WSUS migration from 2012R2 to 2016
- install updates
- copy wsus folder previous server.
- switch off firewall on source wsus server or open port 7000(tcp , udp).
- get parameters source wsus:
- database location: [sql server].
- database name (if changed default): (hklm\software\microsoft\update service\server\setup{sql database name}
- iis settings: wsus pool user (network service)
- smtp server pass:
- code sign certificate:
- group membership: (localhost)\wsus administrator, (localhost)\wsus reporters
- store: d:\wsus example
- on new server install sql management studio, , microsoft report viewer 2012 runtime
- rename database susdb (if database name customized).
- for wsus database add permission (susdb->security->users->add) user [domain name]\(new machine name)$ default schema [dbo]
- on new server in server manager add role wsus role services: wsus service; sql server connectivity.
- content: store locally. specify path wsus folder updates previous server (d:\wsus example).
- specify db instance (sql database host)
- after complete reboot new server.
- stop previous server.
- on new server add local groups wsus administrators , wsus reporters user administration rights (domain\your username or admins group)
- start wsus console , click run.
- when complete run powershell:
$updateserver = get-wsusserver
$config = $updateserver.getconfiguration()
$config.serverid = [system.guid]::newguid()
$config.save()
when changed guid run next
%programfiles%\update services\tools\wsusutil.exe postinstall sql_instance_name=[sql server name] content_dir=[wsus content dir d:\wsus]
- next if need change susdb name:
- in iis stop wsus administration site. stop wsus service
- on new server use regedit edit database name \hklm\software\microsoft\update service\server\setup{sql database name} (susdb_spb)
- change in mssql susdb name.
- start wsus service wsus administration web site.
- set setting child wsus servers
- at child wsus parameters-update source-enter new server name , port. on child servers
- set group policy new wsus server. fast sync new server use command wuauclt.exe /resetauthorization /detectnow
for start reporting:
wuauclt.exe /resetauthorization /detectnow
and
wuauclt.exe /reportnow
- check workability success synchronization server, success reports computers.
on clients check logs %windir%\windowsupdate.log
Windows Server > WSUS
Comments
Post a Comment