Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > WSUS Firewall Config Question

Reply
Thread Tools Display Modes

WSUS Firewall Config Question

 
 
DirkDiggler
Guest
Posts: n/a

 
      10-05-2005
Does anyone know what ports must be opened up for client computers to
download updates from a WSUS server?

My WSUS server is behind a firewall and I only want to open up this server
at a minimum level to the clients.
 
Reply With Quote
 
 
 
 
Ian
Guest
Posts: n/a

 
      10-05-2005
DirkDiggler wrote:
> Does anyone know what ports must be opened up for client computers to
> download updates from a WSUS server?
>
> My WSUS server is behind a firewall and I only want to open up this server
> at a minimum level to the clients.


Would presume it would be the same port that you configure in group
policy when you specify the update location - The default is 8530.

Ian
 
Reply With Quote
 
DirkDiggler
Guest
Posts: n/a

 
      10-05-2005
I don't recall configuring any ports in group policy. I recall configuration
the name of the server, but not ports.

"Ian" wrote:

> DirkDiggler wrote:
> > Does anyone know what ports must be opened up for client computers to
> > download updates from a WSUS server?
> >
> > My WSUS server is behind a firewall and I only want to open up this server
> > at a minimum level to the clients.

>
> Would presume it would be the same port that you configure in group
> policy when you specify the update location - The default is 8530.
>
> Ian
>

 
Reply With Quote
 
Ian
Guest
Posts: n/a

 
      10-05-2005
DirkDiggler wrote:
> I don't recall configuring any ports in group policy. I recall configuration
> the name of the server, but not ports.
>
> "Ian" wrote:
>
>
>>DirkDiggler wrote:
>>
>>>Does anyone know what ports must be opened up for client computers to
>>>download updates from a WSUS server?
>>>
>>>My WSUS server is behind a firewall and I only want to open up this server
>>>at a minimum level to the clients.

>>
>>Would presume it would be the same port that you configure in group
>>policy when you specify the update location - The default is 8530.
>>
>>Ian
>>

Have you configured Group Policy to configure the workstations to use
WSUS yet?

What URL do you use to access the admin site - the Group Policy and
firewall should be set to use the same port as specified after the ":"
in the url.

If no port is specified then it's port 80.

Ian
 
Reply With Quote
 
Arek Iskra [MVP]
Guest
Posts: n/a

 
      10-06-2005
"Ian" <> wrote in message
news:%...
> DirkDiggler wrote:
>> Does anyone know what ports must be opened up for client computers to
>> download updates from a WSUS server?
>>
>> My WSUS server is behind a firewall and I only want to open up this
>> server at a minimum level to the clients.

>
> Would presume it would be the same port that you configure in group policy
> when you specify the update location - The default is 8530.
>
> Ian



Port 8530 is used only if WSUS is not the first website running on that
server (e.g. if WSUS was installed on existing web server).

--
Arek Iskra
MVP for Windows Server - Software Distribution


 
Reply With Quote
 
DirkDiggler
Guest
Posts: n/a

 
      10-06-2005
I tried opening port 80 from the clients to the WSUS server and it didn't
work. For testing purposes I opened up IP/Any to the WSUS server and the
clients immediately began reporting to the update server.

I don't want to leave the firewall open to IP/Any, so does anyone know
exactly which ports are required to allow the clients to receive updates from
the WSUS server?

"Arek Iskra [MVP]" wrote:

> "Ian" <> wrote in message
> news:%...
> > DirkDiggler wrote:
> >> Does anyone know what ports must be opened up for client computers to
> >> download updates from a WSUS server?
> >>
> >> My WSUS server is behind a firewall and I only want to open up this
> >> server at a minimum level to the clients.

> >
> > Would presume it would be the same port that you configure in group policy
> > when you specify the update location - The default is 8530.
> >
> > Ian

>
>
> Port 8530 is used only if WSUS is not the first website running on that
> server (e.g. if WSUS was installed on existing web server).
>
> --
> Arek Iskra
> MVP for Windows Server - Software Distribution
>
>
>

 
Reply With Quote
 
Ian
Guest
Posts: n/a

 
      10-06-2005
DirkDiggler wrote:
> I tried opening port 80 from the clients to the WSUS server and it didn't
> work. For testing purposes I opened up IP/Any to the WSUS server and the
> clients immediately began reporting to the update server.
>
> I don't want to leave the firewall open to IP/Any, so does anyone know
> exactly which ports are required to allow the clients to receive updates from
> the WSUS server?
>
> "Arek Iskra [MVP]" wrote:
>
>
>>"Ian" <> wrote in message
>>news:%.. .
>>
>>>DirkDiggler wrote:
>>>
>>>>Does anyone know what ports must be opened up for client computers to
>>>>download updates from a WSUS server?
>>>>
>>>>My WSUS server is behind a firewall and I only want to open up this
>>>>server at a minimum level to the clients.
>>>
>>>Would presume it would be the same port that you configure in group policy
>>>when you specify the update location - The default is 8530.
>>>
>>>Ian

>>
>>
>>Port 8530 is used only if WSUS is not the first website running on that
>>server (e.g. if WSUS was installed on existing web server).
>>
>>--
>>Arek Iskra
>>MVP for Windows Server - Software Distribution
>>
>>
>>

Look at IIS for your WSUS website - Go to Properties and you will see
what port the site is running on.

Ian
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall Question Terry Windows 64 Bit 3 08-12-2005 08:13 PM
Firewall question Dave Mc Windows Server 5 08-06-2005 02:51 AM
Question about WSUS totomaster Windows Server 2 07-05-2005 05:45 PM
Windows 2003 Firewall Broke Puggy Windows Server 0 05-14-2005 02:42 AM
Opening port 135 Aaron Windows Server 6 03-18-2005 10:58 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59