locked
most wsus client machines show not yet reported as last status report on wsus console RRS feed

  • Question

  • Only one machine shows last status report and the rest of them show "not yet reported".

    I ran Solarwinds wsus diagnotic tool on two different machines and the same result shows as follows:

    Content  error: forbdden

    Incorrect proxy client configuration - use settings tab to test proxy configuration settings; may also be caused by misconfigurated SSL implementation or access rights on WSUS server.

    I did check settings tab to test proxy configuration settings and it shows no proxy setting existing.

    Can someone advise where I can look into the issue?

    By the way, there is no proxy settings on any of workstations and testing the connection between client and server is successful too.

    Thank you very much!


    • Edited by L14507 Tuesday, February 2, 2016 9:51 PM edit
    Tuesday, February 2, 2016 9:48 PM

Answers

  • Hi L14507,

    Have you configured SSL on WSUS server?

    Also check if the client could resolve the WSUS server name to correct IP address.

    Reset windows update component on one client to test if it could work:

    Reset windows update component:

    https://support.microsoft.com/en-us/kb/971058

    If it still doesn't work, in Windows update console, click "Check for update", then check windows update log, location: C:\Windows\WindowsUpdate.log

    Best Regards,

    Anne


    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com.

    Friday, February 19, 2016 9:17 AM

All replies

  • Hi L14507,

    What is the version of the WSUS server, and what are WSUS clients?

    1. Sometimes, WSUS clients will not report to WSUS server immediately, you may wait around 22 hours, check if it will report later. Also use command wuauclt/detectnow on client to check the result.

    2. Check the GPO apply result on clients, verify if the clients has applied the correct GPO.

    3. Check firewall settings, enable the WSUS port is open both on WSUS client and WSUS server.

    4. If the above doesn't work, we may check if run "server cleanup wizard" and reindex WSUS database could help.

    reindex wsus database:
    https://gallery.technet.microsoft.com/scriptcenter/6f8cde49-5c52-4abd-9820-f1d270ddea61

    Best Regards,

    Anne


    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com.

    Wednesday, February 3, 2016 8:57 AM
  • Thank you, Anne He!

    I have done most steps you listed except step 4. firewall on wsus server is off and i turn off firewall on client machine over night. This morning when I checked the status on wsus console, it still shows "not report yet".

    The Solarwinds wsus diagnotic tool said something wrong with proxy:

    Content  error: forbdden

    Incorrect proxy client configuration - use settings tab to test proxy configuration settings; may also be caused by misconfigurated SSL implementation or access rights on WSUS server.

    But none of our client machines have proxy setting. I typed "netsh httpwin show proxy" and got the feedback saying no proxy setting. Is there somewhere else I should take a look?

    Please advise! Thank you very much again!

    Wednesday, February 3, 2016 2:10 PM
  • Here is the report from wsus client:

    # Solarwinds® Diagnostic Tool for the WSUS Agent
    # 2/3/2016
    Machine state
      User rights:                                       User has administrator rights 
      Update service status:                             Running 
      Background Intelligent Transfer service status:    Running 
      OS Version:                                        Windows 8.1 Pro 
      Windows update agent version:                      7.9.9600.18066 (WU Agent is OK)
    Windows Update Agent configuration settings
      Automatic Update:                                  Enabled 
      Options:                                           Scheduled (Every day at  12:00 PM)
      Use WSUS Server:                                   Enabled 
      Windows Update Server:                             http://wsusserver:80 
      Windows Update Status Server:                      http://wsusserver:80 
      WSUS URLs are identical:                           Identical 
      WSUS URL is valid:                                 Valid URL 
    WSUS Server Connectivity
      clientwebservice/client.asmx:                      OK 
      simpleauthwebservice/simpleauth.asmx:              OK 
      content:                                           Error: Forbidden (Incorrect proxy client configuration - use settings tab to test proxy configuration settings; may also be caused by misconfigured SSL implementation or access rights on WSUS server)
      selfupdate/iuident.cab:                            OK 
      iuident.cab:                                       OK 

    Any clue where the problem could be that none of the client machines report the status on wsus console. The last status always stays "not yet reported" for all the client machines.

    Wednesday, February 3, 2016 5:54 PM
  • Hi L14507,

    Have you configured SSL on WSUS server?

    Also check if the client could resolve the WSUS server name to correct IP address.

    Reset windows update component on one client to test if it could work:

    Reset windows update component:

    https://support.microsoft.com/en-us/kb/971058

    If it still doesn't work, in Windows update console, click "Check for update", then check windows update log, location: C:\Windows\WindowsUpdate.log

    Best Regards,

    Anne


    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com.

    Friday, February 19, 2016 9:17 AM