Solved

Managing remote laptops via WSUS 3..0

Posted on 2009-07-13
11
555 Views
Last Modified: 2012-06-27
Hi ,

We have setup WSUS 3.0 SP1 in our internal LAN .There are absolutely no issues with the updates propagating across the clients in LAN .. But i have a scenario where some of the users are Roaming. I dont want them to recieve s the updates from WSUS when connected thro' VPN cos' as you know it clog the Bandwidth . I want them to directly connect to Microsoft Update Server and download the updates.

Is there any ways to achieve this ?

Thanks for the help in advance
0
Comment
Question by:Arisglobal
  • 5
  • 4
  • 2
11 Comments
 
LVL 1

Expert Comment

by:unluckynelson
ID: 24840352
Do they connect onto VPN through ISA server?
If so you can simply create a firewall rule to block the WSUS access on ISA...
0
 
LVL 3

Author Comment

by:Arisglobal
ID: 24840655
No We dont have ISA Server. Can we block the ports on the Firewall box which isn't ISA Server?
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24840689
You will need to setup another WSUS server and configure it to NOT store updates locally and point your laptops to this server.
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 
LVL 3

Author Comment

by:Arisglobal
ID: 24840825
Thanks for the reply dstewartj I had this idea before  but i dont wanna have 2 WSUS servers running. its kinda complicated and have to look after both the servers
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24840918
This will be the the only way, It's a all or nothing. You could just put these laptops in another GPO that only uses windows updates,but you wont be able to control these updates(I.E. Approvals)
0
 
LVL 1

Expert Comment

by:unluckynelson
ID: 24840942
The transmission protocols and ports used are HTTP 80 and HTTPS 443. So you could block those ports to the server from the VPN IP Pool....
Unfortunately these are also web ports so you can't block them across the board...
0
 
LVL 3

Author Comment

by:Arisglobal
ID: 24841135
If I configure these laptops for another GPO when the roaming users are back to the office.. they still continue recieve the updates from Windows Updates .

Can't we run any script wherein it checks for the IP ADDRESS  of the local Machine if it points to LAN the registry should point to WSUS server or else to windows updates
0
 
LVL 47

Accepted Solution

by:
Donald Stewart earned 500 total points
ID: 24841350
Create a .reg file with your settings for WSUS and one for Microsoft.
Then use a startup script similar as below.
Modify the gateways below to match your environment, if you have more just add more lines.
 


set GW=
for /f "tokens=2 delims=:" %%a in ('ipconfig ^| find "Gateway"') DO SET GW=%%a
if %GW%== 10.63.106.2 regedit /s \\server\share\WSUS.reg    
if %GW%== 10.63.106.130 regedit /s \\server\share\Microsoft.reg

Open in new window

0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24841617

 
 The below would be all you need to set it to use Microsoft  Updates.
 

Windows Registry Editor Version 5.00
 
[-HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\]
 
 
 
 
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\AU\]
 
 
"UseWUServer"=dword:00000000

Open in new window

0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24848944
So a "B" cause you didnt like the answer???
0
 
LVL 3

Author Comment

by:Arisglobal
ID: 24848984
I'am forced to accept the answer cos' u know most of the users using Laptop will nvr shutdown their laptops put in hibernation or standby .. i have to schedule the script as the job for each ..and moreover i don't prefer scripting . Was thinking is there anyways goaround without using scripts .. But the when architecture is something like this.. i'm forced to accept it
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Usually shares are where we want them for our users and we tend to take them for granted. There are times, however, when those shares may disappear causing difficulty for your users. One of the first things to try is searching for files that shou…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…
I've attached the XLSM Excel spreadsheet I used in the video and also text files containing the macros used below. https://filedb.experts-exchange.com/incoming/2017/03_w12/1151775/Permutations.txt https://filedb.experts-exchange.com/incoming/201…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question