question

Meeee-1869 avatar image
0 Votes"
Meeee-1869 asked RitaHu-MSFT edited

WSUS Set client default download location

I am in the process of setting up a new WSUS server on windows 2019, I have set the server up and am looking at GPO options. We run a multi office environment which includes a lot of mobile people.

I was wondering is there a way to get configure the desktops / laptops to check the WSUS server for which updates they are allowed to install but to get them to pull the updates down direct from the intranet instead. Looking at the GPO options I have to set -
“Set intranet update service for detecting updates” & “Set the intranet statistics server” both to the new server, I am guessing this will then tell the workstations to check and then pull the updates from these servers?

Is there a way to check the server but pull direct from MS?

windows-serverwindows-server-update-services
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Meeee-1869 avatar image
0 Votes"
Meeee-1869 answered RitaHu-MSFT converted comment to answer

Thank you very much

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

AJTek-Adam-J-Marshall avatar image
0 Votes"
AJTek-Adam-J-Marshall answered

You will want to check out my blog regarding this.

https://www.ajtek.ca/wsus/externally-facing-wsus-servers/

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Meeee-1869 avatar image
0 Votes"
Meeee-1869 answered AJTek-Adam-J-Marshall commented

Thanks for the info, so basically I need to set up an additional server in the DMZ and then get the Workstations to pull the updates from here? There is no way for them to talk to the internal server via a VPN then pull the updates directly from microsoft updates rather than them pulling them from the internal server?

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Not if you want the 'AND'

Internally download from WSUS, AND externally download from Microsoft (without VPN - if on VPN they are considered Internal)

You can set WSUS to not store updates and ALL updates download from Microsoft - both internal and external connections/vpn

0 Votes 0 ·
Meeee-1869 avatar image
0 Votes"
Meeee-1869 answered Meeee-1869 published

Thanks, very helpful.
just out of interest how can I set the WSUS server to - "You can set WSUS to not store updates and ALL updates download from Microsoft - both internal and external connections/vpn"

Most of our staff are external so as long as they query the WSUS server for which updates are approved but download them directly from MS that would be fine.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

AJTek-Adam-J-Marshall avatar image
0 Votes"
AJTek-Adam-J-Marshall answered

WSUS Options > Update Files and Languages > Put the radial dot in "Do not store update files locally; computers install from Microsoft Update"

Also, verify you have the "Alternative download location" blank in your WSUS Location GPOs or the computers won't be able to download from Microsoft.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

RitaHu-MSFT avatar image
1 Vote"
RitaHu-MSFT answered RitaHu-MSFT edited

@Meeee-1869
I agree with @AJTek-Adam-J-Marshall

Please tick the below option on the WSUS console. Then the clients will connect to the Internet to get the approved updates when the clients scan for updates from WSUS.
145737-1.png

It seems that it is a helpful solution. Please have a try if the issue haven't been resolved. Please don't forget to accept the helpful solution as an answer if the issue has been resolved. It will be helpful the others to save time researching.

Thanks for your time and wish you have a nice day :)

Regards,
Rita


If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


1.png (93.6 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.