First of all, sorry for my bad english.
We are trying to download Automatic Updates (not Windows update web) from
many Windows XP SP2 workstations but downloads fails with Error 0x800703eb.
The procedure to check wich updates are needed works, only fails when it is
supposed to start the download (windowsupdate.log).
Our setup is an Isa server 2000 with anonymous rules to microsoft.com and
windowsupdate.com sites and HTTP-HTTPS protocols. We want to use ONLY
Web-Proxy for clients because FWC Client IGNORES svchost.exe (needed for
automatic updates) and SecureNAT works but is not an option for security
reasons.
Clients are setup with automatic proxy discovery or manual proxy with
bitsadmin.exe and proxycfg.exe, but "Automatic Updates" ignores proxy server
if the computer has configured an internal DNS Server that resolves external
addresses (like au.download.windowsupdate.com). If the client computer gets
the ip address of an external AU server it tries to download directly
bypassing proxy server, but it fails with 0x800703eb error because client
computer is not SecureNAT client.
If computer is configured with MANUAL proxy and WITHOUT any DNS Server IT
WORKS!!!!! but this is not an option because DNS Server is obviously needed!
This is a big issue for us and many of our customers AND NO, WSUS is not a
viable options for many small companies.
AU Client should be WELL tested behind a proxy server and it does, but the
procedure to determine wich type of connection to AU servers fails (proxy or
direct).
Someone can report this issue to microsoft to fix it?.
|