Solved

WSUS server in DMZ?

Posted on 2011-03-08
9
1,962 Views
Last Modified: 2012-05-11
My firewall is currently configured such that there are no inbound connections from the DMZ to my internal network. I am looking at adding a WSUS server in the DMZ. Is there any way to configure WSUS such that the configuration is pushed from the internal to the DMZ server? Everything I've seen so far requires opening 80 and 443 to my internal network. I'm just looking for the meta data on my server and the updates themselves provided by MS.
0
Comment
Question by:timbrigham
9 Comments
 
LVL 10

Expert Comment

by:NetExpert-Warszawa
ID: 35074071
Why do you want to put WSUS into DMZ? DMZ is for services available for outside. Put WSUS into your internal network. It is the place for it. You will not have problems with a firewall either.
0
 
LVL 13

Expert Comment

by:kdearing
ID: 35074223
Agreed. WSUS belongs in the internel network, not the DMZ where it's publicly available.
0
 
LVL 1

Author Comment

by:timbrigham
ID: 35086633
I don't want to place my internal WSUS server into the DMZ, but I would like to control what updates my users receive while in the field. There have been too many cases where an update from MS has broken one of our systems and we're not able to address it when the user is half way around the world. I'm not aware of a way to do this without a WSUS server; if there is a way to do please enlighten me.

I would like to have a secondary WSUS server located in the DMZ strictly for these remote users I want to do so without opening any ports from the DMZ into my internal network.
0
Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

 
LVL 1

Author Comment

by:timbrigham
ID: 35087072
More specifically I'm looking for a way to synchronize the approvals from the internal to the external server.  
0
 
LVL 10

Accepted Solution

by:
NetExpert-Warszawa earned 500 total points
ID: 35087178
You do not need to use ports 80 or 443. However since you do not want to open any ports, consider http://technet.microsoft.com/en-us/library/cc720486%28WS.10%29.aspx
0
 
LVL 23

Expert Comment

by:Suliman Abu Kharroub
ID: 35087840
You need to deploy WSUS on Replica mode:

http://technet.microsoft.com/en-us/library/cc720448(WS.10).aspx

downstream and upstream server.
depends on you config; allow https(s) from DMZ to internal..
0
 
LVL 1

Author Comment

by:timbrigham
ID: 35087968
Many thanks gentlemen. The disconnected network configuration looks appealing. Is there a way to use that configuration with the meta data only?
0
 
LVL 10

Expert Comment

by:NetExpert-Warszawa
ID: 35088078
Just skip step 2 :)

Why don't you want to copy updates? Do you want to download them twice from the Internet?
0
 
LVL 1

Author Comment

by:timbrigham
ID: 35109195
I want my clients to connect to the MS site for retrieving the windows updates, not the local WSUS server in the DMZ. My bandwidth is provided by a co location facility and we pay for overages - I'd rather our users not be retrieving publicly available files on our dime.
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Eigrp versus OSPF in a ring topology 3 75
cutting over to a new network 9 102
SQL 2016 licensing 6 49
Unmanaged Switches for Optimized Network Speeds 7 40
Hello to you all, I hear of many people congratulate AWS (Amazon Web Services) on how easy it is to spin up and create new EC2 (Elastic Compute Cloud) instances, but then fail and struggle to connect to them using simple tools such as SSH (Secure…
This collection of functions covers all the normal rounding methods of just about any numeric value.
The viewer will learn how to create a normally distributed random variable in Excel, use a normal distribution to simulate the return on an investment over a period of years, Create a Monte Carlo simulation using a normal random variable, and calcul…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question