Mrluckhurst Posted October 22, 2020 Posted October 22, 2020 Hi - we have recently moved to serve r2019 and Windows 10. We used to have a helpful piece of software that scheduled the downloading and then installing of windows updates to times that wouldn't cause our internet connection to grind to halt when we are trying to use it. (e.g. to only run outside of 'business' hours) Unfortunately the advice from our support people this time is: There are a few policy's you can implement to delay them being installed but not for the downloads unfortunately. Best thing to do is make sure workstations are left on the evening of Patch Tuesday and hopefully come Wednesday it'll be downloaded . There must be a better way. How can we sort this? Thanks for your help
Guest Guest Posted October 22, 2020 Posted October 22, 2020 You can use wsus to accomplish this, it downloads updates to the server and manages the installation on devices. https://www.prajwaldesai.com/install-configure-wsus-on-windows-server-2019/
mavhc Posted October 22, 2020 Posted October 22, 2020 WSUS is dead, use P2P sharing of downloads and update compliance. http://www.edugeek.net/forums/windows-10/207846-update-compliance.html 1
3s-gtech Posted October 22, 2020 Posted October 22, 2020 It’s certainly no use for Office 2019 or 365, but it’s not dead. As we’ve ascertained before.
mavhc Posted October 24, 2020 Posted October 24, 2020 Last got any updates 3 years ago, and that was just to fix something new in WU. https://www.wroot.lt/wp/tag/wsus/ can't even see 1909 this says. Pretty much all Windows programmers are working on Windows X, and all Server programmers have moved to Azure.
3s-gtech Posted October 24, 2020 Posted October 24, 2020 Its days are numbered sadly. I’ve got three or four 1909 clients in total, the rest are 1903 so not noticed this yet. I don’t fancy the new system. The MS CDN already swamped our link pulling telemetry from clients, so had to manage it with our firewall.
smurfomatic Posted October 24, 2020 Posted October 24, 2020 WSUS still issues updates for 1909, 2004 and 20H2, they just don't have separate subcategories in Products & Classifications. It shows as "Windows 10 Vibranium and later" 2
Steve21 Posted October 24, 2020 Posted October 24, 2020 It shows as "Windows 10 Vibranium and later" Don't think you even need to change it do you? On ours the Vib options are upgrades/drivers only, thought the rest comes under the 1903+ one still For example 2004 CU is available under 1903+ even without the others ticked Steve 1
smurfomatic Posted October 24, 2020 Posted October 24, 2020 Don't think you even need to change it do you? On ours the Vib options are upgrades/drivers only, thought the rest comes under the 1903+ one still For example 2004 CU is available under 1903+ even without the others ticked Steve That's true, it's only upgrade & servicing drivers for Vibranium, we have 1903 & later ticked which is providing the updates for 1909 onwards 1
3s-gtech Posted October 24, 2020 Posted October 24, 2020 That’s excellent info both, thanks. Makes managing updates much easier when we move to a newer version of 10 next year.
mavhc Posted October 24, 2020 Posted October 24, 2020 Its days are numbered sadly. I’ve got three or four 1909 clients in total, the rest are 1903 so not noticed this yet. I don’t fancy the new system. The MS CDN already swamped our link pulling telemetry from clients, so had to manage it with our firewall. Weird, are you on isdn?
3s-gtech Posted October 24, 2020 Posted October 24, 2020 450 x 5Mb connections to the CDN meant that no, it didn’t need to be ISDN to get choked up - it’s 100Mb. This happened after moving to 1903, and I struggled to stop it with GP settings (though there are plenty related to this). My Pfsense is set to choke certain Akamai IP ranges to 5Mb total - works a treat. Have to be careful to avoid ones that O365 and Teams use! I suspect I could scrub all of those rules now, as it will be a GP setting that I’ve since found inadvertently. If I moved away from WSUS I would definitely have to do this.
ajg Posted October 24, 2020 Posted October 24, 2020 450 x 5Mb connections to the CDN meant that no, it didn’t need to be ISDN to get choked up - it’s 100Mb. This happened after moving to 1903, and I struggled to stop it with GP settings (though there are plenty related to this). My Pfsense is set to choke certain Akamai IP ranges to 5Mb total - works a treat. Have to be careful to avoid ones that O365 and Teams use! I suspect I could scrub all of those rules now, as it will be a GP setting that I’ve since found inadvertently. If I moved away from WSUS I would definitely have to do this. Out of curiosity what did you have to do to prevent this issue? We’ve been struggling with bandwidth hogging issues which appears to be coming from windows itself.
3s-gtech Posted October 24, 2020 Posted October 24, 2020 Pfsense combined with ntopng, placed as an Edge firewall with all traffic passing through it. That allowed me to see which IP ranges were hammering us. I then Googled the range to see what it was, then put in a rule to choke it. I had to do this many, many times until it fixed the issue - there are masses of Akamai ranges! You would best describe this as a bodge. However, it did allow me to pinpoint the issue and it hasn’t been a problem for around 12 months now. I’m left with a free, powerful firewall.
mavhc Posted October 24, 2020 Posted October 24, 2020 You had a continuous 5Mb upload from every computer?
3s-gtech Posted October 24, 2020 Posted October 24, 2020 You had a continuous 5Mb upload from every computer? Yup. We lost WAN connectivity until I sorted it, such was the saturation. Last August was awful, never been so stressed. This was over weeks, not days. I had shut down the analytics, update sharing off-LAN and anything else I could find, but in the end the firewall gave me some breathing space - within a day of installing it we had working systems and I could drill down on the issues. I guess 1703 to 1903 increased the peer to peer and analytics stuff. Do a forum search - wasn’t just me that got hit by this.
mavhc Posted October 25, 2020 Posted October 25, 2020 I remember you had issues with Store app updates downloading, and then someone said WSUS did store apps, but can't remember whether they ever explained how Fun fact, every store app has its own registry hive. Much like Click to run apps 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now