Showing posts with label Wsus. Show all posts
Showing posts with label Wsus. Show all posts

Windows 10/11 - how to limit Windows Update bandwidth

Here it is article that explain on how to limit badnwidth used for Windows updates background and foreground downloading.

https://www.thewindowsclub.com/limit-windows-update-bandwidth-windows-10#

Security - Sophos AV stop definitions updates #WORKAROUND & #DETAILS **JULY 2023**

During these latter weeks Sophos released new AV version. (Core Agent 2023.1/Server Core Agent 2023.1 )

PROBLEM

  • This letter Sophos version require that these O.S. have propter September 2021 patches installed.
  • In case you are not on track with MS updates or Windows version it will occur this problem
  • End point Sophos definition updates will stop working
    • Client: Early of July 2023
    • Server: End of July 2023

AFFECTED SYSTEMS AND DEVICES

    • Windows computers:
      • From early-June 2023, Windows 10 (x64) operating systems and above that don't support Azure Code Signing (ACS) will fail to complete the upgrade process to Core Agent 2023.1 and above.
    • Windows servers:
      • From late-July 2023, Windows 2016 operating systems and above that don't support Azure Code Signing (ACS) will fail to complete the upgrade process to Server Core Agent 2023.1 and above.

  WORKAROUND APPLICABLE TO POSTPONE PROBLEM

  • The Software Packages functionality in Sophos Central can be used to assign devices to a Fixed term support (FTS) version.
  • The current version for Windows computers and servers is FTS 2022.4.3.2 and can be assigned to devices for the duration of time it takes to apply the Windows Security Updates.
  • Note: There is an expiry date for all software package versions after which devices will stop updating.
    • The expiry date for FTS 2022.4.3.2 on Windows computers is October 10, 2023.
    • The expiry date for FTS 2022.4.3.2 on Windows servers is November 14, 2023.
  • To achieve this goal you must modify Update Management policy as indicated in below screenshots.

 


APPENDIX

Full details on required updates can be found in Microsoft’s official KB5022661 on this topic. 
https://support.microsoft.com/en-gb/topic/kb5022661-windows-support-for-the-azure-code-signing-program-4b505a31-fa1e-4ea6-85dd-6630229e8ef4

In addition to having the required Windows Security Updates to verify modules signed by Azure Code Signing, devices must have the "Microsoft Identity Verification Root Certificate Authority 2020" certificate authority (CA) installed.

Generally impacted O.S. are Windows 10/11 and Windows 2016/2019/2021 server versions.

Legacy O.S. are not impacted:

Windows 8.1

  1. Windows Server 2012 R2
  2. Windows Server 2012
  3. Windows 7.0 SP1
  4. Windows Server 2008 R2
  5. Windows Server 2008 SP2 

New Installation

From the 18th of April 2023, new installations to operating systems that don't support Azure Code Signing (ACS) will fail.

Freeware - SolarWinds All Free Network/System/Security/DB/clients monitoring tools



Today I would like to mention several SolarWinds Free tools. 

They have limited options against full versions but have interesting features useful for day by day System and Network administration tasks/monitoring/troubleshooting.


System Administrations tools

  1. Solar-PuTTY Connect to any server or device in your network with Solar-PuTTY for Windows. This is an interesting Putty or PuttyCM alternative.
  2. VM Monitor Hyper-V: monitors your VMware vSphere or Microsoft Hyper-V host and associated virtual machines in real-time.
  3. Server Health Monitor Monitor the health, status, and availability of server hardware.
  4. Exchange Monitor  Monitor and alert on performance, availability, and capacity of your Microsoft Exchange servers.
  5. Remote Execution Enabler for PowerShell Streamline PowerShell tasks across all of your servers.
  6. Admin Bundle for Active Directory Keep your Active Directory tidy with this trio of management tools
  7. Permissions Analyzer for Active Directory Get instant visibility into user and group permissions.
  8. VM Monitor Continuously monitor a VMware or Microsoft Hyper-V host and associated virtual machines.
  9. Diagnostic Tool for the WSUS Agent Test WSUS connections and validate Windows Update Agent configuration.
  10. Web Transaction Watcher Easily record and capture the results of a single web transaction.
  11. WMI Monitor  Monitor real-time performance metrics on Windows servers and applications.
  12. SNMP Enabler for Windows Remotely configure SNMP on Windows servers and workstations.
  13. VM Console Bounce problematic VMs without ever logging into VMware vCenter.
  14. Storage Response Time Monitor Track your sluggish VMs and pinpoint exactly where you have high storage latency.

