hy everybody
we have the following problem with the windows update service
we have our hosts behind the firewall and try to make the fw as much secure
as possible. because of that issue we also tried to allow the hosts just to
windowsupdate.microsoft.com with port 80. of course, that doesnīt work. now
we decided to allow everything to the whole microsoft-subnet. but the
problem is that microsoft has the most of itīs downloads on completly
different servers. like 200.61.45.133 or 195.176.255.143 and so on.
in my opinion itīs impossible to enable all this sites because i think they
are really dynamic. is there a way to point the updates to just one or two
servers so it is possible to enable such rules on the fw?
SUS is no alternative for it
thanks for all tips
kind regards
Hans