Link to home
Start Free TrialLog in
Avatar of sitqadmin
sitqadminFlag for Canada

asked on

WSUS clients appear and disapear

Hi,

We have a problem with our WSUS 3.1 sp1. Its a DC on Windows 2003 Standard R2 Sp2. The pcs appear and disappear from the All Computers (But it looks that the updates are applied). We use the GPO to assign the pc in a target group and it doesnt work. I need help please.

This is all the steps that I have made:

Reinstall the WSUS on the server.

On the client pc I ran newsid.exe

And rebooted the pc

On the pc I ran the following script:

net stop wuauserv
REG DELETE HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v
PingID /f
REG DELETE HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v
AccountDomainSid /f
REG DELETE HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v
SusClientID /f
net start wuauserv
wuauclt.exe /resetauthorization /detectnow

and rebooted the pc

On the client pc I ran Gpresult.exe :

(Sorry the result is in French, the pc is in Paris, but it looks the GPO is applied))

C:\>gpresult

Outil de résultat du système d'exploitation Microsoft (R) Windows (R) XP v2.0
Copyright (C) Microsoft Corp. 1981-2001

Jeu créé le 22/05/2009 à 15:10:15


Résultats RSOP pour SITQSAS\visiteursitq sur EPARIS-CBASSO : mode journalisation
---------------------------------------------------------------------------------

Type de système d'exploitation :                     Microsoft Windows XP Professionnel
 Configuration du système d'exploitation :                  Station de travail membre
Version du système d'exploitation :                  5.1.2600
Nom du domaine :SITQSAS
Type de domaine :Windows 2000
Nom du site :                   PARIS
Profil itinérant :
Profil local :C:\Documents and Settings\visiteursitq
Connexion via une liaison lente ? : Non


Paramètre de l'ordinateur
--------------------------
    CN=EPARIS-CBASSO,OU=ordi,OU=Paris,OU=SITQSAS,DC=sitqsas,DC=com
    Heure de la dernière application de la stratégie de groupe : 22/05/2009 at 13:34:49
    Stratégie de groupe appliquée depuis :      eparis-wdc01.sitqsas.com
    Seuil de liaison lente dans la stratégie de groupe :   500 kbps

    Objets Stratégie de groupe appliqués
    -------------------------------------
        WSUS_Paris
        Default Paris User
        Default SITQSAS User Policy
        Default Domain Policy

    Les objets stratégie de groupe n'ont pas été appliqués car ils ont été refusé
    ------------------------------------------------------------------------------
        Stratégie de groupe locale
            Filtrage :  Non appliqué (vide)

    L'ordinateur fait partie des groupes de sécurité suivants :
    -----------------------------------------------------------
        BUILTIN\Administrators
        Tout le monde
        BUILTIN\Users
        RESEAU
        Utilisateurs authentifiés
        EPARIS-CBASSO$
        Domain Computers


PARAMÈTRES UTILISATEURS
------------------------
    CN=Visiteur SITQ,OU=Paris,OU=SITQSAS,DC=sitqsas,DC=com
    Heure de la dernière application de la stratégie de groupe : 22/05/2009 at 14:32:13
    Stratégie de groupe appliquée depuis :      eparis-wdc01.sitqsas.com
    Seuil de liaison lente dans la stratégie de groupe :   200 kbps

    Objets Stratégie de groupe appliqués
    -------------------------------------
        Default Paris User
        Default SITQSAS User Policy
        Default Domain Policy

    Les objets stratégie de groupe n'ont pas été appliqués car ils ont été refusé
    ------------------------------------------------------------------------------
        Stratégie de groupe locale
            Filtrage :  Non appliqué (vide)

    L'utilisateur fait partie des groupes de sécurité suivants :
    ------------------------------------------------------------
        Domain Users
        Tout le monde
        Remote Desktop Users
        BUILTIN\Administrators
        BUILTIN\Users
        REMOTE INTERACTIVE LOGON
        INTERACTIF
        Utilisateurs authentifiés
        LOCAL
        G_SITQ Paris
        _Par

On client PC ClientDiag.exe:

WSUS Client Diagnostics Tool

Checking Machine State
        Checking for admin rights to run tool . . . . . . . . . PASS
        Automatic Updates Service is running. . . . . . . . . . PASS
        Background Intelligent Transfer Service is running. . . PASS
        Wuaueng.dll version 7.2.6001.788. . . . . . . . . . . . PASS
                This version is WSUS 2.0

Checking AU Settings
        AU Option is 4: Scheduled Install . . . . . . . . . . . PASS
                Option is from Policy settings

