Re: SMS2003 -Direct Internet Connection?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Richard Threlkeld (pleasenospam_at_hotmail.com)
Date: 04/19/04


Date: Mon, 19 Apr 2004 16:31:47 -0700

Sorry for the late reply Matthew, missed this one the other day...

Can you run the DSUW from an Admin workstation that has internet access?
This way the admin workstation can speak to your site server and pull down
the updates without your site server needing internet access.

--
Richard Threlkeld
Microsoft MVP - SMS
Looking to get more involved in the SMS community?
Join the SMS email discussion list today:
http://lists.listleague.com/mailman/listinfo/mssms
"Matthew" <matthew.edwards@blue-source.com> wrote in message
news:8BD9010E-2671-4B48-93C9-92BD8FA5E656@microsoft.com...
> Thanks for your quick reply Richard,
>
> I don't think that these suggestions address the issue however :-(
>
> The problem we have is that SMS will not let you pull down a patch from
Microsoft unless it can talk simultaneously to the Site server. This breaks
our security (the synch client can talk to the Internet or our SMS site
server - but not at the same time.) This used to work quite well with SUS as
we could switch the SUS NICs to the Internet connection and download the
patches and then switch the SUS server back to the LAN to approve and deploy
them.
>
> Do you have any other ideas?
>
> Thanks
>
> Matthew
>
>      ----- Richard Threlkeld <MVP> wrote: -----
>
>      The Sync Host can be any SMS client in your site heirarchy, and if
you want
>      it to automatically download the latest catalog it can be configured
to do
>      so if it has an internet connection.  You can also use
patchdownloader.exe
>      to use a user account of your choice.  If you don't want this either,
you
>      can manually download the latest security update bulletin catalog
>      (mssecure.cab) from http://go.microsoft.com/fwlink/?LinkId=23130 and
place
>      it in the Scan Tool package Data Source, then refresh your
Distribution
>      Points.  Or you could do the same process you did with your SUS
Server and
>      muli-NIC your Sync Host.
>
>      --
>      Richard Threlkeld
>      Microsoft MVP - SMS
>
>      Looking to get more involved in the SMS community?
>      Join the SMS email discussion list today:
>      http://lists.listleague.com/mailman/listinfo/mssms
>
>      "Matthew" <matthew.edwards@blue-source.com> wrote in message
>      news:A4E73EE6-7815-4297-835F-3C457D7AFCD2@microsoft.com...
>      > Hi - I have found what appears to be a major disadvantage of
SMS2003 vs
>      SUS.
>      >> Up until now we have been using SMS 2.0 with SUS to roll out
hotfixes etc.
>      >> Because of tight security we cannot connect our network directly
to the
>      internet. So we have two NICs in the SUS server (one private and the
other
>      public) and disable the private NIC whilst retrieving updates from
MS.
>      >> We are trying to roll out SMS2003 with a Software synchronization
client,
>      but it would appear that the synchronization server requires direct
access
>      to the SMS site server and MS at the same time, which is impossible
with our
>      security restrictions. Is there any way around this? I had thought of
>      building a phantom site server on the public network and using DTS or
some
>      other tool to replicate table changes to the live site server.
>      >> Can you help?
>      >


Relevant Pages

  • Re: SMS2003 -Direct Internet Connection?
    ... since the Internal network and the 'Internet access' network are completely ... Site server, which our setup simply can't accomodate. ... > Can you run the DSUW from an Admin workstation that has internet access? ... > Looking to get more involved in the SMS community? ...
    (microsoft.public.sms.swdist)
  • SMS Software update...or ... WSUS
    ... sys2 synchost (with internet connection) ... i have installed & configured SMS software update... ... as per documentation sync host updates security updates catalog file. ... this info is updated to site server. ...
    (microsoft.public.sms.swdist)
  • Re: SMS2003 Vs SMS2/SUS problem
    ... Sorry for the late response. ... SMS 2003 Technical FAQ: ... > vs SUS. ... I had thought of building a phantom site server on the public ...
    (microsoft.public.sms.setup)
  • Re: SMS & SUS Compatibility
    ... > Will SMS function properly when SUS is installed on the site server? ... I do have SUS ... If the sms site server is performing any functions that require IIS then ... you might run into problems because sus automatically runs IIS lockdown. ...
    (microsoft.public.sms.admin)
  • Re: Too Many DDR Files - Please Help :( Giant SMS Heirarchy
    ... We have over 70,000 sms clients now joined to a central site server (that is really just a reporting server.. ... Since we joined 8 area level SMS site servers to the central site server, we are now experiencing a huge backlog of DDR files. ... I could see how lower level discovery settings could be overvelming our central site server. ...
    (microsoft.public.sms.setup)