Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

WSUS not pushing updates to server 2022 and server 2019


  • Please log in to reply
12 replies to this topic

#1 rranger

rranger

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:36 AM

Posted 28 February 2024 - 04:15 PM

Updates show up in WSUS, I can approve them and all of my 2022 & 2019 servers are reporting to WSUS (via: tnc wsusservername -port 8530) but the updates never push to them after I approve them.

 

I ran server cleanup wizard, did the WUAUCLT commands, and everything else, but they still don't show up.

 

Have an idea what's wrong?

 



BC AdBot (Login to Remove)

 


#2 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:36 AM

Posted 28 February 2024 - 04:18 PM

Is that port open in the firewall?

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#3 rranger

rranger
  • Topic Starter

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:36 AM

Posted 28 February 2024 - 04:19 PM

Yes it is and the servers are in the WSUS console.


Edited by rranger, 28 February 2024 - 04:21 PM.


#4 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:36 AM

Posted 28 February 2024 - 04:32 PM

Can the machines reach the sus?

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#5 rranger

rranger
  • Topic Starter

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:36 AM

Posted 28 February 2024 - 04:36 PM

Can the machines reach the sus?

Yes they can - they're communicating with the WSUS server. All other machines that aren't server 2022 or 2019 are reporting into the same WSUS server and do receive updates. 



#6 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:36 AM

Posted 28 February 2024 - 04:46 PM

Compare the GPO of the workstations to the servers and see what's different. Also group memberships

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#7 rranger

rranger
  • Topic Starter

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:36 AM

Posted 28 February 2024 - 05:51 PM

I don't manage the workstations at my company, just the servers. There are no differences in the registry settings either between the 2022 & 2019 servers and out 2016 servers. 

 

This is a tough one. 

 

We do use an azure an automation account with log analytics workspaces, but we are NOT azure domain joined. I just use the deployment schedules for starting the install and reboots for the updates - WSUS is used to approve the updates. I was maybe thinking that the deployment schedules in Azure were possibly removing the updates somehow and just rebooting the servers (because the servers do reboot) but I don't think that's possible. I never bothered to look at if the approved updates showed up on my servers to begin with either (for this month, Feb 2024) because this has never been a problem until now.. Thanks.

 

The only other thing I can think of is that for our Jan patching, I was told to remove group policy as updating from azure would handle everything but that wasn't true - updating from azure works without group policy ONLY if you're azure domain joined and none of our servers are so I set group policy back to what it was.

 

Inheritance is also blocked on our WIN2022 OU but that's not big deal as we simply link the WSUS policy separately to it - our 2019 servers aren't in that OU either so that helps in determining that nothing got messed up with the inheritance being blocked (we have inheritance blocked due to event viewer being disabled if it's not).



#8 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:36 AM

Posted 28 February 2024 - 06:07 PM

Any major changes to Azure or other parts of the infrastructure?

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#9 rranger

rranger
  • Topic Starter

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:36 AM

Posted 28 February 2024 - 06:14 PM

Not at all. What's even crazier is that when I look at the report in WSUS for one of the feb. cumulative updates, it says the status is "installed" for all the 2022 servers. Something is very strange here. 



#10 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:36 AM

Posted 28 February 2024 - 06:31 PM

Does it show the IP or host of the server in the logs that said installed?

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#11 rranger

rranger
  • Topic Starter

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:36 AM

Posted 28 February 2024 - 06:54 PM

Both, it's literally just the status report you run by right clicking on a machine.



#12 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:36 AM

Posted 28 February 2024 - 07:01 PM

And everything matches?

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#13 rranger

rranger
  • Topic Starter

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:36 AM

Posted 28 February 2024 - 07:03 PM

Yes






1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users