Checking Proxy Configuration
        Checking for winhttp local machine Proxy settings . . . PASS
                Winhttp local machine access type
                        <Direct Connection>
                Winhttp local machine Proxy. . . . . . . . . .  NONE
                Winhttp local machine ProxyBypass. . . . . . .  NONE
        Checking User IE Proxy settings . . . . . . . . . . . . PASS
                User IE Proxy. . . . . . . . . . . . . . . . .  NONE
                User IE ProxyByPass. . . . . . . . . . . . . .  NONE
                User IE AutoConfig URL Proxy . . . . . . . . .  NONE
                User IE AutoDetect
                AutoDetect not in use

Checking Connection to WSUS/SUS Server
                WUServer = http://eparis-wdc02:8530
                WUStatusServer = http://eparis-wdc02:8530
        UseWuServer is enabled. . . . . . . . . . . . . . . . . PASS
        Connection to server. . . . . . . . . . . . . . . . . . PASS
        SelfUpdate folder is present. . . . . . . . . . . . . . PASS


On client PC, I was able to extract the file uident.txt from the following URL  http://eparis-wdc02.sitqsas.com:8530/iuident.cab


On WSUS server I ran >wsusdebugtool.exe /tool:getconfiguration  :

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Update Services\Server\Setup
      :
      Version:3
      VersionString:3.1.6001.65
      ConfigurationSource:0
      ServicePackLevel:1
      TargetDir:C:\Program Files\Update Services\
      InstallType:1
      EnableRemoting:1
      WsusAdministratorsSid:S-1-5-21-963296369-1936308829-3530546634-1645
      WSUSReportersSid:S-1-5-21-963296369-1936308829-3530546634-1644
      SqlServerName:EPARIS-WDC02\MICROSOFT##SSEE
      SqlAuthenticationMode:WindowsAuthentication
      SqlDatabaseName:SUSDB
      SqlUserName:
      SqlEncryptedPassword:
      SqlInstanceIsRemote:0
      wYukonInstalled:1
      IISInstallRevision:3.1.6001.65
      IISPreviousInstallRevision:
      IISUninstallConfigFilePath:C:\Program Files\Update Services\setup\UninstallSettings.xml
      IISTargetWebSiteCreated:True
      IISTargetWebSiteIndex:983783965
      ContentDir:D:\WSUS
      SmtpUserPassword:
      ProxyPassword:
      PortNumber:8530
      IIsDynamicCompression:-1
      EncryptionParam:System.Byte[]
      EncryptionKey:System.Byte[]
<NewDataSet>
  <Table>
    <ConfigurationID>1</ConfigurationID>
    <LastConfigChange>2009-05-25T13:47:18.6200000+02:00</LastConfigChange>
    <DssAnonymousTargeting>false</DssAnonymousTargeting>
    <IsRegistrationRequired>true</IsRegistrationRequired>
    <MaxDeltaSyncPeriod>30</MaxDeltaSyncPeriod>
    <ReportingServiceUrl>https://stats.update.microsoft.com</ReportingServiceUrl>
    <ServerID>528988cd-c87d-4c0f-b470-8202e4dc0d22</ServerID>
    <AnonymousCookieExpirationTime>10080</AnonymousCookieExpirationTime>
    <SimpleTargetingCookieExpirationTime>60</SimpleTargetingCookieExpirationTime>
    <MaximumServerCookieExpirationTime>10080</MaximumServerCookieExpirationTime>
    <DssTargetingCookieExpirationTime>240</DssTargetingCookieExpirationTime>
    <EncryptionKey>hAlRlIwohwErOfPMDmTpBRbdkncJO1V0</EncryptionKey>
    <ServerTargeting>true</ServerTargeting>
    <SyncToMU>true</SyncToMU>
    <UpstreamServerName />
    <ServerPortNumber>80</ServerPortNumber>
    <UpstreamServerUseSSL>false</UpstreamServerUseSSL>
    <UseProxy>false</UseProxy>
    <ProxyName />
    <ProxyServerPort>80</ProxyServerPort>
    <AnonymousProxyAccess>true</AnonymousProxyAccess>
    <ProxyUserName />
    <HostOnMu>false</HostOnMu>
    <LocalContentCacheLocation>d:\WSUS\WsusContent\</LocalContentCacheLocation>
    <ServerSupportsAllLanguages>false</ServerSupportsAllLanguages>
    <LogLevel>0</LogLevel>
    <LogPath />
    <SubscriptionFailureNumberOfRetries>3</SubscriptionFailureNumberOfRetries>
    <SubscriptionFailureWaitBetweenRetriesTime>15</SubscriptionFailureWaitBetweenRetriesTime>
    <DispatchManagerPollingInterval>5</DispatchManagerPollingInterval>
    <StateMachineTransitionLoggingEnabled>false</StateMachineTransitionLoggingEnabled>
    <StateMachineTransitionErrorCaptureLength>600</StateMachineTransitionErrorCaptureLength>
    <MaxSimultaneousFileDownloads>10</MaxSimultaneousFileDownloads>
    <MUUrl>https://update.microsoft.com/v6</MUUrl>
    <EventLogFloodProtectTime>10</EventLogFloodProtectTime>
