Registered users    
MembershipMembership:
Latest New UserLatest:jenisa villarin
New TodayNew Today:12
New YesterdayNew Yesterday:10
User CountOverall:23322

Private messaging    
You must be logged in to use this module.
Top 10 posters    
NamePosts
Mariette Knap12893
Marina Roos12507
Eriq Neale2114
Stan Guinn1913
Michael Patrick1912
Robert Pearman1771
Nick Pieters1425
Stewart Brown616
william warren598
Kevin D.579
Welcome unauthorized visitor    
If you want to join us in the discussions on this forum you need to register first. Registration is free! If you are already a registered user please login to join the forum.
Small Business Server Support Forum    
Subject: Client updates
Prev Next
You are not authorized to post a reply.

Author Messages
Jens Hellberg User is Offline
South Africa
Member since
1/16/2006

Platinum Membership
Posts: 20

11/16/2007 07:54 AM  
After installing ISA no client on the domain can process Windows updates (Error number: 0x80072EFD). All clients use FWC. Clients can browse the internet, connect to remote work place, internal websites, just not Windows updates. Any ideas?
 
Server info:
 - SBS 2003 R2 Premium SP2
 - ISA 2004 SP3
robert pearman User is Offline
United Kingdom
Member since
2/23/2007

Platinum Membership
Posts: 1771

11/16/2007 10:25 AM  
this is quite a common issue.

are your firewall clients also configured as web proxy clients -

we had this issue for a while, and it is one microsoft dont have a 'simple fix' for.

there are a lot of different methods to get round this (that we found whilst troubleshooting)

you can try adding all the windows update sites as trusted sites in IE,

http://support.microsoft.com/kb/836941 - useful starting point

http://support.microsoft.com/kb/900935/ - more info

Good luck!
Jens Hellberg User is Offline
South Africa
Member since
1/16/2006

Platinum Membership
Posts: 20

11/19/2007 07:21 AM  
Hi Robert
 
I've been through a few articles about error 0x80072EFD with no luck so far. I'm thinking about installing WSUS 3.0 and experimenting with that to see if that won't sort out our windows update problem.
 
I suspect our current problem is linked to our clients using FWC and no web proxy. We have gone this route for logging reasons to show user's name and not ip address as described in an artical on isaserver.org
robert pearman User is Offline
United Kingdom
Member since
2/23/2007

Platinum Membership
Posts: 1771

11/19/2007 11:39 AM  
well i guess thats a company decision -

i have my fwc set to use a proxy as well, and my username and client machine are logged, so maybe that is somthing you could review.

WSUS may allow you to get around the problem - as you can specefy the proxy settings in the wsus conneciton properties - however the sbs WSUS install that comes with R2 is quite restrictive (IMO)
Jens Hellberg User is Offline
South Africa
Member since
1/16/2006

Platinum Membership
Posts: 20

11/20/2007 11:20 AM  
Hi Robert
 
I have found a work around although it is not ideal. If I add "All Users" to the "SBS Internet Access Rule" then windows updates work. All domain users are members of "Internet Users", so why does it only work when "All Users" is added? I'm assuming it's got to do with authentication.
robert pearman User is Offline
United Kingdom
Member since
2/23/2007

Platinum Membership
Posts: 1771

11/20/2007 12:59 PM  
i think this may be down to the way the windows update process works - you could try tightening it down by using 'all authenticated users'

although there is a sbs windows update rule - not sure why this is not kicking in - ill check one of my sbs with isa to see their config.
robert pearman User is Offline
United Kingdom
Member since
2/23/2007

Platinum Membership
Posts: 1771

11/20/2007 01:06 PM  
yes the SBS Microsoft Update Sites Access Rule - is HTTP/HTTPS to 2 system policy allowed Domain Name Sets (includes error reporting and all Microsoft update sites) this rule is set to all users - it should be HIGHER in the list than the SBS internet access rule.

this allows for less restricted access to the updates/error reporting sites for all users.
Jens Hellberg User is Offline
South Africa
Member since
1/16/2006

Platinum Membership
Posts: 20

11/20/2007 01:22 PM  
The windows update rule is higher than the internet access rule and is set to "All Users". If I start a query, logging all requests from a user when performing a windows update, some requests come through as anonymous and are caught by the internet access rule and they are denied because they are not authenticated users, unless I add "All Users".
robert pearman User is Offline
United Kingdom
Member since
2/23/2007

Platinum Membership
Posts: 1771

11/20/2007 02:16 PM  
please check that the rule is enabled - and also can you post up the contents of the domain name sets in that update sites rule
You are not authorized to post a reply.



ActiveForums 3.7
Forum policy    
These Discussion Forums are dedicated to the discussion of the Small Business Server and related server and client software. For the benefit of the community please observe the following posting guidelines:
  1. No Advertising. This includes promotion of commercial products and non-commercial products which are not directly related to Small Business Server and related server and client software.
  2. No Flaming or Trolling.
  3. No Profanity, Racism, or Prejudice.
  4. Site Moderators have the final word on approving/removing a thread or post or comment.