BJG Posted November 19, 2021 Posted November 19, 2021 Yesterday a bunch of remote users started raising tickets that the network was running very slowly, and a Broadband speed check in the office showed 70Mbp down but only 1.5Mbp up. We decided this was because we'd approved a round of WSUS updates that were being deployed to all the users now working remotely on laptops. Has anyone else seen this problem with the move to remote working...? We're wondering what the best solution is; eg breaking up the remote laptops into smaller groups or directing them to online servers instead of our central one. It's quite an old version of WSUS, still running on Server 2012, and I expect things may be better using SCCM on a modern OS, but I don't know when that's likely to happen. Any ideas welcome.
Net_Man Posted November 19, 2021 Posted November 19, 2021 Hi BJG, Have you disabled dual scan on the remote devices. Is there a VPN between the main site and the computers working remotely. 1
BJG Posted November 19, 2021 Author Posted November 19, 2021 (edited) ...thanks, not heard of dual scan, just reading up on it. Yep, there's a VPN...what impact does that have...? (Does the idea of directing laptops to Microsoft servers online make sense...? Is it still possible to control what updates clients receive in this way via a WSUS server...?) Edited November 19, 2021 by BJG
jthompson Posted November 19, 2021 Posted November 19, 2021 Does the idea of directing laptops to Microsoft servers online make sense...? Is it still possible to control what updates clients receive in this way via a WSUS server...? I'm pretty sure it is. Clients report in and check for any updates against your WSUS, but the downloading of them is then done direct from MS. You should be able to set that using the usual Group Policy options, so a GPO for your remote laptops to do that, with all your on-prem devices still set to do everything via WSUS. 1
computer_expert Posted November 19, 2021 Posted November 19, 2021 I'm pretty sure it is. Clients report in and check for any updates against your WSUS, but the downloading of them is then done direct from MS. You should be able to set that using the usual Group Policy options, so a GPO for your remote laptops to do that, with all your on-prem devices still set to do everything via WSUS. If @BJG is using a full tunnel VPN (rather than split tunneling) then all traffic will traverse the VPN. Instead of 10 clients hitting the WSUS box and pulling updates from there, you've now got 10 clients hitting the WSUS box for policy, plus the same 10 clients also downloading the updates from MS over the VPN. 2
Warwick_Tech Posted November 30, 2021 Posted November 30, 2021 We had massive issues with our WSUS - Even later versions; until we used this WSUS script; https://www.ajtek.ca/ You have to pay in $ and via CC, but I can confirm it's legit and works wonders when setup. (Your mileage may vary) 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now