Patching ISA servers with WSUS
While playing with a lab, I noticed the the ISA servers weren’t get the Patching goodness from the WSUS server.
A quick check of the logs and I saw the some protocols being denied from the WSUS machine to the ISA’s themselves. Hmm. Too lazy to do the leg work myself, a quick bit of searching and found a nice walk through by Steve Moffat on what and how to allow updates:
http://isaserver.bm/isa_articles/wsus.html
Don’t forget, if you set WSUS up on a non standard port, then create a User defined protocol in ISA for it and apply it to the rule as well.
e.g. WSUS running on TCP port 8530, create a new ISA protocol for TCP 8530 outbound add that to the rule and ditch the HTTP (TCP 80) protocol

Leave a Reply