Downstream/Upstream Configuration Help


i having difficulty setting downstream/upstream connection, , may simple me being new wsus , not having necessary knowledge apply.  said, assistance appreciated.

i have closed network in wsus server receives updates via import of export package created on different wsus server using wsusutil.exe.  have been tasked upstream server wsus server in different forest configured downstream different wsus server.  not administrator of downstream server , have not control on getting configured.

i attempted add downstream server console fqdn on port 80 , received "cannot connect <server>.  server may using port or differnt ssl setting."  because server configured connect different upstream server or matter?  when change settings pull server, able add them console , able sync server or missing whole lot of other configurations on end? the downstream server not replica server.  will only pull updates.  

thank in advance feedback/assistance.

yes, apparently confused. misread references your closed network, , confused new downstream server added.

in scenario understand, requirement downstream server must reconfigured.

in options | update source , proxy server | update source

the server name (and port number) must modified point server new upstream server.

in addition, since environments cross-forest, i'll consider possibility firewalls involved, you'll need configure firewall rules may needed.

as cross-forest/cross-domain question, speaking, wsus not care. wsus domain agnostic, , there 3 situations in active directory relevant issue:

1. deploying windows update agent configuration via group policy.

2. authenticating remote console connections (there must "domain trust" between console machine , wsus server).

3. authenticating secured server-to-server connections (downstream server synchronization). standard downstream server synchronization connection made anonymously, unless you've implemented features described in section secure wsus 3.0 sp2 deployment in deployment guide related server synchronizations, wsus servers obliviuos domain/forest memberships, or lack thereof.

once downstream server has been configured , synchronizes upstream server, should see downstream server in downstream servers node. absence of entry suggest either server has not been configured (possible), or has not synchronized (more in given scenario).

for question of being able connect downstream server in console ... error received function of "domain trust" requirement of remote console connections. if remote forest/domain not have trust established forest/domain, not able authenticate console connection domain account.

you can, however, 'workaround' limitation creating pseudo-trust between domain account , downstream wsus server creating local account on downstream server using domain account name and your exact domain account password. of course, duplicating password has whole host of potential security issues -- least of being password can extracted sam of wsus server -- one-way forest/domain trust better solution. alternatively, remote desktop machine in remote forest/domain other solution console access downstream server.


lawrence garvin, m.s., mcitp:ea, mcdba, mcsa
principal/cto, onsite technology solutions, houston, texas
microsoft mvp - software distribution (2005-2010)
my mvp profile: http://mvp.support.microsoft.com/profile/lawrence.garvin
my blog: http://onsitechsolutions.spaces.live.com


Windows Server  >  WSUS



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2