Managing remote laptops via WSUS 3..0

Hi ,

We have setup WSUS 3.0 SP1 in our internal LAN .There are absolutely no issues with the updates propagating across the clients in LAN .. But i have a scenario where some of the users are Roaming. I dont want them to recieve s the updates from WSUS when connected thro' VPN cos' as you know it clog the Bandwidth . I want them to directly connect to Microsoft Update Server and download the updates.

Is there any ways to achieve this ?

Thanks for the help in advance
LVL 3
ArisglobalAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

unluckynelsonCommented:
Do they connect onto VPN through ISA server?
If so you can simply create a firewall rule to block the WSUS access on ISA...
0
ArisglobalAuthor Commented:
No We dont have ISA Server. Can we block the ports on the Firewall box which isn't ISA Server?
0
DonNetwork AdministratorCommented:
You will need to setup another WSUS server and configure it to NOT store updates locally and point your laptops to this server.
0
Cloud Class® Course: Microsoft Windows 7 Basic

This introductory course to Windows 7 environment will teach you about working with the Windows operating system. You will learn about basic functions including start menu; the desktop; managing files, folders, and libraries.

ArisglobalAuthor Commented:
Thanks for the reply dstewartj I had this idea before  but i dont wanna have 2 WSUS servers running. its kinda complicated and have to look after both the servers
0
DonNetwork AdministratorCommented:
This will be the the only way, It's a all or nothing. You could just put these laptops in another GPO that only uses windows updates,but you wont be able to control these updates(I.E. Approvals)
0
unluckynelsonCommented:
The transmission protocols and ports used are HTTP 80 and HTTPS 443. So you could block those ports to the server from the VPN IP Pool....
Unfortunately these are also web ports so you can't block them across the board...
0
ArisglobalAuthor Commented:
If I configure these laptops for another GPO when the roaming users are back to the office.. they still continue recieve the updates from Windows Updates .

Can't we run any script wherein it checks for the IP ADDRESS  of the local Machine if it points to LAN the registry should point to WSUS server or else to windows updates
0
DonNetwork AdministratorCommented:
Create a .reg file with your settings for WSUS and one for Microsoft.
Then use a startup script similar as below.
Modify the gateways below to match your environment, if you have more just add more lines.
 


set GW=
for /f "tokens=2 delims=:" %%a in ('ipconfig ^| find "Gateway"') DO SET GW=%%a
if %GW%== 10.63.106.2 regedit /s \\server\share\WSUS.reg    
if %GW%== 10.63.106.130 regedit /s \\server\share\Microsoft.reg

Open in new window

0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
DonNetwork AdministratorCommented:

 
 The below would be all you need to set it to use Microsoft  Updates.
 

Windows Registry Editor Version 5.00
 
[-HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\]
 
 
 
 
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\AU\]
 
 
"UseWUServer"=dword:00000000

Open in new window

0
DonNetwork AdministratorCommented:
So a "B" cause you didnt like the answer???
0
ArisglobalAuthor Commented:
I'am forced to accept the answer cos' u know most of the users using Laptop will nvr shutdown their laptops put in hibernation or standby .. i have to schedule the script as the job for each ..and moreover i don't prefer scripting . Was thinking is there anyways goaround without using scripts .. But the when architecture is something like this.. i'm forced to accept it
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Server Hardware

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.