    <HandshakeAnchor>9390202,2009-05-25 13:47:24.599</HandshakeAnchor>
    <StatsDotNetWebServiceUri>http://localhost</StatsDotNetWebServiceUri>
    <QueueFlushTimeInMS>3000</QueueFlushTimeInMS>
    <QueueFlushCount>100</QueueFlushCount>
    <QueueRejectCount>500</QueueRejectCount>
    <SleepTimeAfterErrorInMS>30000</SleepTimeAfterErrorInMS>
    <LogDestinations>0</LogDestinations>
    <AutoRefreshDeployments>true</AutoRefreshDeployments>
    <RedirectorChangeNumber>6</RedirectorChangeNumber>
    <ImportLocalPath />
    <UseCookieValidation>true</UseCookieValidation>
    <AutoPurgeClientEventAgeThreshold>15</AutoPurgeClientEventAgeThreshold>
    <AutoPurgeServerEventAgeThreshold>90</AutoPurgeServerEventAgeThreshold>
    <AutoPurgeDetectionPeriod>12</AutoPurgeDetectionPeriod>
    <DoReportingDataValidation>true</DoReportingDataValidation>
    <DoReportingSummarization>true</DoReportingSummarization>
    <MaxNumberOfIdsToRequestDataFromUss>100</MaxNumberOfIdsToRequestDataFromUss>
    <MaxCoreUpdatesPerRequest>30</MaxCoreUpdatesPerRequest>
    <MaxExtendedUpdatesPerRequest>50</MaxExtendedUpdatesPerRequest>
    <DownloadRegulationUrl />
    <AllowProxyCredentialsOverNonSsl>false</AllowProxyCredentialsOverNonSsl>
    <LazySync>true</LazySync>
    <DownloadExpressPackages>false</DownloadExpressPackages>
    <DoServerSyncCompression>true</DoServerSyncCompression>
    <ProxyUserDomain />
    <BitsHealthScanningInterval>3600000</BitsHealthScanningInterval>
    <BitsDownloadPriorityForeground>false</BitsDownloadPriorityForeground>
    <MaxXmlPerRequest>200000</MaxXmlPerRequest>
    <MaxXmlPerRequestInServerSync>2000000</MaxXmlPerRequestInServerSync>
    <MaxTargetComputers>30000</MaxTargetComputers>
    <MaxEventInstances>2000000</MaxEventInstances>
    <LogRolloverFileSizeInBytes>0</LogRolloverFileSizeInBytes>
    <WUSInstallType>0</WUSInstallType>
    <ReplicaMode>false</ReplicaMode>
    <AutoDeployMandatory>true</AutoDeployMandatory>
    <DeploymentChangeDeferral>30</DeploymentChangeDeferral>
    <RevisionDeletionTimeThreshold>30</RevisionDeletionTimeThreshold>
    <RevisionDeletionSizeThreshold>1024</RevisionDeletionSizeThreshold>
    <CollectClientInventory>false</CollectClientInventory>
    <DoDetailedRollup>true</DoDetailedRollup>
    <RollupResetGuid>9d5e8262-bcc6-4f0d-a9da-b1f4301c00b9</RollupResetGuid>
    <UssSupportsAllLanguages>true</UssSupportsAllLanguages>
    <GetContentFromMU>false</GetContentFromMU>
    <HmDetectIntervalInSeconds>600</HmDetectIntervalInSeconds>
    <HmRefreshIntervalInSeconds>21600</HmRefreshIntervalInSeconds>
    <HmCoreDiskSpaceGreenMegabytes>500</HmCoreDiskSpaceGreenMegabytes>
    <HmCoreDiskSpaceRedMegabytes>200</HmCoreDiskSpaceRedMegabytes>
    <HmCoreCatalogSyncIntervalInDays>1</HmCoreCatalogSyncIntervalInDays>
    <HmClientsInstallUpdatesGreenPercent>10</HmClientsInstallUpdatesGreenPercent>
    <HmClientsInstallUpdatesRedPercent>25</HmClientsInstallUpdatesRedPercent>
    <HmClientsInventoryGreenPercent>2</HmClientsInventoryGreenPercent>
    <HmClientsInventoryRedPercent>5</HmClientsInventoryRedPercent>
    <HmClientsInventoryScanDiffInHours>30</HmClientsInventoryScanDiffInHours>
    <HmClientsSilentGreenPercent>10</HmClientsSilentGreenPercent>
    <HmClientsSilentRedPercent>25</HmClientsSilentRedPercent>
    <HmClientsSilentDays>30</HmClientsSilentDays>
    <DssRollupChunkSize>5000</DssRollupChunkSize>
    <MURollupOptin>False</MURollupOptin>
    <AutoRefreshDeploymentsDeclineExpired>true</AutoRefreshDeploymentsDeclineExpired>
    <ServerString>Default</ServerString>
    <HmCoreFlags>-1</HmCoreFlags>
    <HmClientsFlags>-1</HmClientsFlags>
    <HmDatabaseFlags>-1</HmDatabaseFlags>
    <HmWebServicesFlags>-1</HmWebServicesFlags>
    <ClientReportingLevel>2</ClientReportingLevel>
    <LocalPublishingMaxCabSize>384</LocalPublishingMaxCabSize>
    <DownloadRegulationWebServiceUrl />
    <LoadOdfLocally>false</LoadOdfLocally>
    <OdfFilePath />
    <HmClientsTooManyGreenPercent>80</HmClientsTooManyGreenPercent>
    <HmClientsTooManyRedPercent>90</HmClientsTooManyRedPercent>
    <ComputerDeletionTimeThreshold>30</ComputerDeletionTimeThreshold>
    <ConfigurationChangeNumber>3327</ConfigurationChangeNumber>
    <UseSeparateProxyForSsl>false</UseSeparateProxyForSsl>
    <SslProxyName />
    <SslProxyServerPort>443</SslProxyServerPort>
  </Table>
</NewDataSet>


