Hi,
I have computer "A" which is running Windows Server 2012 R2 and is not connected to any domain.
I have computer "B" which is joined to domain "B" and runs a WSUS server. 172.21.3.150
I have computer "C" which is joined to domain "C" and runs a WSUS server.
There is no firewall, antivirus, or routing restriction that prevents any from talking to one another.
I set A to retrieve updates from B or C by setting the appropriate local policy which in turn changes HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\WUServer.
A can receive WSUS updates from C.
A cannot receive WSUS updates from B. A's error log appears below. Computer on domain B can use B to get WSUS updates. From A I can use telnet to make a TCP/IP connection to port 8530 on B so I'm certain there is connectivity.
Hundreds of group policy changes have been applied to "B" as part of a hardening process called "STIG". The hardening is described at https://www.stigviewer.com/stig/windows_server_2012_2012_r2_member_server/ and includes for example"limit TCP/IP retry attempts" and "The LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM". I suspect one of these hundreds of settings is responsible for denying non-domain-joined computers
to take a WSUS update from B. I wish a log entry could help me identify the specific technical reason for the failure.
There is no indication of a problem on B as far as I could tell. Nothing in the Event Viewer. Nothing in the IIS logs (!)... not even an indication that a bad request came in.
How can I figure out why WSUS updates are failing from A to B?
Chris
PS: When specifying the WSUS server on A I use B's IP address (which normally works fine). But out of desperation I also tried specifying B's FQDN (as it is known within domain B). Of course, I also had to add the FQDN to A's host file. That
also failed.
2018-01-25 13:15:19:590 1408 3164 Misc =========== Logging initialized (build: 7.9.9600.18696, tz: -0500) ===========
2018-01-25 13:15:19:590 1408 3164 Misc = Process: C:\Windows\system32\svchost.exe
2018-01-25 13:15:19:590 1408 3164 Misc = Module: c:\windows\system32\wuaueng.dll
2018-01-25 13:15:19:590 1408 3164 Service *************
2018-01-25 13:15:19:590 1408 3164 Service ** START ** Service: Service startup
2018-01-25 13:15:19:590 1408 3164 Service *********
2018-01-25 13:15:19:606 1408 3164 IdleTmr Non-AoAc machine. Aoac operations will be ignored.
2018-01-25 13:15:19:606 1408 3164 Agent * WU client version 7.9.9600.18696
2018-01-25 13:15:19:606 1408 3164 Agent WARNING: SleepStudyTracker: Machine is non-AOAC. Sleep study tracker disabled.
2018-01-25 13:15:19:606 1408 3164 Agent * Base directory: C:\Windows\SoftwareDistribution
2018-01-25 13:15:19:606 1408 3164 Agent * Access type: No proxy
2018-01-25 13:15:19:606 1408 3164 Service UpdateNetworkState Ipv6, cNetworkInterfaces = 3.
2018-01-25 13:15:19:606 1408 3164 Service UpdateNetworkState Ipv4, cNetworkInterfaces = 3.
2018-01-25 13:15:19:606 1408 3164 Agent * Network state: Connected
2018-01-25 13:15:19:606 1408 3164 Service UpdateNetworkState Ipv6, cNetworkInterfaces = 3.
2018-01-25 13:15:19:606 1408 3164 Service UpdateNetworkState Ipv4, cNetworkInterfaces = 3.
2018-01-25 13:15:19:622 1408 3164 Agent *********** Agent: Initializing global settings cache ***********
2018-01-25 13:15:19:622 1408 3164 Agent * Endpoint Provider: 00000000-0000-0000-0000-000000000000
2018-01-25 13:15:19:622 1408 3164 Agent * WSUS server: http://172.21.3.150:8530
2018-01-25 13:15:19:622 1408 3164 Agent * WSUS status server: http://172.21.3.150:8530
2018-01-25 13:15:19:622 1408 3164 Agent * Target group: (Unassigned Computers)
2018-01-25 13:15:19:622 1408 3164 Agent * Windows Update access disabled: No
2018-01-25 13:15:19:622 1408 3164 Misc WARNING: Network Cost is assumed to be not supported as something failed with trying to get handles to wcmapi.dll
2018-01-25 13:15:19:622 1408 3164 WuTask WuTaskManager delay initialize completed successfully..
