Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows Server in DMZ dosn't fetch Windows Updates

Dear community,

at present I'm looking for a solution for the following scenario:
I've got a Windows Server sitting in the DMZ.
For security reasons, direct I-net access is not allowed.

To allow Windows Update Downloads, I followed this KB article https://support.sophos.com/support/s/article/KB-000036981?language=en_US
by creating the needed exception.
But even when created and set to active, this doesn't seem to do the job.

When I start the Update process on the server, it displays some found Updates but doesn't download them
Instead it stays forever in the state "download pending".

Any help to resolve this is appreciated.

Best regards
ranX



This thread was automatically locked due to age.
Parents Reply
  • Well, still no luck.  To trigger update traffic on the windows host, I always do "net stop wuauserv" and "net start wuauserv".
    To be sure, the update service does a full refresh, I even delete the "SoftwareDistribution" folder.  
    On the machine the refresh of available update always works, but when it gets to the point, to download them, it's stuck at the state "download pending".

    At that time there is nothing to see on the Web Filter Log.
    On the Firewall log I see this, when I set the filter for entries of the respective Windows machine as can be seen in the upper corner.  
    I assume, these external IPs, the host tries to connect, are the microsoft update servers.
    But I got no idea, how to allow access, as I don't know their URLs and a reverse lookup only tells, these are Microsoft servers.

    Here the firewall log

Children