Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

SUS server

Posted on 2006-04-13
10
Medium Priority
?
303 Views
Last Modified: 2010-04-18
I have a server that we have setup as a SUS server. How do we change where the server goes to look up windows updates is this a registry change? Thank you
0
Comment
Question by:zenworksb
10 Comments
 
LVL 23

Accepted Solution

by:
TheCleaner earned 2000 total points
ID: 16446187
If you are referring to WSUS, that is done through Group policy:

http://technet2.microsoft.com/windowsserver/en/library//4ac8d574-f48e-4d9d-86c9-9aeb0f57e7501033.mspx

That guide ^^ will walk you through the settings and configuration.

Let us know if you have questions about this, but that's pretty much it.  You just point the clients via group policy to your internal WSUS server.
0
 
LVL 51

Expert Comment

by:Netman66
ID: 16446190
Can you clarify what you are looking for?

Do you mean where WSUS goes for the updates to provide the client or where the actual server will update itself from?

If it's the latter, then the server acts exactly as the client does.  It can be set onthe Default Domain Controller Policy in the same location as the client policies.

0
 

Author Comment

by:zenworksb
ID: 16446696
we do not haver active directory. what can we do on teh clients to point to our server internally
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 8

Expert Comment

by:bilbus
ID: 16446721
You need to go into the registry and change the location for automatic updates on the client computers.

I beleve you can also do this via the local computer policy on each computer
0
 
LVL 22

Expert Comment

by:mcsween
ID: 16446972
You can set the same policies you would in a GPO.  The only difference is you will have to go to each computer to set these up.

Start Run, gpedit.msc

If you clients are NOT XP SP1 or better you will have to import the template.  If client is SP1 or better than skip to the next step.
   1. Download from http://www.microsoft.com/downloads/details.aspx?FamilyID=92759d4b-7112-4b6c-ad4a-bbf3802a5c9b&displaylang=en
   2. RC Admin Templates under Computer Config and add wuau.adm to the list...if it's already there just skip

Setting it up.
   1. On each workstation configure the settings under Computer Config | Admin Templates | Windows Componets | Windows Update

the service location is the specific one you are asking about.  Just enter the FQN of the WSUS server (e.g. MyServer.domain.local)

I'm not 100% sure but you may have to setup DNS on your network so you can give this server a FQN since you have no domain.  Install DNS on your WSUS server and create a Forward Lookup zone called CompanyName.local.  Add an "A" or host record to the zone with the WSUS server netbios name and IP.  Setup forwarders on this server to your external DNS to resolve real world names.  Also make sure there is no "." zone...if there is just delete it.

Go to System Properties on your WSUS server and click the Computer Name tab, Click Change, Click More, Change the primary suffix to "CompanyName.local"

Set all your clients to look at this server as their primary DNS server.  You can enter an external DNS as a secondary.


My final suggestion would be to skip everything I listed above and just go to your WSUS server and run dcpromo.  Create a domain, add the workstations to it, setup a group policy and be done with it.  This may not be feasable but if it is, it's definatly the best way to go.
0
 
LVL 51

Expert Comment

by:Netman66
ID: 16447058
Just copy this into a file with a .reg extension and double click it (on the client).

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate]
"WUServer"="http://{FQDN of SUS server}"
"WUStatusServer"="http://{FQDN of SUS server}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"NoAutoUpdate"=dword:00000000
"UseWUServer"=dword:00000001
"RescheduleWaitTime"=dword:00000001
"NoAutoRebootWithLoggedOnUsers"=dword:00000000
"AUOptions"=dword:00000004
"ScheduledInstallDay"=dword:00000000
"ScheduledInstallTime"=dword:00000005

Just change this value : {FQDN of SUS server} to your own server FQDN less the brackets.

0
 
LVL 23

Expert Comment

by:TheCleaner
ID: 16447175
ah...workgroup environment...


See here:  http://www.wsuswiki.com/TroubleshootingAUUpdatesWithWSUS

[quote]
2. For clients in a a workgroup environment, configuration is via the registry or via local policy.


3. Confirm the the client's AU settings and ensure they are set the way you intend. A simple way is to use the REG.exe command to dump out the policy settings from the client's registry. Use the following syntax:

Reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /s

You should see something like this:

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
WSUServer REG_SZ http://dc1.nwtraders.msft
WSUStatusServer REG_SZ http://dc1.nwtraders.msft

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
NoAutoUpdate REG_DWORD 0x0
AUOptions REG_DWORD 0x3
ScheduledInstallDay REG_DWORD 0x0
ScheduledInstallTime REG_DWORD 0x3
UseWSUServer REG_DWORD 0x1
DetectionFrequencyEnabled REG_DWORD 0x1
DetectionFrequency REG_DWORD 0x1
[/quote]


also see this great online documentation:  http://uphold2001.brinkster.net/vbshf/wsus/wsus_faq.htm


There WAS a KB article on scripting this...But I don't see it anymore online (it was 555454).

0
 
LVL 23

Expert Comment

by:TheCleaner
ID: 16447187
Sorry Netman, I should have hit F5 again after leaving my desk for a few minutes and coming back to this question...that's right on the money.
0
 
LVL 51

Expert Comment

by:Netman66
ID: 16447415
No problem - at least he's well taken care of ! :o)
0
 
LVL 23

Expert Comment

by:TheCleaner
ID: 16478332
Got it working I assume?
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
Look below the covers at a subform control , and the form that is inside it. Explore properties and see how easy it is to aggregate, get statistics, and synchronize results for your data. A Microsoft Access subform is used to show relevant calcul…
As many of you are aware about Scanpst.exe utility which is owned by Microsoft itself to repair inaccessible or damaged PST files, but the question is do you really think Scanpst.exe is capable to repair all sorts of PST related corruption issues?

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question