?
Solved

What port(s) does Windows Update use?

Posted on 2006-05-31
9
Medium Priority
?
25,697 Views
Last Modified: 2012-06-27
I have recently set up a firewall for egress filtering that blocks all traffic originating in my DMZ unless it is HTTP, HTTPS, or DNS.  I have a web server in there running Windows 2000 Server that I would like to check for patches, but Windwos Update no longer works.  I can get to the web site, but when I click check for updates, I get a failure message.  I suspect, but have not tried it, that I could resolve the issue by unblocking all traffic temporarily.  I would prefer to poke a hole in the firewall for this instead.  Can you tell me the port number(s) and destination servers that I need to create exceptions for in order to make this work?

Thanks in advance!
0
Comment
Question by:NPSRWR
  • 5
  • 4
9 Comments
 
LVL 13

Expert Comment

by:prashsax
ID: 16801440
Have you allowed TCP/80 for any destination.

Are you able to browse other internet sites easily. e.g google.com, yahoo.com etc.

Just try and enable access to FTP port 20-21 as well.

0
 

Author Comment

by:NPSRWR
ID: 16801497
Hi prashsax,

TCP 80 is open for any destination.  I am able to browse other web sites.

Added FTP ports as suggested.  Still getting the failure message...
0
 

Author Comment

by:NPSRWR
ID: 16801515
Wait, let me try that again.  FTP was closed on port 20... back in 5 minutes.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:NPSRWR
ID: 16801555
Nope, that didn't work.  More info on Error message:

Error Number 0xC8000408

"The website has encountered a problem and cannot display the page you are trying to view."

Microsoft then offers a faq link that did not contain the word "port" when I searched for it.
0
 
LVL 13

Accepted Solution

by:
prashsax earned 2000 total points
ID: 16801585
The error you posted is linked to permissions.

Please check if SYSTEM has full control over Drive C on the server.
0
 
LVL 13

Expert Comment

by:prashsax
ID: 16801661
Windows uses port 80 or 443 or both to download updates.

Now, we need to make sure it windows update is not happening because of firewall or for some other reason.

Could you make a rule which allow all ports to any destination. ( just to test if update works).

0
 

Author Comment

by:NPSRWR
ID: 16801700
Thanks prashsax!  That was it exactly.
0
 

Author Comment

by:NPSRWR
ID: 16801795
BTW, I closed the FTP ports and it was still able to do the Windows updates.

Thanks again!
0
 
LVL 13

Expert Comment

by:prashsax
ID: 16801813
Thanks!.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article we will discuss all things related to StageFright bug, the most vulnerable bug of android devices.
#Citrix #POC #XenDesktop #vCenter #VMware #ESX
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.
Suggested Courses

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question