Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Update Services > Question on WSUS design

Reply
Thread Tools Display Modes

Question on WSUS design

 
 
Daniel V
Guest
Posts: n/a

 
      07-31-2009
Im have been working on a WSUS 3.0 SP1 design for some time with the purpose
to support laptops on the road as well as internal hosts. Currently the
setup we are testing is to have two WSUS servers. One in the DMZ to host
laptops on the outside, this will use a SSL with certs to secure. The
internal server will not use SSL. The internal server is the master with the
DMZ being a replica.

Since we dont have computers go straight to containers, but move manually
this adds a bit of extra work moving systems on both WSUS servers. Nothing
big to do but adds a little work and requires space for patches and
synchronization between the two servers.

My question is would using a High availability design sharing one database
and DFS share be a better solution? In my design it would not be exactly for
clustering the WSUS servers for high availability as it would be more for a
using a single database and DFS share to reduce or eliminate replications and
rollups while allowing laptops to connect from the outside and internal host
connecting to the inside. Would this work or is there something I am
overlooking in this design?
 
Reply With Quote
 
 
 
 
Lawrence Garvin [MVP]
Guest
Posts: n/a

 
      07-31-2009
"Daniel V" <> wrote in message
news:917607E4-E3F4-4B82-BE2B-...

> My question is would using a High availability design sharing one database
> and DFS share be a better solution?


Not really. Consider your primary objective (or what should be your primary
objective) for using a separate server for mobile systems. Normally this
motivation is because downloading content across VPN connections is
expensive, not to mention somewhat unreliable because of the transient
nature of VPN-connected machines. By configuring a separate server for
mobile clients, without a content store, these mobile clients can obtain
*content* directly from microsoft.com when any Internet connection is
active, and only require the VPN connection to obtain *approvals* from the
central authority.

Second, I doubt an NLB environment would far well across a firewall. Among
other things the DMZ server would have to access the database inside the
firewall, and I doubt you really want to open SQL Server ports from the DMZ
to the Internal LAN. In addition, the DFS share would require that resource
to also be open from the DMZ to the Internal LAN, and you'd be moving mobile
computer content traffic.. not only across the VPN, but also through the
DMZ/Internal firewall interface.



--
Lawrence Garvin, M.S., MCITP:EA, MCDBA
Principal/CTO, Onsite Technology Solutions, Houston, Texas
Microsoft MVP - Software Distribution (2005-2009)

MS WSUS Website: http://www.microsoft.com/wsus
My MVP Profile: http://mvp.support.microsoft.com/pro...awrence.Garvin

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
WSUS design nntp.aioe.org Update Services 1 07-07-2007 12:11 PM
WSUS Design PariP Update Services 5 05-21-2007 08:59 AM
WSUS 2.0 design questions SLongxyzzy Update Services 4 02-02-2007 07:25 PM
WSUS installation/design question Björn Axell Update Services 1 04-03-2006 10:04 AM
WSUS and SBS 2003 Design Question Jason J. Thomas Update Services 1 02-12-2006 12:41 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59