locked
Client configured to report to WSUS server but log shows it only contact Microsoft Update sites RRS feed

  • Question

  • There is one strange Windows 7 machine on my test environment, I already configured it to report to my WSUS server but it just never report to WSUS server, instead it is checking updates against Microsoft update sites.

    I double-checked the settings in local security policy, it is correctly configured.

    I had done all the troubleshooting I can think of:

    1. verify wuauserv running, bits running

    2. Firewall not blocking 8530, telnet wsus at 8530 no problem

    3. Removed SoftwareDistribution folder, removed catroot2 folder, regsvr32 all related dlls

    4. Removed susclientid

    5. installed Windows Update Agent 7.6.

    The computer is in a domain, the WSUS server is in a workgroup. There are many other wsus clients on the network, some in domain, some in workgroup, none have this problem.

    There is no Internet connection for all the wsus clients.

    Windowsupdate.log:

    2016-01-12 09:07:13:579 1248 267c Misc WARNING: Send failed with hr = 80072ee7.
    2016-01-12 09:07:13:579 1248 267c Misc WARNING: SendRequest failed with hr = 80072ee7. Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes used : <>
    2016-01-12 09:07:13:579 1248 267c Misc WARNING: WinHttp: SendRequestUsingProxy failed for <http://fe2.update.microsoft.com/v11/2/windowsupdate/redir/v6-win7sp1-wuredir.cab>. error 0x8024402c
    2016-01-12 09:07:13:579 1248 267c Misc WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x8024402c
    2016-01-12 09:07:13:579 1248 267c Misc WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x8024402c
    2016-01-12 09:07:13:579 1248 267c Misc WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x8024402c
    2016-01-12 09:07:32:375 1248 267c Misc WARNING: Send failed with hr = 80072ee7.
    2016-01-12 09:07:32:375 1248 267c Misc WARNING: SendRequest failed with hr = 80072ee7. Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes used : <>
    2016-01-12 09:07:32:375 1248 267c Misc WARNING: WinHttp: SendRequestUsingProxy failed for <http://fe2.update.microsoft.com/v11/2/windowsupdate/redir/v6-win7sp1-wuredir.cab>. error 0x8024402c
    2016-01-12 09:07:32:375 1248 267c Misc WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x8024402c
    2016-01-12 09:07:32:375 1248 267c Misc WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x8024402c
    2016-01-12 09:07:32:375 1248 267c Misc WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x8024402c
    2016-01-12 09:07:46:657 1248 267c Misc WARNING: Send failed with hr = 80072ee7.
    2016-01-12 09:07:46:657 1248 267c Misc WARNING: SendRequest failed with hr = 80072ee7. Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes used : <>
    2016-01-12 09:07:46:657 1248 267c Misc WARNING: WinHttp: SendRequestUsingProxy failed for <http://fe2.update.microsoft.com/v11/2/windowsupdate/redir/v6-win7sp1-wuredir.cab>. error 0x8024402c
    2016-01-12 09:07:46:657 1248 267c Misc WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x8024402c
    2016-01-12 09:07:46:657 1248 267c Misc WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x8024402c
    2016-01-12 09:07:46:657 1248 267c Misc WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x8024402c
    2016-01-12 09:07:46:657 1248 267c Misc WARNING: DownloadFileInternal failed for http://fe2.update.microsoft.com/v11/2/windowsupdate/redir/v6-win7sp1-wuredir.cab: error 0x8024402c
    2016-01-12 09:07:46:657 1248 267c Agent WARNING: Failed to obtain the authorization cab URLs, hr=0x8024402c
    2016-01-12 09:07:46:657 1248 267c Agent   * WARNING: Online service registration/service ID resolution failed, hr=0x8024402C
    2016-01-12 09:07:46:657 1248 267c Agent   * WARNING: Exit code = 0x8024402C
    2016-01-12 09:07:46:657 1248 267c Agent *********
    2016-01-12 09:07:46:657 1248 267c Agent **  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2016-01-12 09:07:46:657 1248 267c Agent *************
    2016-01-12 09:07:46:657 1248 267c Agent WARNING: WU client failed Searching for update with error 0x8024402c
    2016-01-12 09:07:46:657 1248 2680 AU >>##  RESUMED  ## AU: Search for updates [CallId = {BFBE5994-AE57-4C91-9E2F-9C55EE9A1F72}]
    2016-01-12 09:07:46:657 1248 2680 AU   # WARNING: Search callback failed, result = 0x8024402C
    2016-01-12 09:07:46:657 1248 2680 AU   # WARNING: Failed to find updates with error code 8024402C
    2016-01-12 09:07:46:657 1248 2680 AU #########
    2016-01-12 09:07:46:657 1248 2680 AU ##  END  ##  AU: Search for updates [CallId = {BFBE5994-AE57-4C91-9E2F-9C55EE9A1F72}]
    2016-01-12 09:07:46:657 1248 2680 AU #############
    2016-01-12 09:07:46:657 1248 2680 AU Need to show Unable to Detect notification
    2016-01-12 09:07:46:657 1248 2680 AU Successfully wrote event for AU health state:1
    2016-01-12 09:07:46:657 1248 2680 AU AU setting next detection timeout to 2016-01-12 06:07:46
    2016-01-12 09:07:46:657 1248 2680 AU Setting AU scheduled install time to 2016-01-12 19:00:00
    2016-01-12 09:07:46:657 1248 2680 AU Successfully wrote event for AU health state:1
    2016-01-12 09:07:46:657 1248 2680 AU Successfully wrote event for AU health state:1
    2016-01-12 09:07:51:657 1248 267c Report CWERReporter finishing event handling. (00000000)
    2016-01-12 09:38:55:000 1248 2634 AU AU setting next sqm report timeout to 2016-01-13 01:38:55
    2016-01-12 09:43:36:000 1248 2634 AU AU was unable to detect updates for more than 48 hours
    2016-01-12 09:43:41:000 1248 2738 Report REPORT EVENT: {9600B6C8-179C-41F5-A0C8-0AE0C1BD220B} 2016-01-12 09:43:36:000+0800 1 149 102 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Failure Software Synchronization Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.
    2016-01-12 09:43:41:000 1248 2738 Report CWERReporter finishing event handling. (00000000)

    Any help is appreciated.


    Valuable skills are not learned, learned skills aren't valuable.

    Tuesday, January 12, 2016 5:26 AM

Answers

  • The new file does indicate 'null' for wsus server:

    <...>
    2016-01-12 17:02:40:909 1248 27d8 Agent ***********  Agent: Initializing global settings cache  ***********
    2016-01-12 17:02:40:909 1248 27d8 Agent   * WSUS server: <NULL>
    2016-01-12 17:02:40:909 1248 27d8 Agent   * WSUS status server: <NULL>
    2016-01-12 17:02:40:909 1248 27d8 Agent   * Target group: (Unassigned Computers)
    <....>

    Running wsus clientdiag it showed a failure at the end:

    UseWuServer value is missing..................................FAIL

    Ok, so, this client is not configured for WSUS at all.
    That would explain the attempts to default to WU/MU.

    Configure this client for your WSUS implementation, and try again :)


    Don [doesn't work for MSFT, and they're probably glad about that ;]

    • Proposed as answer by Steven_Lee0510 Tuesday, February 9, 2016 2:20 PM
    • Marked as answer by Steven_Lee0510 Wednesday, February 10, 2016 4:18 AM
    Tuesday, January 12, 2016 9:46 AM

All replies

  • the errors shown in this windowupdate.log all relate to could_not_resolve_hostname_via_dns, this agrees with your "no internet access" for the machine.
    So, for your scenario, these errors are not very surprising.

    But the issue is that this machine should be communicating with your WUS and not to WU/MU on the web?

    the logfile extract you showed us, does not include the critical data which is logged at service startup (i.e. the WUServer configuration).

    - stop the wuauserv service on this machine (net stop wuauserv)
    - wait a few seconds for the service to stop, then, rename the c:\windows\windowsupdate.log file to some other name
    - start the wuauserv (net start wuauserv)
    - examine the beginning of this fresh logfile, focus on the service startup lines in the log, e.g.:

    2009-11-04 12:18:46:890  152 c7c Misc ===========  Logging initialized (build: 7.4.7600.226, tz: +0100)  ===========
    2009-11-04 12:18:46:890  152 c7c Misc   = Process: C:\WINDOWS\System32\svchost.exe
    2009-11-04 12:18:46:890  152 c7c Misc   = Module: C:\WINDOWS\system32\wuaueng.dll
    2009-11-04 12:18:46:890  152 c7c Service *************
    2009-11-04 12:18:46:890  152 c7c Service ** START **  Service: Service startup
    2009-11-04 12:18:46:890  152 c7c Service *********
    2009-11-04 12:18:46:890  152 c7c Agent   * WU client version 7.4.7600.226
    2009-11-04 12:18:46:890  152 c7c Agent   * Base directory: C:\WINDOWS\SoftwareDistribution
    2009-11-04 12:18:46:890  152 c7c Agent   * Access type: No proxy
    2009-11-04 12:18:46:905  152 c7c Agent   * Network state: Connected
    2009-11-04 12:19:33:436  152 c7c Agent ***********  Agent: Initializing Windows Update Agent  ***********
    2009-11-04 12:19:33:452  152 c7c Agent ***********  Agent: Initializing global settings cache  ***********
    2009-11-04 12:19:33:452  152 c7c Agent   * WSUS server: http://AFDBWSUS1:8530
    2009-11-04 12:19:33:452  152 c7c Agent   * WSUS status server: http://AFDBWSUS1:8530
    2009-11-04 12:19:33:452  152 c7c Agent   * Target group: Patching Desktop Prod
    2009-11-04 12:19:33:452  152 c7c Agent   * Windows Update access disabled: No
    2009-11-04 12:19:33:468  152 c7c DnldMgr Download manager restoring 0 downloads
    2009-11-04 12:19:33:483  152 c7c AU ###########  AU: Initializing Automatic Updates  ###########
    2009-11-04 12:19:33:483  152 c7c AU AU setting next sqm report timeout to 2009-11-04 11:19:33
    2009-11-04 12:19:33:499  152 c7c AU   # WSUS server: http://AFDBWSUS1:8530
    2009-11-04 12:19:33:499  152 c7c AU   # Detection frequency: 22
    2009-11-04 12:19:33:499  152 c7c AU   # Target group: Patching Desktop Prod
    2009-11-04 12:19:33:499  152 c7c AU   # Approval type: Scheduled (Policy)
    2009-11-04 12:19:33:499  152 c7c AU   # Scheduled install day/time: Every day at 4:00
    2009-11-04 12:19:33:499  152 c7c AU   # Auto-install minor updates: No (Policy)
    2009-11-04 12:19:33:499  152 c7c AU   # Will interact with non-admins (Non-admins are elevated (Policy))
    2009-11-04 12:19:33:515  152 c7c AU Setting AU scheduled install time to 2009-11-05 03:00:00

    You may find this article helpful to understand the windowsupdate.log file:

    https://support.microsoft.com/en-us/kb/902093


    Don [doesn't work for MSFT, and they're probably glad about that ;]


    • Edited by DonPick Tuesday, January 12, 2016 6:26 AM
    Tuesday, January 12, 2016 6:25 AM
  • The new file does indicate 'null' for wsus server:

