At the company I work for, we do not allow DNS server resolution for machine
in the DMZ (protected by Firewall). So to allow Windows Update to function in
this setup, I had been able to create a local host file
(C:\winnt\system32\drivers\etc\hosts) that would resolve various windows
update host names and allow the feature to work. I found recently that this
workaround is no longer working on XP machines (possible 2000 as well) and I
am not sure if it is because Windows update is now V6 and things changed or
because MS implemented some steps to protect against viruses and no longer
allows a local hosts files to be used for windows update name resolution.
As mentioned above, I do not have access to DNS server and the DNS Client
Service is turned off. Originally, I thought that the Hosts files was not
being used at all for host name resolution, but after some troubleshooting I
discovered that just certain entries in the hosts file are being ignored. As
an example I could ping to resolve genuine.microsoft.com and
update.microsoft.com but whenever I ping update.microsoft.com or
windowsupdate.microsoft.com the response is always:
Ping request could not find host update.microsoft.com. Please check the name
and try again.
This response indicates that host name resolution is ignoring the local
Hosts entries for update.microsoft.com and windowsupdate.microsoft.com. Even
if I change the IP address to localhost (127.0.0.1) I get the same response.
I suspect that MS implemented some code to prevent a virus from redirecting
windowsupdate but could not find any reference to this in Google.
Does anyone on this list have a suggestion for me? In the meantime, it is
easy enought for me to apply the patches using a CD or thumdrive, but it
would be much more convenient if I could find a solution.
regards,
Brent
P.S. I have attached a sample of what my hosts file looks like for reference:
207.46.157.30 update.microsoft.com
207.46.157.30 update.microsoft.com.nsatc.net
206.24.192.221 download.windowsupdate.com
206.24.192.221 download.windowsupdate.com.c.footprint.net
131.107.115.28 crl.microsoft.com
131.107.115.28 cr1.microsoft.com
207.46.232.190 genuine.microsoft.com
207.46.19.30
www.microsoft.com
207.46.198.60
www.microsoft.com
207.46.18.94
www.windowsupdate.com
207.46.18.94 windowsupdate.microsoft.com
207.46.18.94 windowsupdate.microsoft.nsatc.net
207.46.134.126 v4.windowsupdate.microsoft.com
207.46.134.126 v4windowsupdate.microsoft.nsatc.net