Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > WSUS - Default Sync Connection with Microsoft Update?

Reply
Thread Tools Display Modes

WSUS - Default Sync Connection with Microsoft Update?

 
 
Sara Windsor
Guest
Posts: n/a

 
      07-24-2008
In a simple scenario with a single WSUS 3 server configured to synchronize
with Microsoft Update, does the WSUS server connect to synchronize & update
via standard HTTP? or HTTPS? (no proxies configured)

We had a period over the weekend (about 8-10am Saturday morning) when our
Internet connection slowed considerably. The ISP's network expert did some
packet sniffing & other analysis (not sure what) and said that a single
connection from the server was hogging all the bandwidth - see below (from a
netstat printout):

TCP <servername>:2226 cds179.sjc9.llnw.net:http ESTABLISHED

Additionally, the expert says that WSUS was the culprit, and that this
connection was due to some hung-up download on WSUS's part. He says that
WSUS's connection was to Limelight (although the IP that the FQDN resolves to
comes back as registered to Microsoft), and says that when talking to a
support engineer from Limelight, they said that Limelight does sometimes host
Microsoft downloads.

I manage the WSUS service, and WSUS logged no errors at all - in fact, on
the day in question it synchronized at 12:32am & completed less than a minute
later with no new updates to download. I'm convinced that WSUS had nothing to
do with it.

When I run a manual sync, netstat shows:

TCP <servername>:4756 64.4.21.91:https ESTABLISHED 184
[WsusService.exe]

If it's true that WSUS uses SSL to sync with Microsoft, then it's very clear
that the "problem" connection over the weekend had nothing to do with WSUS!
Can anyone confirm the default WSUS connection behavior when syncing with
Microsoft Update? I've been hunting for clear documentation, but haven't
found it yet.

TIA.
 
Reply With Quote
 
 
 
 
MowGreen [MVP]
Guest
Posts: n/a

 
      07-24-2008
Forwarded to the WSUS NG for OP's convenience:

Web-based reader <for the kidz>
http://www.microsoft.com/communities...pdate_services

NNTP reader <for adults>
news://msnews.microsoft.com/microsof...pdate_services


Sara Windsor wrote:
> In a simple scenario with a single WSUS 3 server configured to synchronize
> with Microsoft Update, does the WSUS server connect to synchronize & update
> via standard HTTP? or HTTPS? (no proxies configured)
>
> We had a period over the weekend (about 8-10am Saturday morning) when our
> Internet connection slowed considerably. The ISP's network expert did some
> packet sniffing & other analysis (not sure what) and said that a single
> connection from the server was hogging all the bandwidth - see below (from a
> netstat printout):
>
> TCP <servername>:2226 cds179.sjc9.llnw.net:http ESTABLISHED
>
> Additionally, the expert says that WSUS was the culprit, and that this
> connection was due to some hung-up download on WSUS's part. He says that
> WSUS's connection was to Limelight (although the IP that the FQDN resolves to
> comes back as registered to Microsoft), and says that when talking to a
> support engineer from Limelight, they said that Limelight does sometimes host
> Microsoft downloads.
>
> I manage the WSUS service, and WSUS logged no errors at all - in fact, on
> the day in question it synchronized at 12:32am & completed less than a minute
> later with no new updates to download. I'm convinced that WSUS had nothing to
> do with it.
>
> When I run a manual sync, netstat shows:
>
> TCP <servername>:4756 64.4.21.91:https ESTABLISHED 184
> [WsusService.exe]
>
> If it's true that WSUS uses SSL to sync with Microsoft, then it's very clear
> that the "problem" connection over the weekend had nothing to do with WSUS!
> Can anyone confirm the default WSUS connection behavior when syncing with
> Microsoft Update? I've been hunting for clear documentation, but haven't
> found it yet.
>
> TIA.



MowGreen [MVP 2003-2008]
===============
*-343-* FDNY
Never Forgotten
===============
 
Reply With Quote
 
DaveMills
Guest
Posts: n/a

 
      07-25-2008
The metadata sync uses HTTPS. The download of the updates themselves uses HTTP
(they are digitally signed so why use SLL/TLS)

On Thu, 24 Jul 2008 11:19:13 -0700, "MowGreen [MVP]" <>
wrote:

>Forwarded to the WSUS NG for OP's convenience:
>
>Web-based reader <for the kidz>
>http://www.microsoft.com/communities...pdate_services
>
>NNTP reader <for adults>
>news://msnews.microsoft.com/microsof...pdate_services
>
>
>Sara Windsor wrote:
>> In a simple scenario with a single WSUS 3 server configured to synchronize
>> with Microsoft Update, does the WSUS server connect to synchronize & update
>> via standard HTTP? or HTTPS? (no proxies configured)
>>
>> We had a period over the weekend (about 8-10am Saturday morning) when our
>> Internet connection slowed considerably. The ISP's network expert did some
>> packet sniffing & other analysis (not sure what) and said that a single
>> connection from the server was hogging all the bandwidth - see below (from a
>> netstat printout):
>>
>> TCP <servername>:2226 cds179.sjc9.llnw.net:http ESTABLISHED
>>
>> Additionally, the expert says that WSUS was the culprit, and that this
>> connection was due to some hung-up download on WSUS's part. He says that
>> WSUS's connection was to Limelight (although the IP that the FQDN resolves to
>> comes back as registered to Microsoft), and says that when talking to a
>> support engineer from Limelight, they said that Limelight does sometimes host
>> Microsoft downloads.
>>
>> I manage the WSUS service, and WSUS logged no errors at all - in fact, on
>> the day in question it synchronized at 12:32am & completed less than a minute
>> later with no new updates to download. I'm convinced that WSUS had nothing to
>> do with it.
>>
>> When I run a manual sync, netstat shows:
>>
>> TCP <servername>:4756 64.4.21.91:https ESTABLISHED 184
>> [WsusService.exe]
>>
>> If it's true that WSUS uses SSL to sync with Microsoft, then it's very clear
>> that the "problem" connection over the weekend had nothing to do with WSUS!
>> Can anyone confirm the default WSUS connection behavior when syncing with
>> Microsoft Update? I've been hunting for clear documentation, but haven't
>> found it yet.
>>
>> TIA.

>
>
>MowGreen [MVP 2003-2008]
>===============
> *-343-* FDNY
>Never Forgotten
>===============

--
Dave Mills
There are 10 type of people, those that understand binary and those that don't.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
WSUS 2.0 SP1 master WSUS on W2K3 SP1 -- will it sync with WSUS 2.0 Bob Windows Update 1 11-21-2007 05:59 AM
Going from Wsus client pc to using microsoft update? vyaw2003@gmail.com Windows Update 0 09-23-2007 10:56 PM
WSUS Sync Error 386 Justin Windows Update 20 12-22-2006 08:49 PM
Does WSUS server have a web interface like update.microsoft.com? Paul Cyr Windows Update 1 11-17-2005 03:42 PM
Applying patches offline - Microsoft Update? WSUS? SMS? HFNetChk? cjg.groups@gmail.com Windows Update 3 10-18-2005 07:37 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59