Windows Vista Forums

ISA blocks client Automatic Updates
  1. #1


    Dave Solly Guest

    ISA blocks client Automatic Updates

    I have just become aware that Automatic Updates (whether Windows or
    Microsoft) are no longer working on XP clients on our SBS2003 Premium
    network. Monitoring ISA 2004 shows that it initially allows HTTP access
    under the builtin "Microsoft Update Sites" rule, but then denies an HTTPS
    connection to another site (65.55.184.16 on one instance, but this seems to
    vary). I can't obtain a reverse DNS lookup on these sites (not sure why ?),
    so that means this URL-based rule (*.windowsupdate.com etc) wouldn't be
    expected to work. I guess this is a recent change to Windows Update ? I
    can't resolve it by creating an IP-based rule instead, since I don't know all
    the IP addresses MS might use here. SO, how do I get Automatic Updates going
    again ? This is very frustrating as I'm having to update all clients
    manually !
    Any ideas appreciated.
    --
    Dave Solly



      My System SpecsSystem Spec

  2. #2


    SteveB Guest

    Re: ISA blocks client Automatic Updates

    Have you checked out this kb? http://support.microsoft.com/kb/885819

    You might also consider installing WSUS so you can centrally manage the MS
    updates for the XP clients.

    "Dave Solly" <DaveS@newsgroup> wrote in message
    news:2AF1BC9F-91B0-48BE-8CBA-139525AFD701@newsgroup

    >I have just become aware that Automatic Updates (whether Windows or
    > Microsoft) are no longer working on XP clients on our SBS2003 Premium
    > network. Monitoring ISA 2004 shows that it initially allows HTTP access
    > under the builtin "Microsoft Update Sites" rule, but then denies an HTTPS
    > connection to another site (65.55.184.16 on one instance, but this seems
    > to
    > vary). I can't obtain a reverse DNS lookup on these sites (not sure why
    > ?),
    > so that means this URL-based rule (*.windowsupdate.com etc) wouldn't be
    > expected to work. I guess this is a recent change to Windows Update ? I
    > can't resolve it by creating an IP-based rule instead, since I don't know
    > all
    > the IP addresses MS might use here. SO, how do I get Automatic Updates
    > going
    > again ? This is very frustrating as I'm having to update all clients
    > manually !
    > Any ideas appreciated.
    > --
    > Dave Solly


      My System SpecsSystem Spec

  3. #3


    Dave Solly Guest

    Re: ISA blocks client Automatic Updates

    Thanks for the suggestion Steve.

    I've already added *.download.microsoft.com and
    *.windowsupdate.microsoft.com to the existing *.windowsupdate.com in
    theMicrosoft Update Sites rule and this made no difference. IE6 is at SP3 so
    should include the 871260 fix.
    WSUS is an option, though this seems rather overkill for a dozen clients.
    It would be good to understand what this HTTPS access is for - can't see why
    SSL is needed for windows update.
    --
    Dave Solly


    "SteveB" wrote:

    > Have you checked out this kb? http://support.microsoft.com/kb/885819
    >
    > You might also consider installing WSUS so you can centrally manage the MS
    > updates for the XP clients.
    >
    > "Dave Solly" <DaveS@newsgroup> wrote in message
    > news:2AF1BC9F-91B0-48BE-8CBA-139525AFD701@newsgroup

    > >I have just become aware that Automatic Updates (whether Windows or
    > > Microsoft) are no longer working on XP clients on our SBS2003 Premium
    > > network. Monitoring ISA 2004 shows that it initially allows HTTP access
    > > under the builtin "Microsoft Update Sites" rule, but then denies an HTTPS
    > > connection to another site (65.55.184.16 on one instance, but this seems
    > > to
    > > vary). I can't obtain a reverse DNS lookup on these sites (not sure why
    > > ?),
    > > so that means this URL-based rule (*.windowsupdate.com etc) wouldn't be
    > > expected to work. I guess this is a recent change to Windows Update ? I
    > > can't resolve it by creating an IP-based rule instead, since I don't know
    > > all
    > > the IP addresses MS might use here. SO, how do I get Automatic Updates
    > > going
    > > again ? This is very frustrating as I'm having to update all clients
    > > manually !
    > > Any ideas appreciated.
    > > --
    > > Dave Solly
    >
    >
    > .
    >

      My System SpecsSystem Spec

  4. #4


    SteveB Guest

    Re: ISA blocks client Automatic Updates

    I find WSUS useful even with my smaller clients. I'd definitely use it with
    a dozen workstations involved.

    "Dave Solly" <DaveS@newsgroup> wrote in message
    news:FD06CFEB-03C2-49A1-A62A-2C2E7FFCBDA4@newsgroup

    > Thanks for the suggestion Steve.
    >
    > I've already added *.download.microsoft.com and
    > *.windowsupdate.microsoft.com to the existing *.windowsupdate.com in
    > theMicrosoft Update Sites rule and this made no difference. IE6 is at SP3
    > so
    > should include the 871260 fix.
    > WSUS is an option, though this seems rather overkill for a dozen clients.
    > It would be good to understand what this HTTPS access is for - can't see
    > why
    > SSL is needed for windows update.
    > --
    > Dave Solly
    >
    >
    > "SteveB" wrote:
    >

    >> Have you checked out this kb? http://support.microsoft.com/kb/885819
    >>
    >> You might also consider installing WSUS so you can centrally manage the
    >> MS
    >> updates for the XP clients.
    >>
    >> "Dave Solly" <DaveS@newsgroup> wrote in message
    >> news:2AF1BC9F-91B0-48BE-8CBA-139525AFD701@newsgroup

    >> >I have just become aware that Automatic Updates (whether Windows or
    >> > Microsoft) are no longer working on XP clients on our SBS2003 Premium
    >> > network. Monitoring ISA 2004 shows that it initially allows HTTP
    >> > access
    >> > under the builtin "Microsoft Update Sites" rule, but then denies an
    >> > HTTPS
    >> > connection to another site (65.55.184.16 on one instance, but this
    >> > seems
    >> > to
    >> > vary). I can't obtain a reverse DNS lookup on these sites (not sure
    >> > why
    >> > ?),
    >> > so that means this URL-based rule (*.windowsupdate.com etc) wouldn't be
    >> > expected to work. I guess this is a recent change to Windows Update ?
    >> > I
    >> > can't resolve it by creating an IP-based rule instead, since I don't
    >> > know
    >> > all
    >> > the IP addresses MS might use here. SO, how do I get Automatic Updates
    >> > going
    >> > again ? This is very frustrating as I'm having to update all clients
    >> > manually !
    >> > Any ideas appreciated.
    >> > --
    >> > Dave Solly
    >>
    >>
    >> .
    >>


      My System SpecsSystem Spec

ISA blocks client Automatic Updates problems?

Similar Threads
Thread Thread Starter Forum Replies Last Post
No automatic updates EragonX Software 2 22 Sep 2008
HELP! Can't change Automatic Updates or check for updates! VKGT Vista performance & maintenance 1 05 Jul 2008
automatic updates coby Vista General 4 31 Mar 2008
Automatic Updates velosity Vista General 3 13 May 2007
Another Reason not to use Automatic Updates cfstansell Vista General 11 16 Apr 2007