What ports need WSUS?

Hi,

Which ports need to be open for WSUS?

Which ports from WSUS server to client servers?

Which port from client servers to WSUS server?

Thanks
LVL 1
SAM2009Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

dipopoCommented:
You can obtaain this from IIS used for WSUS.

To determine the port settings in IIS 6.0
On the WSUS server, open Internet Information Services (IIS) Manager.
Expand Web Sites, right-click the Web site for the WSUS server, and then click Properties. It is recommended that the WSUS custom Web site be used, but the default Web site might have been chosen when WSUS was being installed.
Click the Web Site tab. The HTTP port setting is displayed in TCP port, and the HTTPS port setting is displayed in SSL port.
To determine the port settings used in IIS 7.0
On the WSUS server, open Internet Information Services (IIS) Manager.
Expand Sites, right-click the Web site for the WSUS server, and then click Edit Bindings. It is recommended that the WSUS custom Web site be used, but the default Web site might have been chosen when WSUS was being installed. The port is displayed for each binding.
0
David Paris VicenteSystems and Comunications  Administrator Commented:
For all communication to WSUS servers you need only the base port that the WSUS server is configured to listen on -- port 80, by default; port 8530 if the server is on an alternate virtual root.

    If there is a corporate firewall between WSUS and the Internet, you might need to configure that firewall to ensure that WSUS can obtain updates. To obtain updates from Microsoft Update, the WSUS server uses port 80 for HTTP protocol and port 443 for HTTPS protocol. This is not configurable.

    If your organization does not allow those ports and protocols open to all addresses, you can restrict access to only the following domains so that WSUS and Automatic Updates can communicate with Microsoft Update:
        http://windowsupdate.microsoft.com
        http://*.windowsupdate.microsoft.com
        https://*.windowsupdate.microsoft.com
        http://*.update.microsoft.com
        https://*.update.microsoft.com
        http://*.windowsupdate.com
        http://download.windowsupdate.com
        http://download.microsoft.com
        http://*.download.windowsupdate.com
        http://wustat.windows.com
        http://ntservicepack.microsoft.com


Regards
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
DonNetwork AdministratorCommented:
Official Doc

How to Configure a Firewall for Software Updates

http://technet.microsoft.com/en-us/library/bb693717.aspx
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

SAM2009Author Commented:
What I want to make sure is WSUS needs to talk with client servers or servers will talk with WSUS?
0
David Paris VicenteSystems and Comunications  Administrator Commented:
Both ways.

You can deploy the updates via WSUS or the Servers can contact WSUS by the Update Button.

What do you intend to do?
0
DonNetwork AdministratorCommented:
"You can deploy the updates via WSUS"   ????

No you cant!!!!

WSUS is a pull technology only!!! Clients query WSUS for updates that are needed/approved.
0
SAM2009Author Commented:
OK I see thanks
0
David Paris VicenteSystems and Comunications  Administrator Commented:
dstewartjr
Yes you are right, my mystake, I was thinking about other thing when i write.
Apologies for my mistake.
0
SAM2009Author Commented:
Thanks
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.