Security and various tools

  1. Free IT Security Tools:  Manage all end-user trouble tickets and track service request lifecycle, from ticket creation to resolution, from one centralized help desk management web interface.
  2. Event Log Forwarder for Windows Forward Windows events based on event source, event ID, users, computers, and keywords in the event to your syslog server in order to take further action.
  3. Firewall Browser Verify firewall rule changes and perform unlimited configuration searches.
  4. Event Log Consolidator  Consolidate logs from up to five Windows servers or workstations Graph events over time to find patterns and troubleshoot issues Send desktop alerts for specific events or export events to CSV.
  5. Free IT Help Desk Tools Manage all end-user trouble tickets and track service request lifecycle, from ticket creation to resolution, from one centralized help desk management web interface.
  6. Database Performance Analyzer Free Reveal performance bottlenecks deep inside your SQL Server, Oracle, DB2 and SAP ASE instances. No other database monitoring tool focuses on response time and Multi-Dimensional Performance Analysis™ like DPA does.

Network Management Tools

  1. Traceroute NG Perform accurate network path analysis.
  2. Port Scanner  Scan available IP addresses and their corresponding TCP and UDP ports to identify network vulnerabilities.
  3. Network Device Monitor: it work on any devieces with snmp credentials enabled there
  4. NetFlow Configurator Quickly and easily activate NetFlow on your network devices with NetFlow Configurator.
  5. GNS3 Network Emulator Construct and test your network in a risk-free virtual environment.
  6. Real Time AppFlow Analyzer Investigate, troubleshoot, and quickly resolve application and network slowdowns.
  7. Response Time Viewer for Wireshark Quickly analyze Wireshark® packet capture files to troubleshoot performance issues.
  8. Network Analyzer & Bandwidth Monitoring Bundle Monitor network bandwidth usage with our free network analyzer and bandwidth monitor.
  9. TFTP Server Free TFTP server for reliable and secure network file transfers.
  10. IP Address Tracker Scan, track, and manage IP addresses and obtain detailed IP histories and event logs.
  11. Real-Time Bandwidth Monitor Keep a close eye on bandwidth usage with this free bandwidth monitor from SolarWinds.
  12. Real-Time NetFlow Analyzer See what types of traffic are on your network with SolarWinds free netflow analyzer.
  13. Call Detail Record Tracker The free SolarWinds tool that lets you monitor VoIP performance.
  14. Network Configuration Generator Automatically create template-based configuration scripts for network devices.
  15. IP SLA Monitor Analyze IP service levels for network-based apps and services with our free IP SLA Monitor.
  16. Advanced Subnet Calculator Help ensure that your IP addresses don’t conflict with one another, and save time managing DHCP, DNS, and IP addresses.
  17. Wake-On-LAN Power up your network PC remotely.
  18. Kiwi Syslog Server Free Edition View and archive syslog messages and SNMP traps in real time.
  19. FTP Voyager FTP Client for Windows FTP, FTPS, and SFTP secure file transfer and automation with a full-featured scheduler.
  20. SFTP/SCP Server Free SFTP server for reliable and secure network file transfers.

Windows 10 - How to manage updates

Today I would like to highlith these Microsoft articles that explain how to manage Windows 10 updates as a service.

