Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Firewall doesn't let windows updates

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 General] >> General >> Firewall doesn't let windows updates Page: [1]
Login
Message << Older Topic   Newer Topic >>
Firewall doesn't let windows updates - 11.Aug.2005 7:17:00 AM   
nnmmss

 

Posts: 85
Joined: 30.Nov.2004
Status: offline
i want to update the computer for windows updates, but i get this error from microsoft
0x80072EE2 which means
A misconfigured Proxy/Firewall can cause this problem. Double-check the Proxy/Firewall settings.
Add the following urls to the exception list within your Firewall/Proxy:
http://*.update.microsoft.com
https://*.update.microsoft.com
http://download.windowsupdate.com
For help configuring Proxy/Firewall refer to documentation or contact the manufacturer

is there anyone who can tell me whereand how i can do this?
thanks

[ August 11, 2005, 07:19 AM: Message edited by: nnmmss ]
Post #: 1
RE: Firewall doesn't let windows updates - 11.Aug.2005 1:27:00 PM   
LLigetfa

 

Posts: 2184
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
You need to configure an anonymous rule to the specific sites.

Then at the client, go into proxycfg and make sure it is pointing to your ISA server.

(in reply to nnmmss)
Post #: 2
RE: Firewall doesn't let windows updates - 13.Aug.2005 5:04:00 AM   
nnmmss

 

Posts: 85
Joined: 30.Nov.2004
Status: offline
sure that i have set the borwser to ISA server, if i didn't i couldn't surf the web.
any other help?
thanks

(in reply to nnmmss)
Post #: 3
RE: Firewall doesn't let windows updates - 13.Aug.2005 8:15:00 AM   
LLigetfa

 

Posts: 2184
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
The command PROXYCFG has nothing to do with your browser and everything to do with the WinHTTP API. Did you check to see it is set like I suggested?

Do you have an anonymous rule to the needed sites and is it above the others?

(in reply to nnmmss)
Post #: 4
RE: Firewall doesn't let windows updates - 24.Feb.2006 1:07:15 AM   
zwat

 

Posts: 4
Joined: 24.Feb.2006
Status: offline
i get same error message.

i only want the isa server 2004 to update itself not any clients. and i don't use wsus. i have made a access rule with protocols HTTP
and HTTPS from localhost to url set *.microsoft.com and *.windowsupdate.com for both HTTP and HTTPS for all users.

what else do i need to set up? i only get to run microsoft updates if i opern all protocols from local host to external.

< Message edited by zwat -- 24.Feb.2006 1:09:36 AM >

(in reply to LLigetfa)
Post #: 5
RE: Firewall doesn't let windows updates - 24.Feb.2006 1:46:22 AM   
LLigetfa

 

Posts: 2184
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
I am sure you need more than just those two URLs in your destination set.  Look in the Windows Update.log to see what other URLs are needed.

_____________________________

The School of Hard Knocks is a mean teacher. She gives the exam before the lesson.

(in reply to zwat)
Post #: 6
RE: Firewall doesn't let windows updates - 24.Feb.2006 9:23:28 AM   
zwat

 

