Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Managing remote laptops via WSUS 3..0

Posted on 2009-07-13
11
Medium Priority
?
559 Views
Last Modified: 2012-06-27
Hi ,

We have setup WSUS 3.0 SP1 in our internal LAN .There are absolutely no issues with the updates propagating across the clients in LAN .. But i have a scenario where some of the users are Roaming. I dont want them to recieve s the updates from WSUS when connected thro' VPN cos' as you know it clog the Bandwidth . I want them to directly connect to Microsoft Update Server and download the updates.

Is there any ways to achieve this ?

Thanks for the help in advance
0
Comment
Question by:Arisglobal
  • 5
  • 4
  • 2
11 Comments
 
LVL 1

Expert Comment

by:unluckynelson
ID: 24840352
Do they connect onto VPN through ISA server?
If so you can simply create a firewall rule to block the WSUS access on ISA...
0
 
LVL 3

Author Comment

by:Arisglobal
ID: 24840655
No We dont have ISA Server. Can we block the ports on the Firewall box which isn't ISA Server?
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24840689
You will need to setup another WSUS server and configure it to NOT store updates locally and point your laptops to this server.
0
Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

 
LVL 3

Author Comment

by:Arisglobal
ID: 24840825
Thanks for the reply dstewartj I had this idea before  but i dont wanna have 2 WSUS servers running. its kinda complicated and have to look after both the servers
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24840918
This will be the the only way, It's a all or nothing. You could just put these laptops in another GPO that only uses windows updates,but you wont be able to control these updates(I.E. Approvals)
0
 
LVL 1

Expert Comment

by:unluckynelson
ID: 24840942
The transmission protocols and ports used are HTTP 80 and HTTPS 443. So you could block those ports to the server from the VPN IP Pool....
Unfortunately these are also web ports so you can't block them across the board...
0
 
LVL 3

Author Comment

by:Arisglobal
ID: 24841135
If I configure these laptops for another GPO when the roaming users are back to the office.. they still continue recieve the updates from Windows Updates .

Can't we run any script wherein it checks for the IP ADDRESS  of the local Machine if it points to LAN the registry should point to WSUS server or else to windows updates
0
 
LVL 47

Accepted Solution

by:
Donald Stewart earned 1500 total points
ID: 24841350
Create a .reg file with your settings for WSUS and one for Microsoft.
Then use a startup script similar as below.
Modify the gateways below to match your environment, if you have more just add more lines.
 


set GW=
for /f "tokens=2 delims=:" %%a in ('ipconfig ^| find "Gateway"') DO SET GW=%%a
if %GW%== 10.63.106.2 regedit /s \\server\share\WSUS.reg    
if %GW%== 10.63.106.130 regedit /s \\server\share\Microsoft.reg

Open in new window

0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24841617

 
 The below would be all you need to set it to use Microsoft  Updates.
 

Windows Registry Editor Version 5.00
 
[-HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\]
 
 
 
 
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\AU\]
 
 
"UseWUServer"=dword:00000000

Open in new window

0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24848944
So a "B" cause you didnt like the answer???
0
 
LVL 3

Author Comment

by:Arisglobal
ID: 24848984
I'am forced to accept the answer cos' u know most of the users using Laptop will nvr shutdown their laptops put in hibernation or standby .. i have to schedule the script as the job for each ..and moreover i don't prefer scripting . Was thinking is there anyways goaround without using scripts .. But the when architecture is something like this.. i'm forced to accept it
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
Learn about cloud computing and its benefits for small business owners.
In this video, Percona Director of Solution Engineering Jon Tobin discusses the function and features of Percona Server for MongoDB. How Percona can help Percona can help you determine if Percona Server for MongoDB is the right solution for …
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question