Unfortunately they are in italian language but could be easily translated on line to any preferred language.

https://technet.microsoft.com/it-it/itpro/windows/manage/waas-update-windows-10?wt.mc_id=AID521892_EML_4912522

ArgomentoDescrizione
Guida rapida a Windows as a ServiceFornisce un breve riepilogo dei punti principali relativi al nuovo modello di manutenzione per Windows 10.
Panoramica di Windows as a ServiceSpiega le differenze in termini di compilazione, distribuzione e manutenzione di Windows 10, presenta gli aggiornamenti delle funzionalità, gli aggiornamenti qualitativi e i diversi rami di manutenzione e confronta gli strumenti di manutenzione.
Preparare la strategia di manutenzione per gli aggiornamenti di Windows 10Illustra le decisioni da prendere nella strategia di manutenzione.
Creare circuiti di distribuzione per gli aggiornamenti di Windows 10Spiega come usare i rami di manutenzione e i rinvii degli aggiornamenti per gestire gli aggiornamenti di Windows 10.
Assegnare i dispositivi ai rami di manutenzione per gli aggiornamenti di Windows 10Spiega come assegnare dispositivi al ramo CB (Current Branch) o CBB (Branch for Business) per gli aggiornamenti qualitativi e delle funzionalità e come registrare dispositivi in Windows Insider.
Ottimizzare il recapito degli aggiornamenti di Windows 10Illustra i vantaggi dell'uso di Ottimizzazione recapito o BranchCache per la distribuzione degli aggiornamenti.
Gestire gli aggiornamenti per Windows 10 Mobile Enterprise e Windows 10 IoT MobileDescrive gli aggiornamenti per Windows 10 Mobile Enterprise e Windows 10 IoT Mobile.
Gestire gli aggiornamenti con Windows Update for BusinessSpiega come usare Windows Update for Business per gestire quando i dispositivi ricevono gli aggiornamenti direttamente da Windows Update. Include procedure dettagliate per configurare Windows Update for Business tramite Criteri di gruppo e Microsoft Intune.
Gestire gli aggiornamenti di Windows 10 con Windows Server Update Services (WSUS)Spiega come usare WSUS per gestire gli aggiornamenti di Windows 10.
Gestire gli aggiornamenti di Windows 10 con System Center Configuration ManagerSpiega come usare Configuration Manager per gestire gli aggiornamenti di Windows 10.
Gestire i riavvii dei dispositivi dopo gli aggiornamentiSpiega come usare Criteri di gruppo per gestire i riavvii dei dispositivi.

Wsus - How to move Wsus internal database to a different drive on Windows 2012

If you are planning to move Wsus internal database on your windows 2012 Server you can take note about procedure merging these two articles.

Summarizing you need to:


  • install SQL Management 2012 Express Studio, 
  • detach Database, 
  • move database to new drive 
  • reattach it

Move or Delete a WSUS 4 Windows Internal Database (WID) on Windows 


The Windows Server Essentials and Small Business Server Blog

https://blogs.technet.microsoft.com/sbs/2009/09/23/how-to-move-wsus-content-and-database-files-to-a-different-volume/


If you are getting this error during SQL Management console:


Microsoft SQL Server 2012 Release Candidate 0 Setup
The following error has occurred:
Error while enabling Windows feature: NetFx3, Error Code: -2146498298, Please try enabling
Windows feature: NetFx3 from Windows management tools and then run setup again. For more

information on how to enable Windows features, see http://go.microsoft.com/fwlink/?linkid=227143

Start --> CMD --> Run As administrator:

dism /online /enable-feature /featurename:netfx3 /all /source:d:\sources\sxs


(consider to insert CD rom Drive to give 2012 server to find binaries)

Otherwise you can review these articles:

http://www.sqlcoffee.com/troubleshooting101.htm

https://garvis.ca/2013/01/04/installing-netfx3-on-windows-server-2012/

WSUS - Reinstall WSUS with clean Settings

You can go here:

cd %drive%\Program Files\Update Services\Tools

wsusutil reset

To re-install WSUS with a clean database ie no previous configuration;

