Multiple WSUS servers

Our admin gave our risk dept access to a WSUS server for patch mgmt assurance. A couple of questions:

1) If we run an MBSA report on our PC - it lists WSUS server at the top of the report. The name of the WSUS server is different the one we login to to view WSUS reports. WIll both WSUS servers be reporting the same thing? How can I check?

2) Are the default reports in WSUS reporting machines out of date based on those patches the WSUS admin has approved, or out of date based on those pacthes MS has released? i.e. whats it using as its benchmark to determine out of date machines, the admins approved list, or MS released list?

3) How can we check every workstation and server in the domain is showing up in the WSUS server?
LVL 4
pma111Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

DonNetwork AdministratorCommented:
You may be looking at a Replica WSUS server

http://technet.microsoft.com/en-us/library/cc708511%28v=ws.10%29.aspx

Both options explained here(Replica and Autonomous)
http://technet.microsoft.com/en-us/library/dd939820%28v=ws.10%29.aspx

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
pma111Author Commented:
How can we tell if its a replica server?
DonNetwork AdministratorCommented:
Within the WSUS console, click on Options>>>Update Source


"Synchronize from another Windows Update Services Server" would be checked
The 7 Worst Nightmares of a Sysadmin

Fear not! To defend your business’ IT systems we’re going to shine a light on the seven most sinister terrors that haunt sysadmins. That way you can be sure there’s nothing in your stack waiting to go bump in the night.

pma111Author Commented:
I only have reporter access so I cant see options.
DonNetwork AdministratorCommented:
Reporting still allows you to view the options selected, just dont allow you make changes.
pma111Author Commented:
I cant see where you mean, could you provide a screenshot?
DonNetwork AdministratorCommented:
wsus
pma111Author Commented:
Ok got to that screen - but what field am I looking for?
DonNetwork AdministratorCommented:
What is selected ??

"Synchronize from Microsoft"

Or

"Synchronize from another Windows Update Services Server" (Replica/Downstream)
DonNetwork AdministratorCommented:
Autonomous mode: An upstream WSUS server shares updates with its downstream server or servers during synchronization, but not update approval status or computer group information. Downstream WSUS servers must be administered separately. Autonomous servers can also synchronize updates for a set of languages that is a subset of the set synchronized by their upstream server.

Replica mode: An upstream WSUS server shares updates, approval status, and computer groups with its downstream server or servers. Downstream replica servers inherit update approvals and cannot be administered apart from their upstream WSUS server.

http://technet.microsoft.com/en-us/library/cc720448%28v=ws.10%29.aspx
pma111Author Commented:
sync from microsoft is selected
pma111Author Commented:
If of any relevance, the MBSA reports a server in WSUS server that seems to relate to SCCM. Does SCCM "call" a WSUS server to do its thing, as opposed to do the actual patching.
DonNetwork AdministratorCommented:
Yes SCCM uses WSUS

Things to Know About the Software Update Point (explaining WSUS Integration)

http://blogs.technet.com/b/umeno/archive/2012/01/19/1159715.aspx
pma111Author Commented:
Thanks. Excuse my ignorance, but what does "sync from microsoft is selected" actually tell me about replica/autonomous?
David Johnson, CD, MVPOwnerCommented:
sync from microsoft is selected

This means that you are only using WSUS to approve/deny updates but not downloading the files themselves each client will check with wsus to find out what updates it needs and then download that update from microsoft.  In a small environment where bandwidth is not a problem but disk space is a priority then this is the preferred scenario.  In a large organization, downloading only 1 copy over the internet at the expense of disk space may be an overriding criteria.  In a LOW speed/low bandwidth internet scenario it would also be beneficial.
DonNetwork AdministratorCommented:
"This means that you are only using WSUS to approve/deny updates but not downloading the files themselves each client will check with wsus to find out what updates it needs and then download that update from microsoft."


ABSOLUTELY WRONG!!

An organization can have one or more WSUS servers. Using multiple WSUS servers allows you to scale WSUS in a large organization. If the organization uses multiple WSUS servers, one of the servers will act as the upstream WSUS server (the remaining servers are downstream servers). You use the upstream server to specify the updates that you want to synchronize with Microsoft Update. The upstream WSUS server should have the IUpdateServerConfiguration.SyncFromMicrosoftUpdate configuration setting set to true.

Downstream servers synchronize updates from the upstream WSUS server. There are two forms of downstream servers: autonomous and replica. An autonomous server synchronizes the same updates as the upstream server; however, it can create its own target groups and manage its own approvals.

http://msdn.microsoft.com/en-us/library/windows/desktop/ms744629%28v=vs.85%29.aspx

The "Store updates locally on this server" and "Do not store update files locally; Computers install from microsoft update" setting is in relation to bandwidth/storage...NOT Synchronization

http://technet.microsoft.com/en-us/library/cc708492%28v=ws.10%29.aspx
David Johnson, CD, MVPOwnerCommented:
mea culpa, I had the 2 items mixed up.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft Server OS

From novice to tech pro — start learning today.