Jump to content

Recommended Posts

Posted

Hi All,

 

I've got several DMZ Windows server that I'd like to know how to update them, it is serving as terminal server and the webserver with only port 443 and 80 & 8080 opened to the internet with port 1521 for database connection.

 

I do have WSUS in place and already working fine in the internal domain, how do people usually do their patching for the DMZ servers ?

 

Any idea would be greatly appreciated.

 

Thanks,

Posted
You could poke a single port 443 hole in the firewall for the specific IPs of the DMZ servers to access the internal WSUS server, you would need to configure the DMZ servers in local policy to implement this though unless they are domain joined.
Posted
If they are domain joined you could create a one way trust from the DMZ to the internal domain. This is what we do to allow out KMS server to license our DMZ machines

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...