Jump to content


  • 0
makarovs

SCCM 2012 with 3 WSUS Servers

Question

Hello,

 

We have 3 offices, each one has it's own WSUS server, on Windows 2012. These WSUS Servers are downstream servers for the main WSUSBRANCH1 Server

 

 

We have GPO configured, which will push update server address for each branch respectively to save bandwidth and use local server, which is synced with master. For branch 1 it will be http://wsusbranch1.domain.ltd, for branch 2 http://wsusbranch2.domain.ltd, etc

 

 

And we have SCCM 2012, which has wsusbranch1, wsusbranch2, and wsusbranch3 added as Software Update Points. I thought SCCM will understand which WSUS Server is assigned to the branch, but it seems like it tries to overwrite WSUS address to wsusbranch1 in every office

 

 

Log:
Enabling WUA Managed server policy to use server: HTTP://WSUSBRANCH1.DOMAIN.LTD:8530 WUAHandler 5/23/2013 6:01:38 PM 6268 (0x187C)
Group policy settings were overwritten by a higher authority (Domain Controller) to: Server HTTP://WSUSBRANCH2.DOMAIN.LTD:8530 and Policy ENABLED WUAHandler 5/23/2013 6:01:55 PM 6268 (0x187C)
Is there anything i can do with this? Maybe Boundaries? (Now it's configured as one global, including all branches)
Regards,

 

Share this post


Link to post
Share on other sites

2 answers to this question

Recommended Posts

  • 0

The challenge here is twofold.

 

The first is attempting to assign a Software Update Point to a Configuration Manager client using Group Policy. It will work, if you're assigning the right SUP; but generally speaking the SUP is assigned to a client based on the SITE assignment of the client by the Site Server.

 

The second is misunderstanding the role of additional SUPs in a single site. Starting with Service Pack 1, ConfigMgr 2012 now supports multiple SUPs within a single site, but the additional SUPs are not operational SUPs, they are fallback SUPs in the event the primary SUP fails.

 

All clients in a site are assigned to the primary SUP. If the client is unable to communicate with the primary SUP, it will fallback to one of the secondary SUPs. The secondary SUPs are defined by the Site Server as well.

Share this post


Link to post
Share on other sites

  • 0

Hello, I have added all three WSUS servers to SCCM as Update servers, and configured boundaries. Yes, I've read that additional SUPs maybe used only as failover. But as i can see, after few days of errors all branches somehow picked up correct WSUS for their site and Software Update went fine

 

Log:

 

Error:
Group policy settings were overwritten by a higher authority (Domain Controller) to: Server http://wsus1branch.domain.ltd:8530 and Policy ENABLED WUAHandler 5/27/2013 10:03:40 AM 4828 (0x12DC)
Failed to Add Update Source for WUAgent of type (2) and id ({A14814B3-9259-4E67-9D55-1FE3C0E8DE77}). Error = 0x87d00692. WUAHandler 5/27/2013 10:03:40 AM 4828 (0x12DC)
Its a WSUS Update Source type ({A14814B3-9259-4E67-9D55-1FE3C0E8DE77}), adding it. WUAHandler 5/27/2013 1:14:51 PM 9312 (0x2460)
Success:
Enabling WUA Managed server policy to use server: http://wsus1branch.domain.ltd:8530 WUAHandler 5/27/2013 1:14:51 PM 9312 (0x2460)
Waiting for 2 mins for Group Policy to notify of WUA policy change... WUAHandler 5/27/2013 1:14:51 PM 9312 (0x2460)
Waiting for 30 secs for policy to take effect on WU Agent. WUAHandler 5/27/2013 1:14:59 PM 9312 (0x2460)
Added Update Source ({A14814B3-9259-4E67-9D55-1FE3C0E8DE77}) of content type: 2 WUAHandler 5/27/2013 1:15:29 PM 9312 (0x2460)
Scan results will include superseded updates only when they are superseded by service packs and definition updates. WUAHandler 5/27/2013 1:15:29 PM 9312 (0x2460)
Search Criteria is (DeploymentAction=* AND Type='Software') OR (DeploymentAction=* AND Type='Driver') WUAHandler 5/27/2013 1:15:29 PM 9312 (0x2460)
Async searching of updates using WUAgent started. WUAHandler 5/27/2013 1:15:29 PM 9312 (0x2460)
Async searching completed. WUAHandler 5/27/2013 1:16:06 PM 8724 (0x2214)
Successfully completed scan. WUAHandler 5/27/2013 1:16:08 PM 3016 (0x0BC8)

 

Magic!

 

Thank you,

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Answer this question...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.