Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > Windows Update Access Through Corporate Firewall

Reply
Thread Tools Display Modes

Windows Update Access Through Corporate Firewall

 
 
John
Guest
Posts: n/a

 
      01-10-2006
Hello,
Forgive me if this has been answered before or should be posted in another
forum.
I have about 20 Windows 2000/2003 servers and while manually running Windows
Update on them they always fail with the error 0x80072EE2. We've gone through
every single possible "fix" article we've been able to find without any luck.
We regulate both ingress/egress traffic so while testing we've found this to
be the culprit. With normal firewall rules in place (Secure Linux OS
Checkpoint NG Firewall) we continue to get this error. However, if we allow
all outgoing traffic to the outside world from any specific server then that
specific server is able to run Windows Updae without any issue at all. What
we would like to do is not jeopardize our security by allowing everything out
through the firewall just so we can get successful Windows Updates.

With the above said, my question is - Does anyone know the Windows Update
server(s) IP Ranges to allow outbound through a firewall to successfully
query the Windows Update servers? Allowing everything outbound from our
servers seems to be the only fix so naturally we think that by allowing all
80/443 traffic to the Windows Update IP range should work.

If you need further info please let me know. Your thoughts and/or
suggestions are appreciated.

 
Reply With Quote
 
 
 
 
Technokid
Guest
Posts: n/a

 
      01-10-2006
We had a similar problem while using content filtering. We did a nslookup on
windowsupdate.com and it sent back other domains that we listed as "allowed"
domains. This resolved our problem

"John" wrote:

> Hello,
> Forgive me if this has been answered before or should be posted in another
> forum.
> I have about 20 Windows 2000/2003 servers and while manually running Windows
> Update on them they always fail with the error 0x80072EE2. We've gone through
> every single possible "fix" article we've been able to find without any luck.
> We regulate both ingress/egress traffic so while testing we've found this to
> be the culprit. With normal firewall rules in place (Secure Linux OS
> Checkpoint NG Firewall) we continue to get this error. However, if we allow
> all outgoing traffic to the outside world from any specific server then that
> specific server is able to run Windows Updae without any issue at all. What
> we would like to do is not jeopardize our security by allowing everything out
> through the firewall just so we can get successful Windows Updates.
>
> With the above said, my question is - Does anyone know the Windows Update
> server(s) IP Ranges to allow outbound through a firewall to successfully
> query the Windows Update servers? Allowing everything outbound from our
> servers seems to be the only fix so naturally we think that by allowing all
> 80/443 traffic to the Windows Update IP range should work.
>
> If you need further info please let me know. Your thoughts and/or
> suggestions are appreciated.
>

 
Reply With Quote
 
John
Guest
Posts: n/a

 
      01-11-2006
Thanks for the reply. This is what I've started doing. My problem is we can't
define safe domains by host alone on our firewall, only IP. With MS bouncing
WU off multiple subnets and domains it makes it that much more difficult to
map them all. We'll see what happens.

Thanks again.

"Technokid" wrote:

> We had a similar problem while using content filtering. We did a nslookup on
> windowsupdate.com and it sent back other domains that we listed as "allowed"
> domains. This resolved our problem
>
> "John" wrote:
>
> > Hello,
> > Forgive me if this has been answered before or should be posted in another
> > forum.
> > I have about 20 Windows 2000/2003 servers and while manually running Windows
> > Update on them they always fail with the error 0x80072EE2. We've gone through
> > every single possible "fix" article we've been able to find without any luck.
> > We regulate both ingress/egress traffic so while testing we've found this to
> > be the culprit. With normal firewall rules in place (Secure Linux OS
> > Checkpoint NG Firewall) we continue to get this error. However, if we allow
> > all outgoing traffic to the outside world from any specific server then that
> > specific server is able to run Windows Updae without any issue at all. What
> > we would like to do is not jeopardize our security by allowing everything out
> > through the firewall just so we can get successful Windows Updates.
> >
> > With the above said, my question is - Does anyone know the Windows Update
> > server(s) IP Ranges to allow outbound through a firewall to successfully
> > query the Windows Update servers? Allowing everything outbound from our
> > servers seems to be the only fix so naturally we think that by allowing all
> > 80/443 traffic to the Windows Update IP range should work.
> >
> > If you need further info please let me know. Your thoughts and/or
> > suggestions are appreciated.
> >

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
windows corporate update site R.D.Geran Windows Update 2 01-02-2005 06:13 PM
Windows Update Corporate Dominique Windows Update 1 12-26-2004 07:12 AM
Windows update server ip addresses access thru our firewall technicaldiva@earthlink.net Windows Update 3 05-04-2004 09:57 PM
Firewall Access to Windows update changed? andy Windows Update 1 01-30-2004 10:45 PM
Corporate Methods for Windows Update Daniel King Windows Update 2 08-26-2003 04:45 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59