impact performance during the day. Also Windows Updates generally aren't that large (unless the device hasn't updated for a while), so clients won't have that much to download. 1
PyROm Posted February 12, 2020 Author Posted February 12, 2020 Thanks for the replies, I will switch to allowing WSUS through the VPN. I dont really want to allow them to connect to MU for downloads, as when in school I could have 60 laptops simultaneously trying to download updates over the internet. At least very few will use them at home so less people trying to grab updates.
mavhc Posted February 12, 2020 Posted February 12, 2020 Ah, you turn on P2P updates, then they share them with each other, according to Update Compliance I've saved 50% bandwidth that way. Also means you get driver and WDAV updates, and don't have to run WSUS, saving 500GBs and your sanity
PyROm Posted March 5, 2020 Author Posted March 5, 2020 I am looking at this again using Microsoft update servers (so wufb) is there any way to permanently block feature updates? ie. I roll out an image with 1909 on, which should be good for 3 years, I dont want it to auto update itself to 2004 (or whatever the new number is) when that comes out. I have seen the defer for 365 days, but this is not much use if it is 3 years.
CyBeRkId2002 Posted March 5, 2020 Posted March 5, 2020 Interested to know the answer to the above question... We use SCCM but it is so fiddly to maintain and the additional storage demands are leaning on the ridiculous side of things so am thinking of switching back to Microsoft Update servers. Local made sense when bandwidth was an issue but that is less of a problem these days.
PyROm Posted March 6, 2020 Author Posted March 6, 2020 You can turn local storage off on wsus, so that it lets you control updates but the machines grab them from Microsoft update directly, its on the wsus mmc, update files and languages page.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now