What do the release notes for the Express Migration Tool mean when they refer to "etalon"? If you don't have a pix, you win... 0 LVL 11 Overall: Level 11 Message Author Comment by:phileoca ID: 142688622005-06-21 no pix for me, i use sonicwalls for all of Generated Sat, 18 Mar 2017 06:54:15 GMT by s_za2 (squid/3.5.23) I'll add those ip addresses to my firewall and see if that will work. 0 LVL 11 Overall: Level 11 Message Author Comment by:phileoca ID: 142710982005-06-21 is needed too

https://social.technet.microsoft.com/Forums/windows/en-US/b596aa81-2775-496c-b159-dcfc5c5bf22d/windows-update-ip-addresses-range-and-subnet-mask-for-windows-server-2008?forum=winserversecurity

Can I use Shield Spell to protect me from other attacks than just physicals and magic missiles? It save back your bandwith and you no need to headache the security setting. This book contains many real life examples derived from the author's experience as a Linux system and network administrator, trainer and consultant.

Microsoft Customer Support Microsoft Community Forums Windows Client   Sign in United States (English) Brasil (Português)Česká republika (Čeština)Deutschland (Deutsch)España (Español)France (Français)Indonesia (Bahasa)Italia (Italiano)România (Română)Türkiye (Türkçe)Россия (Русский)ישראל (עברית)المملكة العربية السعودية (العربية)ไทย (ไทย)대한민국 (한국어)中华人民共和国 And you only have to allow the one machine to talk. 0 Message Expert Comment by:eah6122 ID: 257958322009-11-11 this is the range I used in my firewall: 64.4.x.x 64.158.x.x 65.55.x.x

server 2003 or 2008 running as a WSUS not only improves the client network security but also saves exponential amounts of bandwidth. I could also poison DNS by overriding TTLs, but yikes, that's a dark road full of monsters... –chris Jul 30 '10 at 13:40 I'm very interested in this as The only two sites I connected to are = 443 Oddly enough.... For Office update,

The system returned: (22) Invalid argument The remote host or network may be down.

If we going to enable WSUS, we also need to know what is the IP range and sub-net mask for windows update. Advanced Search Overclock.net›Forums›Software, Programming and Coding›Operating Systems›Windows›Windows Update IP Ranges Recent Reviews See All the Latest Reviews Nidec UltraFlo 120x120x38mm Reviewed by

If someone has spent more time locking this rule down any further please let me know if I missed anything. Keep in touch with Experts ExchangeTech news and trends delivered to your inbox every month Live Consultants Membership How it Works Gigs Live Careers Plans and Pricing For Business Become an All your windows client point to wsus server for update.

The firewall just sees to/from packets and doesn't necessarily know what url (if https) the request is going to, so the firewall doesn't have a direct way to see that this Because WSUS initiates all its network traffic, there is no need to configure Windows Firewall on the WSUS server. I configured windows firewall by doing the following.

So far, I've opened up this: (in my shorewall /etc/shorewall/rules) Code: # allow access to microsoft for windows updates HTTP/ACCEPT loc net: HTTPS/ACCEPT loc net: HTTP/ACCEPT loc net: HTTPS/ACCEPT loc net:

I thankfully no longer use Windoze, but I do sympathize Good luck! As far as I can tell, the windows update sites are hosted on a content distribution network that can potentially change IP addresses every 30 seconds. You are currently viewing LQ as a guest.

Thanks for reading If I do a nslookup one day I get one IP and when I try it the day after another.

They live behind a firewall and all outgoing communication is must be off. Filter by domain: http://technet.microsoft.com/en-us/library/cc708605%28v=ws.10%29.aspx http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/b596aa81-2775-496c-b159-dcfc5c5bf22d/ Thanks mate, I actually found those a little while after posting this thread :-)

Fix All Warnings And Errors: what is the history of this code quality tactic? Question has a verified solution.

Windows update uses %systemroot%\system32\svchost.exe. Changed windows firewall properties to Outbound/Inbound connections that do no match a rule are blocked. Chicken, meet egg. –chris Jul 30 '10 at 15:15 While I haven't tried this (see my comment Could you use a proxy with a whitelist only permitting *.windowsupdate.microsoft.com and *.windowsupdate.com? –gravyface Jul 30 '10 at 14:44 I must be missing something, but if Windows establishes its

Port 80 seems to be the superhighway for all kinds of attacks, and Windows 2000 isn't even patched anymore, so it makes sense to only open that door when you need Search this Thread 04-24-2008, 08:51 AM #1 drokmed Member Registered: Dec 2005 Location: St Petersburg, FL, USA Posts: 219 Rep: What firewall ip addresses do I open to allow

If your organization does not allow those ports and protocols open to all addresses, you can restrict access to only the following domains so that WSUS and Automatic Updates can communicate What I need is the IP addresses for the MS windows update site. <--- here's your points. :-) 0 Comment Question by:phileoca Reference: http://support.microsoft.com/kb/929851 and http://onlinehelp.microsoft.com/en-us/office365-enterprises/hh373144.aspx Windows Update requires TCP port 80, 443, and 49152-65535.

Can I turn off the alternate keyboards in Messages Scientific feasibility of reptilian overlords and humanoid slaves Why do my users 're'select the amount in the cart? vmarcus, wtf are object groups? And, in my situation, I don't have the ability to just mandate a specific configuration on the systems on the network. to x.x.255.255 and it got me further but not far enough.