Run Windows Powershell as Administrator and use the following commands:

Uninstall-WindowsFeature -Name UpdateServices,Windows-Internal-Database -Restart

Post restart, delete EVERYTHING in the "C:\Windows\WID" (for Win 2012 r2) folder, then run the following command to re-install WSUS:

Install-WindowsFeature UpdateServices -Restart

This only works on Powershell 3 or higher. More info here: https://technet.microsoft.com/en-us/library/cc732257.aspx

==============================================================

Related articles:


Wsus - Windows 10 problem and Update enables ESD decryption provision in WSUS in Windows Server 2012 and Windows Server 2012 R2

We faced problems with Wsus server and Windows 10 clients.

This fix solve this kind of issue.

This article describes an update to a feature that enables Windows Server Update Services (WSUS) to natively decrypt Electronic Software Distribution (ESD) in Windows Server 2012 and Windows Server 2012 R2. Before you install this update, see the Prerequisites section.

Note You must install this update on any WSUS server that is intended to sync and distribute Windows 10 upgrades (and feature updates) that are released after May 1, 2016.

https://support.microsoft.com/en-us/kb/3159706



==============================================================

Related articles:


Wsus - Update to enable WSUS support for Windows 10 feature upgrades KB3095113

This update enables Windows Server Update Services (WSUS) on a Windows Server 2012-based or a Windows Server 2012 R2-based server to sync and distribute feature upgrades for Windows 10. This update is not required to enable WSUS to sync and distribute servicing updates for Windows 10.

Important This update must be installed before you sync the upgrades classification. If the update is not installed when the upgrades classification is enabled, WSUS will see the Windows 10 build 1511 feature upgrade even if it can’t properly download and deploy the associated packages. If you try to sync any upgrades without having first installed KB 3095113, you will populate the SUSDB with unusable data that must be cleared before upgrades can be properly distributed. This situation is recoverable but the process is nontrivial and can be avoided altogether if you make sure to install the update before enabling sync of upgrades. If you have encountered this issue, refer to the following article:
For more information about Windows 10 servicing and how feature upgrades and servicing updates differ, see the following TechNet topic:
This update also fixes an issue in which Windows 10-based computers are displayed as "Windows Vista" on Windows Server 2012 R2 or Windows Server 2012.

https://support.microsoft.com/en-us/kb/3095113

WSUS - errors 800B0001 on clients from 2008/2012 server with Wsus role KB2720211

I had clients and server that was trying to download patches from Windows 2008/2012 R2 WSUS server.

Inside c:\windows\windowsupdate.log I got this error:

Agent WARNING: WU client failed Searching for update with error 0x800b0001

To solve this issue I applied this Microsoft article that talk about patch to be installed on Wsus server.

https://support.microsoft.com/en-us/kb/2720211


Update for Windows Server Update Services 3.0 SP2 (KB2720211)

DownloadDownload the package now.

Update for Windows Server Update Services 3.0 SP2 for x64-based Systems (KB2720211)

DownloadDownload the package now. 

Verbosely Procedure:

1. Install this patch on wsus server
  • Download and run Update for Windows Server Update Services 3.0 SP2 for x64-based Systems (KB2720211)
  • http://www.microsoft.com/en-us/download/details.aspx?id=29999
  • After the hotfix is complete, Stop your WWW Service
  • Stop you UPDATE SERVICES Service
  • Perform an IISRESET (which seemed redundant to me, but it does start the WWW service)
  • Start your UPDATE SERVICES

2. Install this patch on Wsus server


  • https://support.microsoft.com/en-us/kb/2734608
  • Issues that are fixed
  • This update lets servers that are running Windows Server Update Services (WSUS) 3.2 provide updates to computers that are running Windows 8 or Windows Server 2012.


if c:\windows\windowsupdate.log on Windows 2012 R2 you view this raw:

WARNING: Failed to get Network Cost info from NLM, assuming network is NOT metered, error = 0x80240037


 open the "local group policy"
    expand  local computer policy -->computer configuration -->windows settings -->security settings --> network list manager policies
    in the right pane you will see Unidentified Networks , double click it , then you can configure theLocation Type when the network connection is unidentified
    If there is domain , you need to change the same entry in "Domain Policy"
    after that please restart your computer
==============================================================

Related articles:


Wsus - how to move repository from one drive to another

If you need to move WSUS 3.0 SP2 repository from a drive to another without download again patches you can proceed in this way:

1. Locate Wsus packages drive and folder
2. Locate wsusutil that should be similar to this examplificative path C:\Program Files\Update Services\Tools
3. give this command line:

wsusutil movecontent  contentpathdestinationpath logfile

For Example

wsusutil movecontent e:\packages d:\move.log

here is official Microsoft article that is exaustive on WSUS 3.0 SP2 

Manage WSUS 3.0 SP2 Storage

https://technet.microsoft.com/en-us/library/dd939905(v=ws.10).aspx

KB3114409 - Outlook 2010 only starts in Safe Mode after installing KB3114409

Last December 2015 outlook 2010 patch KB3114409 creates these problems:


  • Outlook start in safe mode.
  • Outlook 2010 is loaded with the default settings.
  • Reading Pane is turned off.
  • Modified settings aren’t being retained upon restarting Outlook.
  • Add-ins are disabled.
  • The Quick Access Toolbar and Ribbon have been reset and can’t be customized.
  • Instant Search doesn’t work.
Other than remove it in add/remove program if you have a WSUS server with patch approved you need to:


1. In the WSUS administrative console, --> click Updates.

2. In the list of updates, select one or more updates that you want to approve for removal and right-click them.

3. In the Approve Updates dialog box, select the computer group from which you want to remove the update, and click the arrow next to it.

4. Select Approved for Removal, and then click the Remove button.

5. After the remove approval has completed, you may select a deadline by right-clicking the update once more, selecting the appropriate computer group, and clicking the arrow next to it. Then select Deadline.

You may select one of the standard deadlines (one week, two weeks, one month), or you may click Custom to select a specific date and time.

6. If you want an update to be removed as soon as the client computers contact the server, click Custom, and set a date in the past.





2012 - How to install WSUS on 2012 R2

Here is microsoft article that, step by step, give you instruction how to install WSUS role on Windows 2012 R2 Server.

https://technet.microsoft.com/en-us/library/hh852344.aspx

Wsus - Choose your best WSUS architecture

Here they are two official Microsoft Guide to explain you all options to better determine your company wsus infastructure.




here they are some options:

1. There is possibility to define an upstream server where approve patch and replicate to downstream servers. In this case you can decide, to preserve mpls connectivity, to download patch with local internet withouth downloading them from upstream server.
2. Support about roaming clients to point to nearest wsus server.
3. Manage branch offices
4. Centralized management
6. Distributed management



Branch offices

· Using the BranchCache feature:

BranchCache is a new feature in Windows 7 and Windows Server 2008 R2 that reduces
WAN link utilization and improves application responsiveness. To enable BranchCache
acceleration of content served by the WSUS server, install the BranchCache feature on the
server and the clients, and ensure that the BranchCache service has started. No other steps
are necessary. For information about installing BrancheCache, see the
BranchCache Early
Adopter's Guide
(http://go.microsoft.com/fwlink/?LinkId=148741).

· Branch offices with low-bandwidth connections:

In some organizations, branch offices have low-bandwidth connections to the central office
but high-bandwidth connections to the Internet. In this case you may want to configure
 about how to set up this kind of configuration, see
Advanced Synchronization Options.