On WSUS Server gpotool.exe:

D:\WSUSTool>gpotool
Validating DCs...
Available DCs:
eparis-wdc01.sitqsas.com
EPARIS-WDC02.sitqsas.com
Searching for policies...
Found 10 policies
============================================================
Policy {0A8CDDF6-DFC4-405B-9C55-B2F48CE16DE5}
Friendly name: WSUS_Paris
Policy OK
============================================================
Policy {0C956D67-E7C7-4171-80A8-3CAF6AAE62D6}
Friendly name: Default Lucia User
Policy OK
============================================================
Policy {12F019F7-2708-492A-9201-1C6690F6ECC8}
Friendly name: WSUS_Lucia
Policy OK
============================================================
Policy {14DDE825-671D-4D4A-A414-52A579E2B4B4}
Friendly name: Default Paris User
Policy OK
============================================================
Policy {168C646F-5EB6-4F11-835B-17D2FA3AC21F}
Friendly name: WSUS_Frankfurt
Policy OK
============================================================
Policy {18B60DDE-77F0-44DC-9791-B44549180946}
Friendly name: Default SITQSAS User Policy
Policy OK
============================================================
Policy {31B2F340-016D-11D2-945F-00C04FB984F9}
Friendly name: Default Domain Policy
Policy OK
============================================================
Policy {6AC1786C-016F-11D2-945F-00C04FB984F9}
Friendly name: Default Domain Controllers Policy
Policy OK
============================================================
Policy {DB1DF0BC-6488-48FF-A222-D839AE4131F7}
Friendly name: Default Frankfurt User
Policy OK
============================================================
Policy {E09BA4C9-5920-45FB-A47E-ED7BF46D5F7C}
Friendly name: Default SITQSAS Server Policy
Policy OK
============================================================

Policies OK

I am very confusing on what is wrong on the server or one the pc.

Help will be much appreciated.
Avatar of Rob Stone
Rob Stone
Flag of United Kingdom of Great Britain and Northern Ireland image

If they are disappearing how do you konw when they have slipped off the radar?

When they are not showing in WSUS run a RSOP on the client and check the Windows Update policy to see if it is pointing to the server.  Then run a wuauclt /detectnow and check the windowsupdate.log file to see if it's talking to the WSUS server.

I presume when they disappear they don't fall into the Unassigned Computers container, they actually are not showing if you search for them?
SOLUTION
Avatar of Don
Don
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of sitqadmin

ASKER

I ran Group Policy Results on the DC, and the GPO is applied the pc client. See the attach file PolicyResult.bmp. And the WSUS GPO GPOwsus.bmp. Also, you can see the WSUS GPO, attach file GPOwsus.bmp.

I did the following:
net stop wuauserv
Remove the two keys:
SusClientID and SusClientIDValidation in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate
net start wuauserv
wuauclt.exe /resetauthorization /detectnow
wuauclt.exe /r /ReportNow

Now I can view the pc client in All computers and in Unassigned Computer (and it stays there), but not in the Paris group. What else I can do?

 
PolicyResult.bmp
GPOwsus.bmp
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thank you, it's resolved!

The solution is:
In the WSUS console under Options, Computer, make sure that Use Group Policy or settings on computers is selected.

On all computers I need to remove the SusClientIDValidation:

net stop wuauserv

Remove the two keys:
SusClientID and SusClientIDValidation in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate

net start wuauserv

wuauclt.exe /resetauthorization /detectnow

wuauclt.exe /r /ReportNow

Thanks to all