Jump to content

WSUS overload - staggered updates...?


Recommended Posts

Posted

Yesterday a bunch of remote users started raising tickets that the network was running very slowly, and a Broadband speed check in the office showed 70Mbp down but only 1.5Mbp up. We decided this was because we'd approved a round of WSUS updates that were being deployed to all the users now working remotely on laptops.

 

Has anyone else seen this problem with the move to remote working...? We're wondering what the best solution is; eg breaking up the remote laptops into smaller groups or directing them to online servers instead of our central one. It's quite an old version of WSUS, still running on Server 2012, and I expect things may be better using SCCM on a modern OS, but I don't know when that's likely to happen. Any ideas welcome.

Posted (edited)

...thanks, not heard of dual scan, just reading up on it. Yep, there's a VPN...what impact does that have...?

 

(Does the idea of directing laptops to Microsoft servers online make sense...? Is it still possible to control what updates clients receive in this way via a WSUS server...?)

Edited by BJG
Posted
Does the idea of directing laptops to Microsoft servers online make sense...? Is it still possible to control what updates clients receive in this way via a WSUS server...?

I'm pretty sure it is. Clients report in and check for any updates against your WSUS, but the downloading of them is then done direct from MS. You should be able to set that using the usual Group Policy options, so a GPO for your remote laptops to do that, with all your on-prem devices still set to do everything via WSUS.

  • Thanks 1
Posted
I'm pretty sure it is. Clients report in and check for any updates against your WSUS, but the downloading of them is then done direct from MS. You should be able to set that using the usual Group Policy options, so a GPO for your remote laptops to do that, with all your on-prem devices still set to do everything via WSUS.

 

If @BJG is using a full tunnel VPN (rather than split tunneling) then all traffic will traverse the VPN. Instead of 10 clients hitting the WSUS box and pulling updates from there, you've now got 10 clients hitting the WSUS box for policy, plus the same 10 clients also downloading the updates from MS over the VPN.

  • Thanks 2
  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...