Posts: 4
Joined: 24.Feb.2006
Status: offline
2006-02-24	03:00:10	 924	710	AU	Forced install timer expired for scheduled install
2006-02-24	04:13:02	 924	3c0	Report	Uploading 1 events using cached cookie, reporting URL = http://stats.update.microsoft.com/ReportingWebService/ReportingWebService.asmx
2006-02-24	04:13:07	 924	3c0	Report	Reporter successfully uploaded 1 events.
2006-02-24	05:58:36	 924	710	AU	#############
2006-02-24	05:58:36	 924	710	AU	## START ##  AU: Search for updates
2006-02-24	05:58:36	 924	710	AU	#########
2006-02-24	05:58:36	 924	710	AU	<<## SUBMITTED ## AU: Search for updates [CallId = {F7C1CB77-991F-4999-AC0C-B788F62EFC94}]
2006-02-24	05:58:36	 924	3c0	Agent	*************
2006-02-24	05:58:36	 924	3c0	Agent	** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
2006-02-24	05:58:36	 924	3c0	Agent	*********
2006-02-24	05:58:46	 924	3c0	Setup	***********  Setup: Checking whether self-update is required  ***********
2006-02-24	05:58:46	 924	3c0	Setup	  * Inf file: C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wusetup.inf
2006-02-24	05:58:46	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\cdm.dll: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:46	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\iuengine.dll: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:46	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\wuapi.dll: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:46	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\wuauclt.exe: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:46	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\wuauclt1.exe: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:46	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\wuaucpl.cpl: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:46	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\wuaueng.dll: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:46	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\wuaueng1.dll: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:46	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\wucltui.dll: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:46	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\wups.dll: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:46	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\wups2.dll: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:46	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\wuweb.dll: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:46	 924	3c0	Setup	  * IsUpdateRequired = No
2006-02-24	05:58:47	 924	3c0	Setup	Found non-managed non-WU Service registered with AU
2006-02-24	05:58:49	 924	3c0	Setup	***********  Setup: Checking whether self-update is required  ***********
2006-02-24	05:58:49	 924	3c0	Setup	  * Inf file: C:\WINDOWS\SoftwareDistribution\SelfUpdate\Registered\musetup.inf
2006-02-24	05:58:49	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\mucltui.dll: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:49	 924	3c0	Setup	Update NOT required for C:\WINDOWS\system32\muweb.dll: target version = 5.8.0.2469, required version = 5.8.0.2469
2006-02-24	05:58:49	 924	3c0	Setup	  * IsUpdateRequired = No
2006-02-24	05:58:51	 924	3c0	PT	+++++++++++  PT: Synchronizing server updates  +++++++++++
2006-02-24	05:58:51	 924	3c0	PT	  + ServiceId = {7971F918-A847-4430-9279-4A52D1EFE18D}, Server URL = https://update.microsoft.com/v6/ClientWebService/client.asmx
2006-02-24	05:59:55	 924	3c0	Misc	WARNING: Send failed with hr = 80072ee2.
2006-02-24	05:59:55	 924	3c0	Misc	WARNING: SendRequest failed with hr = 80072ee2. Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes used : <>
2006-02-24	05:59:55	 924	3c0	PT	  + Last proxy send request failed with hr = 0x80072EE2, HTTP status code = 0
2006-02-24	05:59:55	 924	3c0	PT	  + Caller provided credentials = No
2006-02-24	05:59:55	 924	3c0	PT	  + Impersonate flags = 0
2006-02-24	05:59:55	 924	3c0	PT	  + Possible authorization schemes used = 
2006-02-24	05:59:55	 924	3c0	PT	WARNING: SyncUpdates failure, error = 0x80072EE2, soap client error = 5, soap error code = 0, HTTP status code = 200
2006-02-24	05:59:55	 924	3c0	PT	WARNING: Sync of Updates: 0x80072ee2
2006-02-24	05:59:55	 924	3c0	Agent	  * WARNING: Failed to synchronize, error = 0x80072EE2
2006-02-24	05:59:55	 924	3c0	Agent	  * WARNING: Exit code = 0x80072EE2
2006-02-24	05:59:55	 924	3c0	Agent	*********
2006-02-24	05:59:55	 924	3c0	Agent	**  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
2006-02-24	05:59:55	 924	3c0	Agent	*************
2006-02-24	05:59:55	 924	3c0	Agent	WARNING: WU client failed Searching for update with error 0x80072ee2
2006-02-24	05:59:55	 924	3c0	AU	>>##  RESUMED  ## AU: Search for updates [CallId = {F7C1CB77-991F-4999-AC0C-B788F62EFC94}]
2006-02-24	05:59:55	 924	3c0	AU	  # WARNING: Search callback failed, result = 0x80072EE2
2006-02-24	05:59:55	 924	3c0	AU	#########
2006-02-24	05:59:55	 924	3c0	AU	##  END  ##  AU: Search for updates [CallId = {F7C1CB77-991F-4999-AC0C-B788F62EFC94}]
2006-02-24	05:59:55	 924	3c0	AU	#############
2006-02-24	05:59:55	 924	3c0	AU	AU setting next detection timeout to 2006-02-24 09:59:55
2006-02-24	06:00:00	 924	3c0	Report	REPORT EVENT: {227966E5-D303-441D-926F-F18453946EC9}	2006-02-24 05:59:55+0100	1	148	101	{00000000-0000-0000-0000-000000000000}	0	80072ee2	AutomaticUpdates	Failure	Software Synchronization	Error: Agent failed detecting with reason: 0x80072ee2
2006-02-24	07:44:44	 924	3c0	Report	Uploading 1 events using cached cookie, reporting URL = http://stats.update.microsoft.com/ReportingWebService/ReportingWebService.asmx
2006-02-24	07:44:50	 924	3c0	Report	Reporter successfully uploaded 1 events.


thats the log for last try on automatic update. can u decrypt it?

(in reply to LLigetfa)
Post #: 7
RE: Firewall doesn't let windows updates - 24.Feb.2006 7:24:14 PM   
LLigetfa

 

Posts: 2184
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
quote:

Server URL = https://update.microsoft.com/v6/ClientWebService/client.asmx

One would need to correlate that failure with the ISA monitor log to see why it is denied.  Since you have not provided the exact details of your URL set, I cannot hazard a guess.

Personally, I would not open up the anonymous rule with as broad a wildcard as *.microsoft.com so I have more granular URLs (ten in total).

_____________________________

The School of Hard Knocks is a mean teacher. She gives the exam before the lesson.

(in reply to zwat)
Post #: 8
RE: Firewall doesn't let windows updates - 25.Feb.2006 10:23:51 AM   
zwat

 

Posts: 4
Joined: 24.Feb.2006
Status: offline
my url set is:
http:\\*.microsoft.com
http:\\*.windowsupdate.com
https:\\*.microsoft.com
https:\\*.windowsupdate.com

why don't u just paste ur workin rule? :D

(in reply to LLigetfa)
Post #: 9
RE: Firewall doesn't let windows updates - 25.Feb.2006 3:09:37 PM   
LLigetfa

 

Posts: 2184
Joined: 10.Aug.2004
From: fort frances.on.ca
Status: offline
I think you should be using whacks // and not hacks \\.
quote:

why don't u just paste ur workin rule?

Because where I am now, I have only a 26.4 kbps connection and too intolerant of the slow speed to remote to my ISA.  Also, I have a few overlaps from testing and never got around to cleaning it up (lazy).  They might not all be needed for Windows Update, but this is one of my general anonymous allow whitelists.

http://*.download.windowsupdate.com
http://*.update.microsoft.com
http://crl.microsoft.com
http://download.microsoft.com
http://download.windowsupdate.com
http://update.microsoft.com
http://windowsupdate.microsoft.com
http://www.microsoft.com/isapi/*
http://www.windowsupdate.microsoft.com
https://*.windowsupdate.microsoft.com



_____________________________

The School of Hard Knocks is a mean teacher. She gives the exam before the lesson.

(in reply to zwat)
Post #: 10

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 General] >> General >> Firewall doesn't let windows updates Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts