Usages of "allow downloads from other pcs" option / in corporate environment and WSUS (SOHO)

Gio Gogilashvili 0 Reputation points
2024-02-01T08:30:36.9+00:00

Hello, Is "allow downloads from other pcs" option necessary to be on in corporate environment when we use WSUS to push updates? We have WSUS and we push updates from the server, but by default the option "allow downloads from other pcs" in windows in enabled, should I disable this option? Then, will it cause slow network operations or better performace? Our internal website becomes very slow ufter pushing updates from WSUS, (this can be network bandwidth fault or other problem) (and "allow downloads from other pcs" option was enabled by default in this case and wonder if it is better be on or off in our case) I don't know if generally you must configure GPO in corporate environment to disable "allow downloads from other pcs" option if you use WSUS. As Microsoft says: "Sharing this data between PCs helps reduce the internet bandwidth that’s needed to keep more than one device up to date or can make downloads more successful if you have a limited or unreliable Internet connection." Thanks

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Adam J. Marshall 10,356 Reputation points
    2024-02-02T00:57:08.2566667+00:00

    First, WSUS NEVER pushes updates. WSUS is a pull system. You approve an update, it sits in the repository until the client agent pulls the update to itself. You "use WSUS to distribute updates" is a more correct way of saying it.

    I would recommend that you CONTINUE to use it.

    https://www.ajtek.ca/wsus/how-to-setup-manage-and-maintain-wsus-part-4-creating-your-gpos-for-an-inheritance-setup/

    It does not cause problems and always starts with the WSUS server download initiation first, then it moves to 'hey, does anyone here have this file I can download from you?'.

    The issue with your internal website becoming very slow would have a different reason. Is it housed on the same server as WSUS? If yes, then you're saturating the Ethernet line with traffic from both websites - your internal website and the WSUS Administration website. Allowing DO to properly fetch updates from peers would actually be a benefit in this case.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.