WSUS - Good, Free
Hiya;
There is plenty to complain about when discussing Microsoft. However, in my experience working in a medium-sized enterprise of approximately 1250 nodes, I found both SUS and WSUS to be effective and cheap solutions. Once things were up and running on SUS (a while back now…), everything hummed right along and behaved exactly as expected for us. We even chained servers off of a master server to prevent excessive bandwidth use of our Internet lines.
Since then, I have done two additional migrations from SUS to WSUS. I have found that the easiest way to do this is a clean install of WSUS on a machine that is running SQL Server already. Unfortunately, and for some crazy reason, MS doesn’t allow the SQL server to be remote (i.e. not on the same machine as the WSUS server) which irks me considering the multitude of other vendors that work this way by design… whatevah.
A rundown of the things I like most about WSUS follows:
- Decent real-time reporting to tell you which machines have been updated – Very handy when you have “those few” people who don’t reboot their machines, etc.
- Native grouping ability to have different deployment and schedules based on membership to a specific group. While this can work with AD groups, I suggest using the builtin WSUS grouping capability. For me, it is more flexible and simple.
- Patch inheritence is all figured out by design. No more manually figuring out what patch supercedes what older patch, etc. This function is fairly elegant but could probably use some more automation (whatdya want for nothin)
- Office and some Server applications are not patchable via WSUS. One caveat here is that Office XP requires the original installation files available when applying service packs using this (or any) method. But, in general, this is a much improved capability over SUS
The Microsoft WSUS Technical Documentation site has a suprisingly good array of information for helping implementers get through the install, configuration, and operation.
Additionally, the WSUS forums site allows admins to commiserate and share solutions.
_____________________________________________________________KevFrey
. . . . . .. . . . . .



