This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows Server in DMZ dosn't fetch Windows Updates

Dear community,

at present I'm looking for a solution for the following scenario:
I've got a Windows Server sitting in the DMZ.
For security reasons, direct I-net access is not allowed.

To allow Windows Update Downloads, I followed this KB article https://support.sophos.com/support/s/article/KB-000036981?language=en_US
by creating the needed exception.
But even when created and set to active, this doesn't seem to do the job.

When I start the Update process on the server, it displays some found Updates but doesn't download them
Instead it stays forever in the state "download pending".

Any help to resolve this is appreciated.

Best regards
ranX



This thread was automatically locked due to age.
Parents Reply
  • Well, the funny thing is:
    I have a firewall rule and I have a NAT rule.

    When I don't filter for denied traffic, I see most of the outbound traffic from the DMZ going out and in as expected.
    If this were not the case, I wouldn't even see a refresh of the available updates on the Windows host.

    But for some strange reason, the routing of the packets seen on the screenshot goes wrong.
    As you see, they have no "out" Interface entry.
    I assume, this is, why they do not get masked and no rule is applied.
    As long as they are missing this attribute simply no rule will match.

Children