WSUS migration from 2012R2 to 2016


  1.        install updates
  2.        copy wsus folder previous server.
  3.        switch off firewall on source wsus server or open port 7000(tcp , udp).
  4.        get parameters source wsus:
    1.        database location: [sql server].
    2.        database name (if changed default): (hklm\software\microsoft\update service\server\setup{sql database name} 
    3.        iis settings: wsus pool user (network service)
    4.        smtp server pass: 
    5.        code sign certificate: 
    6.         group membership: (localhost)\wsus administrator, (localhost)\wsus reporters
    7.        store: d:\wsus example
  5.        on new server install sql management studio, , microsoft report viewer 2012 runtime
  6.        rename database susdb (if database name customized).
  7.        for wsus database add permission (susdb->security->users->add) user [domain name]\(new machine name)$ default schema [dbo]
  8.    on new server in server manager add role wsus role services: wsus service; sql server connectivity.
  9.    content: store locally. specify path wsus folder updates previous server (d:\wsus example).
  10.    specify db instance (sql database host)
  11.    after complete reboot new server.
  12.    stop previous server.
  13.    on new server add local groups wsus administrators , wsus reporters user administration rights (domain\your username or admins group)
  14.    start wsus console , click run.
  15.    when complete run powershell:

$updateserver = get-wsusserver

$config = $updateserver.getconfiguration()

$config.serverid = [system.guid]::newguid()

$config.save()

 

when changed guid run next

%programfiles%\update services\tools\wsusutil.exe postinstall sql_instance_name=[sql server name] content_dir=[wsus content dir d:\wsus]

  1.    next if need change susdb name:
    1.        in iis stop wsus administration site. stop wsus service
    2.        on new server use regedit edit database name \hklm\software\microsoft\update service\server\setup{sql database name} (susdb_spb)
    3.        change in mssql susdb name.
    4.        start wsus service wsus administration web site.

  2.    set setting child wsus servers
    1.        at child wsus parameters-update source-enter new server name , port. on child servers
  3.    set group policy new wsus server. fast sync new server use command wuauclt.exe /resetauthorization /detectnow

for start reporting:

 wuauclt.exe /resetauthorization /detectnow

and

wuauclt.exe /reportnow

  1.    check workability success synchronization server, success reports computers.

on clients check logs %windir%\windowsupdate.log




Windows Server  >  WSUS



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...