WSUS server on Windows 2003

  
Everyone knows that if the Windows system goes to the Microsoft server to do the patch update, it is really —— a word —— super slow, two words —— very slow, three words —— slow It’s terrible! ! !
The WSUS server is set up to facilitate the faster and more timely loading of system-related patches on computers in the LAN, greatly reducing the proliferation of viruses and Trojans in the LAN.
The following describes the specific method of setting up WSUS server on Windows 2003:
First, the server software environment (required):
* Internet Information Services (IIS) 5.0 or above
*Microsoft. NET Framework 1.1_SP1 or above
*BITS (Background Intelligent Transfer Service) 2.0
Second, the server hardware environment:
The client's WSUS server at 500 or less should not be lower than 750MHz, the memory is not Below 512MB, the hard disk update file storage space is not less than 6.0GB, the system space is not less than 1.0GB, and the disk file format must be NTFS format.
Third, the installation:
After ensuring that the software and hardware environment is up to standard, the installation is started. In fact, the installation is very simple, run the WSUS.exe installation file, and the next step is over.
Please note the following:
1, in the specified "local storage update", be sure to specify the partition space is greater than 6.0GB, otherwise it can not be installed;
2, if the system does not install SQL database, WSUS The installation file will automatically install a desktop version of SQL for you;
3. When you select the "Website Selection" option page, select “Use the existing IIS default website (recommended)” The default installation is fine.
Fourth, configure WSUS options:
After the installation is complete, it is best to restart the computer, so that the system files and related services are initialized.
Open the "Microsoft Windows Server Update Services" under "Administrative Tools" and select the "Options" option in the upper right corner of the page to open the Options page.
1. In the “Sync Options”, you can set the Windows products that your client wants to update, and you can set “Update Category” in the category to exclude unnecessary patch files; if you use a proxy server and Microsoft's update server connection can also be set here; you can also specify update source and update files and language restrictions.
2, in the "automatic approval options" page can be used to detect the synchronization of the update patch, and the update patch can be reviewed and approved before the corresponding installation.
3. Assign the computer to the group in “Computer Options".
Save the settings after the configuration of each option is completed, and start the synchronization update. The synchronization process time is variable, depending on the type of product you need to synchronize and the type of patch you want to update.
Five, client settings
The client update program defaults to Microsoft's update server, which needs to be changed to the WSUS just built.
Run“gpedit.msc”Open the Group Policy Editor and select “Computer Configuration”——>“Administrative Template”——>“Windows Components”—&mdash ;>“Windows Update”.
Only the main two are set here:
1. Open the “Configure Automatic Updates” property and change the status to “Allowed”, and you can set the update mode and update in the Properties dialog box. Plan (see figure) ——> OK.

2, then open the & ldquo; designated Intranet Microsoft update service location & rdquo; attribute box to enable it and & ldquo; Setting Intranet statistics server & rdquo;; to detect update settings Intranet Update Service & rdquo; and & ldquo under fill The newly created update server address, such as “http://192.168.0.252”——> is determined (see figure). After

completed, refresh the group policy, and then enter in operation & ldquo; wuauclt.exe /detectnow & rdquo; to run automatic update, then update the client will point to the LAN 192.168.0.252 this update the server.
Sixth, at this point, the WSUS server is fully deployed. In this way, the bandwidth consumption of the external network is greatly reduced, and the proliferation of viruses and Trojans on the intranet is greatly reduced. why not? Try it now.

Copyright © Windows knowledge All Rights Reserved