SCCM CMG + VPN - Windows update

Karthik Kumar 1 Reputation point
2022-03-23T15:50:26.323+00:00

Hi, Can anyone advice on this. I have SCCM CMG + VPN setup, how to setup the Windows update to install on Devices without spiking Firewall and my proxy will not allow the windows update url *.windowsupdate.com.

Microsoft Security | Intune | Configuration Manager | Updates
Microsoft Security | Intune | Configuration Manager | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Rahul Jindal 11,491 Reputation points
    2022-03-23T17:30:53.887+00:00

    What you should consider is configuring vpn split tunnelling to allow Microsoft urls to directly go over internet and intranet traffic to go via vpn. Make sure to include the cmg and blog storage urls in the split tunnelling configuration. Obviously your VPN needs to support this. Preferably URLs over IPs. See if you can find the list or else let me know and I can share it over here.

    Once done, adjust or create boundary group in ConfigMgr for VPN subnets and add CMG as the resource.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.