Re: Utilizing SUS without Server Internet Connectivity

From: Shenan Stanley (news_helper_at_hushmail.com)
Date: 01/19/05


Date: Wed, 19 Jan 2005 08:13:27 -0600

Comments inline and at the end..

JJ8863 wrote:
> Internet connectivity to a server can not and will not happen. SUS
> needs to have connectivity to Microsoft's web site, this can not
> happen. This was also the case with MBSA, however Microsoft has made
> available a file that can be downloaded so the Baseline Security
> Analyzer can be used without connecting to the internet. The file can
> be downloaded, copied to a memory stick and placed the the MBSA
> directory.
> Can SUS be utilized in the same way?

Not that I know of. At least one server must have Internet Connectivity.
That's ONE server - not every machine on your network.

> I have noticed a few entries asking this question, however there are
> no good answers that could be used within our environment.
> Is anyone aware of how this can be done?

Well, no - not without knowing what about the other answers did not fit your
environment - what is your environment and why is the statement "Internet
connectivity to a server can not and will not happen.." true in your
environment?

> What specifically is SUS
> downloading, where is this being downloaded from and where is it being
> placed. How are the updates made available?

Wow - maybe you should read some before posting.
Below I have one page (Patch Management Using Microsoft Software Update) and
another you should look at:
http://www.microsoft.com/windowsserversystem/sus/susoverview.mspx
and
http://www.microsoft.com/windowsserversystem/sus/default.mspx

SUS is downloading an update catalog based somewhat on parameters you give
it from Microsoft. The catalog is compared to what you already have then
the updates that you do not have are downloaded (again) from Microsoft. You
then, as administrator (depending on setup of the SUS server) choose what
updates of those it has available - you would like ACTUALLY available to
your clients - for whom you have (either through group policies or registry
values) set to get updates from your SUS server.

> Are they the same
> download format as they are available from Microsofts download site?

> Is there a .cab avaliable for these functions.
> I am going to try and install SUS onto one of our servers tomorrow
> and try and manipulate SUS to work in our environment, but if anyone
> could supply any information or ideas I would appreciate it.

Truthfully.. You need at least one machine that has internet connectivity in
order to utilize SUS.

Look through these for ideas..
http://myitforum.techtarget.com/articles/20/view.asp?id=7586

Same person, different responders:
http://www.webservertalk.com/message286528.html

SUS Guidance page:
http://www.microsoft.com/technet/itsolutions/cits/mo/swdist/pmsus/pmsus252.mspx

-- 
<- Shenan ->
-- 
The information is provided "as is", it is suggested you research for
yourself before you take any advice - you are the one ultimately
responsible for your actions/problems/solutions.   Know what you are
getting into before you jump in with both feet. 


Relevant Pages

  • Re: SUS download question?
    ... The SP 2 as used by Sus ... About you only choice is to use a network attached Sus ... Microsoft MVP (Windows Server System: ... > update on a SUS server instead of downloading it? ...
    (microsoft.public.win2000.security)
  • Re: SBS 2003 and SUS
    ... If you're sometimes getting "server can't be reached" and sometimes "can't ... I can't tell you my configuration since I'm running SUS on the SBS, ... You may have to try downloading the catalog several ... If you don't succeed in downloading the catalog after trying it a few times, ...
    (microsoft.public.windows.server.sbs)
  • XP clients not receiving windows updates from SUS server
    ... I have setup SUS on Windows SBS 2000 server and it all appears ... to be synchronising and downloading the updates with no problems. ... my XP SP1 workstations are not getting the updates from the ... I have set SUS up on other sites, and the only noticable difference on ...
    (microsoft.public.win2000.advanced_server)
  • Re: SUS or wait for WUS?
    ... SUS it is then, with updates remaining on Microsoft's server, they will all ... >> them on the server would be fine but downloading masses of unnecessary ...
    (microsoft.public.windows.server.sbs)
  • Re: User autentification and access to "sister" domain resources
    ... As to SUS... ... I don't see why it wouldn't work as long as the host can resolve the server ... > siteA and another rootDC2 in siteB. ... > - link to all DCs from domain A is suddenly broken, ...
    (microsoft.public.win2000.active_directory)