Support for roaming clients

If you have many mobile users who log on to your network from different sites, you may want to use the following configuration to allow them to update their computers from the closest WSUS server. In this configuration, shown in the "Roaming Clients Using Different WSUS Servers" illustration below, there is one WSUS server per region, and each region is a DNS subnet. All clients are pointed to the same WSUS server name, which resolves in each subnet to the nearest WSUS server. See Appendix D: Configure WSUS for Roaming Clients for more information about how to configure DNS to support roaming clients.



Centralized management

Centrally managed WSUS servers utilize replica servers. Replica servers are not administered separately, and are used only to distribute approvals, groups, and updates. The approvals and targeting groups you create on the master server are replicated throughout the entire organization, as shown in the "WSUS Centralized Management (Replica Servers)" illustration below. Remember that computer group membership is not distributed throughout the replica group, only the computer groups themselves. In other words, you always have to load client computers into computer groups.

It is possible that not all the sites in your organization require the same computer groups. The important thing is to create enough computer groups on the administered server to satisfy the needs of the rest of the organization. Computers at different sites can be moved into a group appropriate for the site. Meanwhile, computer groups inappropriate for a particular site simply remain empty. All update approvals, like computer groups, must be created on the master server.

For step-by-step instructions, see Create Replica Servers later in this guide.

You should also make sure that the upstream server is configured for all the languages required by its replica servers. If you add languages to the upstream server, you should copy the new updates to its replica servers. Changing language options on the upstream server alone might result in a mismatch between the number of updates that are approved on the central server and the number of updates approved on the replica servers



Distributed management

Distributed management offers you full control over approvals and computer groups for the
WSUS server, as shown in the "WSUS Distributed Management" illustration below. With the
distributed management model, there is usually an administrator at each site who decides which update languages are needed, creates computer groups, assigns computers to groups, tests and approves updates, and ensures that the correct updates are installed on the right computer groups. Distributed management is the default installation option for all WSUS installations.




Using express installation files

You can use express installation files to limit the bandwidth consumed on your local network, at the cost of bandwidth consumption on your Internet connection and disk space. By default WSUS does not use express installation files. To understand the tradeoff, you first have to understand how WSUS updates client computers.

Updates typically consist of new versions of files that already exist on the computer being
updated. On a binary level these existing files might not differ very much from updated versions.

The express installation files feature is a way of identifying the exact bytes that change between different versions of files, creating and distributing updates that include just these differences, and then merging the original file with the update on the client computer. Sometimes this is called delta delivery because it downloads only the difference, or delta, between two versions of a file.

When you distribute updates this way, there is an initial investment in bandwidth. Express
installation files are larger than the updates they are meant to distribute. This is because the
express installation file must contain all the possible variations of each file it is meant to update.

The upper part of the "Express Installation Files Feature" illustration shows an update being
distributed with express installation files; the lower part of the illustration shows the same update being distributed without using express installation files. Notice that with express installation files enabled, you incur an initial download three times the size of the update. However, this cost is mitigated by the reduced amount of bandwidth required to update client computers on the corporate network. With express installation files disabled, your initial download of updates is smaller, but the full size of the download must then be distributed to each of the clients on your corporate network.

Express Installation Files Feature

The file sizes in the "Express Installation Files Feature" illustration are for illustrative purposes only. Each update and express installation file varies in size, depending on what files need to be updated. Further, the size of each file actually distributed to clients by using express installation files varies depending upon the state of the computer being updated.

Important

Express installation files are often larger than the updates they are meant to distribute.
On the other hand, it is always less expensive to distribute updates within a network
using express installation files than to distribute full update files.

Not all updates are good candidates for distribution using express installation files. If you select this option, you obtain express installation files for any updates being distributed this way. If you are not storing updates locally, you cannot use the express installation files feature. By default, WSUS does not use express installation files. To enable this option, see
Advanced Synchronization Options.

Secure WSUS 3.0 SP2 Deployment

This guide includes three ways to enhance the security of your WSUS server: