Solved

WSUS  - Planning and remote users

Posted on 2014-01-06
7
1,396 Views
Last Modified: 2016-02-20
Hi all,

At the moment we have no control over Windows updates on our networks. They are just set to auto update.

I have 4 sites that I plan to have local WSUS servers setup. My main problem is remote users. I have a number of laptops that connect via VPN daily, and some very rarely. SO my questions are:

1) What woudl be the best way to configure for laptops?

2) I was going to setup group polices for the different site severs filtered by IP scope for each site, is this a good idea?

3) Current WSUS server is 2008 wsus3 sp2 - should I upgrade to 2012 now for Win 8.1 compatibility?
0
Comment
Question by:MJB2011
  • 3
  • 3
7 Comments
 
LVL 12

Expert Comment

by:Chris
ID: 39758851
You could always setup a web facing WSUS server for the external clients. Not something I've ever seriously looked at but there's no reason it should cause any issues. In this instance I would be inclined to setup WSUS just to manage the updates and not to host them. This way you can manage the updates centrally but they'll still be downloaded from MS, saving you bandwidth.

With regards to the version of windows server, there's no need to upgrade. WSUS is simply a database of updates synced with Microsoft, if they are available on Windows Update they should theoretically be available to the WSUS server whether it's running Server 2012, 2008 or even 2003. Just make sure the WSUS software is up to date.
0
 

Author Comment

by:MJB2011
ID: 39758870
Web server not an option unfortunately.
0
 
LVL 12

Expert Comment

by:Sandeep
ID: 39765042
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:MJB2011
ID: 39765077
Fall back although useful, isnt  going to help, as when user is on VPN they will still see the WSUS and drag updates across VPN rather than heading to microsoft.
0
 
LVL 12

Expert Comment

by:Sandeep
ID: 39765089
So you want all your users to point to Microsoft only? Even though they connect to VPN?
0
 

Author Comment

by:MJB2011
ID: 39765111
Basically I need some how to change the server they are looking at depending on whether they are in the office or at home. when they are at home they could either connect to a wsus server at our VPN termination site or go to Microsoft.
0
 
LVL 12

Accepted Solution

by:
Sandeep earned 500 total points
ID: 39765326
If they are connecting from Home over VPN, I would suggest to keep them connected directly with Microsoft Site rather than connecting to WSUS Server. This will slow down the VPN connection speed for that user while Patches are getting downloaded. But if you want to administer which patches should get installed on that machine, then WSUS is the solution for you.

There is one way you can do it, by creating batch file to run registry modification for the users. But here you have to ask them to run that batch file / registry file accordingly.

Simply save below in a notepad and save as with extension .reg

Refer to below which will assist you to draft your registry file. You can export the current settings and do the modification accordingly.

http://technet.microsoft.com/en-us/library/cc708449(v=ws.10).aspx

Windows Patches are released on Monthly basis, so you can ask User to run batch file at least twice a month. When he is at home, they need to run the registry file which changes server to Microsoft Site, and when working at office need to run WSUS Server Registry file.

Hope this helps
0

Featured Post

Being driven mad by email signature updates?

Having to make a change to your users’ email signatures, yet again? Feel like your head is going to explode? Rely on an Exclaimer email signature management solution to make the process simple!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Experts-Exchange users below are the steps you can follow to upgrade your Lync server to latest CU's or cumulative updates. Note: Perform it during non-production hours.   Step 1: Backup your lync and SQL server database. Follow below article: h…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now