Overview
This guide covers the configuration of WSUS Replica Servers, including setup steps for both replica and primary WSUS servers.
It ensures proper synchronization between upstream and downstream WSUS servers in your environment.
| Note: Pre-Requisite - make sure the required ports are open between Primary and replica WSUS server |
| After configuring the WSUS replica server, credentials must be assigned to the replica in JetPatch. See the "JetPatch Credential Assignment" section at the bottom of this article. |
Steps in WSUS Replica
Once the WSUS Replica server setup is complete, please follow the instructions below to set up a WSUS replica:
- Open the Windows Server Update Services from Server Manager -> Tools.
- The first window will explain the requirements that must be met to proceed. Click "Next" to continue.
- Leave the option as is or uncheck it, then click Next
- Select the option "Synchronize from another Windows Server Update Services."
- Enter the FQDN of the Upstream Server
- Depending on your requirements, check "This is a replica of the Upstream." Click Next
- Click on "Start Connecting."
- Select the language for the Windows updates. If you only use Windows in English, choose English. Otherwise, select the appropriate languages based on your requirements. And click Next
- Schedule the synchronization. Note that the synchronization will be between this WSUS server and the WSUS server you selected in the previous steps.
- Check the "Begin initial synchronization" option and click "Next" if you wish to start immediately after completing the configuration.
- Click on the Finish button
Steps in Primary WSUS
- After completing the configuration, log in to the WSUS Upstream Server.
- Expand the WSUS section and click on Downstream Servers.
- Ensure that the Downstream Server is listed there.
JetPatch Credential Assignment (Required)
After completing the WSUS replica configuration, you must assign credentials to the replica server in JetPatch before it can be used for patching. This is a separate step from connector deployment and is required even when the connector is already installed and connected.
Steps:
- Go to Servers in the JetPatch UI
- Find and select the WSUS replica server
- Click Server Actions β Assign Account
- Select the administrative account that has access to the WSUS replica
- Click Save
Verify: Go to Servers β Discovery Sources, find the WSUS discovery source, and confirm connection_status = OK. If credentials are missing the status will show an error or the replica will appear disconnected.
Note: Each replica server requires its own credential assignment. A credential assigned to the primary WSUS server does not carry over to replicas. Missing credentials on a replica will cause No access credentials errors in the logs and WSUS sync failures on endpoints managed by that replica, even though the connector is connected.
Comments
0 comments
Please sign in to leave a comment.