    2016-01-12 17:01:55:268 1248 27d8 Misc ===========  Logging initialized (build: 7.6.7600.320, tz: +0800)  ===========
    2016-01-12 17:01:55:268 1248 27d8 Misc   = Process: C:\Windows\system32\svchost.exe
    2016-01-12 17:01:55:268 1248 27d8 Misc   = Module: c:\windows\system32\wuaueng.dll
    2016-01-12 17:01:55:268 1248 27d8 Service *************
    2016-01-12 17:01:55:268 1248 27d8 Service ** START **  Service: Service startup
    2016-01-12 17:01:55:268 1248 27d8 Service *********
    2016-01-12 17:01:55:346 1248 27d8 Agent   * WU client version 7.6.7600.320
    2016-01-12 17:01:55:346 1248 27d8 Agent   * Base directory: C:\Windows\SoftwareDistribution
    2016-01-12 17:01:55:377 1248 27d8 Agent   * Access type: No proxy
    2016-01-12 17:01:55:393 1248 27d8 Agent   * Network state: Connected
    2016-01-12 17:02:40:831 1248 27d8 Report CWERReporter::Init succeeded
    2016-01-12 17:02:40:831 1248 27d8 Agent ***********  Agent: Initializing Windows Update Agent  ***********
    2016-01-12 17:02:40:909 1248 27d8 Agent   * Prerequisite roots succeeded.
    2016-01-12 17:02:40:909 1248 27d8 Agent ***********  Agent: Initializing global settings cache  ***********
    2016-01-12 17:02:40:909 1248 27d8 Agent   * WSUS server: <NULL>
    2016-01-12 17:02:40:909 1248 27d8 Agent   * WSUS status server: <NULL>
    2016-01-12 17:02:40:909 1248 27d8 Agent   * Target group: (Unassigned Computers)
    2016-01-12 17:02:40:909 1248 27d8 Agent   * Windows Update access disabled: No
    2016-01-12 17:02:40:924 1248 27d8 DnldMgr Download manager restoring 0 downloads
    2016-01-12 17:02:40:924 1248 27d8 AU ###########  AU: Initializing Automatic Updates  ###########
    2016-01-12 17:02:40:956 1248 27d8 AU   # Approval type: Scheduled (Policy)
    2016-01-12 17:02:40:956 1248 27d8 AU   # Scheduled install day/time: Every day at 3:00
    2016-01-12 17:02:40:956 1248 27d8 AU   # Auto-install minor updates: Yes (User preference)
    2016-01-12 17:02:40:956 1248 27d8 AU   # Will interact with non-admins (Non-admins are elevated (User preference))
    2016-01-12 17:02:40:956 1248 27d8 AU Setting AU scheduled install time to 2016-01-12 19:00:00
    2016-01-12 17:02:42:471 1248 27d8 Report ***********  Report: Initializing static reporting data  ***********
    2016-01-12 17:02:42:471 1248 27d8 Report   * OS Version = 6.1.7601.1.0.65792
    2016-01-12 17:02:42:471 1248 27d8 Report   * OS Product Type = 0x00000030
    2016-01-12 17:02:42:643 1248 27d8 Report   * Computer Brand = To Be Filled By O.E.M.
    2016-01-12 17:02:42:643 1248 27d8 Report   * Computer Model = To Be Filled By O.E.M.
    2016-01-12 17:02:42:659 1248 27d8 Report   * Bios Revision = 080015
    2016-01-12 17:02:42:659 1248 27d8 Report   * Bios Name = Default System BIOS
    2016-01-12 17:02:42:659 1248 27d8 Report   * Bios Release Date = 2011-06-14T00:00:00
    2016-01-12 17:02:42:659 1248 27d8 Report   * Locale ID = 1033
    2016-01-12 17:02:42:737 1248 27d8 AU Successfully wrote event for AU health state:1
    2016-01-12 17:02:42:737 1248 27d8 AU Initializing featured updates
    2016-01-12 17:02:42:737 1248 27d8 AU Found 0 cached featured updates
    2016-01-12 17:02:42:737 1248 27d8 AU Successfully wrote event for AU health state:1
    2016-01-12 17:02:42:768 1248 27d8 AU Successfully wrote event for AU health state:1
    2016-01-12 17:02:42:768 1248 27d8 AU AU finished delayed initialization
    2016-01-12 17:02:42:768 1248 27d8 AU #############
    2016-01-12 17:02:42:768 1248 27d8 AU ## START ##  AU: Search for updates
    2016-01-12 17:02:42:768 1248 27d8 AU #########
    2016-01-12 17:02:42:893 1248 27d8 AU <<## SUBMITTED ## AU: Search for updates [CallId = {D58D43A1-0293-4AB7-910B-FCF79D59431C}]
    2016-01-12 17:02:42:893 1248 181c Agent *************
    2016-01-12 17:02:42:893 1248 181c Agent ** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2016-01-12 17:02:42:893 1248 181c Agent *********
    2016-01-12 17:02:42:893 1248 181c Agent   * Online = No; Ignore download priority = No
    2016-01-12 17:02:42:893 1248 181c Agent   * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    2016-01-12 17:02:42:893 1248 181c Agent   * ServiceID = {9482F4B4-E343-43B6-B170-9A65BC822C77} Windows Update
    2016-01-12 17:02:42:893 1248 181c Agent   * Search Scope = {Machine}
    2016-01-12 17:02:43:877 1248 181c Agent   * Found 0 updates and 0 categories in search; evaluated appl. rules of 0 out of 0 deployed entities
    2016-01-12 17:02:43:877 1248 181c Agent *********
    2016-01-12 17:02:43:877 1248 181c Agent **  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2016-01-12 17:02:43:877 1248 181c Agent *************
    2016-01-12 17:02:43:877 1248 202c AU >>##  RESUMED  ## AU: Search for updates [CallId = {D58D43A1-0293-4AB7-910B-FCF79D59431C}]
    2016-01-12 17:02:43:877 1248 202c AU   # 0 updates detected
    2016-01-12 17:02:43:877 1248 202c AU #########
    2016-01-12 17:02:43:877 1248 202c AU ##  END  ##  AU: Search for updates [CallId = {D58D43A1-0293-4AB7-910B-FCF79D59431C}]
    2016-01-12 17:02:43:877 1248 202c AU #############
    2016-01-12 17:02:43:877 1248 202c AU No featured updates notifications to show
    2016-01-12 17:02:43:877 1248 202c AU Setting AU scheduled install time to 2016-01-12 19:00:00
    2016-01-12 17:02:43:877 1248 202c AU Successfully wrote event for AU health state:1
    2016-01-12 17:02:43:877 1248 202c AU Successfully wrote event for AU health state:1
    2016-01-12 17:02:47:721 1248 181c Report REPORT EVENT: {F67CEEAF-C4ED-4770-A5A2-54123BFCBD36} 2016-01-12 17:02:42:737+0800 1 202 102 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Content Install Reboot completed.
    2016-01-12 17:02:48:362 1248 181c Report CWERReporter finishing event handling. (00000000)

    Running wsus clientdiag it showed a failure at the end:

    UseWuServer value is missing..................................FAIL


    Valuable skills are not learned, learned skills aren't valuable.

    Tuesday, January 12, 2016 9:12 AM
  • The new file does indicate 'null' for wsus server:

    <...>
    2016-01-12 17:02:40:909 1248 27d8 Agent ***********  Agent: Initializing global settings cache  ***********
    2016-01-12 17:02:40:909 1248 27d8 Agent   * WSUS server: <NULL>
    2016-01-12 17:02:40:909 1248 27d8 Agent   * WSUS status server: <NULL>
    2016-01-12 17:02:40:909 1248 27d8 Agent   * Target group: (Unassigned Computers)
    <....>

    Running wsus clientdiag it showed a failure at the end:

    UseWuServer value is missing..................................FAIL

    Ok, so, this client is not configured for WSUS at all.
    That would explain the attempts to default to WU/MU.

    Configure this client for your WSUS implementation, and try again :)


    Don [doesn't work for MSFT, and they're probably glad about that ;]

    • Proposed as answer by Steven_Lee0510 Tuesday, February 9, 2016 2:20 PM
    • Marked as answer by Steven_Lee0510 Wednesday, February 10, 2016 4:18 AM
    Tuesday, January 12, 2016 9:46 AM
  • I created the UseWuServer value and gave it a data value of 1. That solved the problem. Don't understand why the settings in local security policy are correct but UseWuServer value not present.

    Wasted me 5 months time wondering.


    Valuable skills are not learned, learned skills aren't valuable.

    Tuesday, January 12, 2016 2:12 PM