2018-01-25 13:15:19:622 1408 3164 AU Timer: 31DA7559-FE27-4810-8FF6-987195B1FD98, Expires 2018-01-25 23:11:24, not idle-only, not network-only
2018-01-25 13:15:19:622 1408 3164 AU Timer: 143FB093-8AA1-4DBC-A582-8806F8F4C1F7, Expires 2018-01-27 18:11:25, not idle-only, not network-only
2018-01-25 13:15:19:622 1408 3164 AU Timer: CF1ABEC6-7887-4964-BB93-B2E21B31CEC1, Expires 2018-01-25 18:43:40, not idle-only, not network-only
2018-01-25 13:15:19:622 1408 3164 AU Timer: 29A863E7-8609-4D1E-B7CD-5668F857F1DB, Expires 2018-01-25 18:43:40, not idle-only, not network-only
2018-01-25 13:15:19:622 1408 3164 Report CWERReporter::Init succeeded
2018-01-25 13:15:19:622 1408 3164 Agent *********** Agent: Initializing Windows Update Agent ***********
2018-01-25 13:15:19:622 1408 3164 DnldMgr Download manager restoring 0 downloads
2018-01-25 13:15:19:622 1408 3164 AU ########### AU: Initializing Automatic Updates ###########
2018-01-25 13:15:19:622 1408 3164 AU AIR Mode is disabled
2018-01-25 13:15:19:622 1408 3164 AU # Policy Driven Provider: http://172.21.3.150:8530
2018-01-25 13:15:19:622 1408 3164 AU # Detection frequency: 22
2018-01-25 13:15:19:622 1408 3164 AU # Approval type: Scheduled (User preference)
2018-01-25 13:15:19:622 1408 3164 AU # Auto-install minor updates: Yes (User preference)
2018-01-25 13:15:19:622 1408 3164 AU # Will interact with non-admins (Non-admins are elevated (User preference))
2018-01-25 13:15:19:622 1408 3164 AU WARNING: Failed to get Wu Exemption info from NLM, assuming not exempt, error = 0x80240037
2018-01-25 13:15:19:622 1408 3164 AU WARNING: Failed to get Network Cost info from NLM, assuming network is NOT metered, error = 0x80240037
2018-01-25 13:15:19:622 1408 3164 AU AU finished delayed initialization
2018-01-25 13:15:19:622 1408 3164 AU Currently AUX is enabled - so not show any WU Upgrade notifications.
2018-01-25 13:15:19:622 1408 3164 AU WARNING: Failed to get Network Cost info from NLM, assuming network is NOT metered, error = 0x80240037
2018-01-25 13:15:19:637 1408 3164 AU WARNING: Failed to get Network Cost info from NLM, assuming network is NOT metered, error = 0x80240037
2018-01-25 13:15:19:637 1408 2b18 DnldMgr Asking handlers to reconcile their sandboxes
2018-01-25 13:15:29:572 1408 4738 IdleTmr Incremented idle timer priority operation counter to 1
2018-01-25 13:15:29:572 1408 4738 AU Triggering AU detection through DetectNow API
2018-01-25 13:15:29:572 1408 4738 AU Triggering Online detection (interactive)
2018-01-25 13:15:29:572 1408 4738 AU Adding timer:
2018-01-25 13:15:29:572 1408 4738 AU Timer: 31DA7559-FE27-4810-8FF6-987195B1FD98, Expires 2018-01-25 18:15:29, not idle-only, not network-only
2018-01-25 13:15:29:572 1408 3164 AU #############
2018-01-25 13:15:29:572 1408 3164 AU ## START ## AU: Search for updates
2018-01-25 13:15:29:572 1408 3164 AU #########
2018-01-25 13:15:29:572 1408 3164 SLS Retrieving SLS response from server...
2018-01-25 13:15:29:572 1408 3164 SLS Making request with URL HTTPS://sls.update.microsoft.com/SLS/{9482F4B4-E343-43B6-B170-9A65BC822C77}/x64/6.3.9600.0/0?CH=352&L=en-US&P=&PT=0x7&WUA=7.9.9600.18696
2018-01-25 13:15:29:572 1408 3164 Misc WARNING: Send failed with hr = 80072ee7.
2018-01-25 13:15:29:572 1408 3164 Misc WARNING: Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes used : <None>
2018-01-25 13:15:29:572 1408 3164 Misc WARNING: Send request failed, hr:0x80072ee7
2018-01-25 13:15:29:572 1408 3164 Misc WARNING: WinHttp: SendRequestUsingProxy failed for <HTTPS://sls.update.microsoft.com/SLS/{9482F4B4-E343-43B6-B170-9A65BC822C77}/x64/6.3.9600.0/0?CH=352&L=en-US&P=&PT=0x7&WUA=7.9.9600.18696>. error 0x8024402c
2018-01-25 13:15:29:572 1408 3164 Misc WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x8024402c
2018-01-25 13:15:29:572 1408 3164 Misc WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x8024402c
2018-01-25 13:15:29:572 1408 3164 Misc WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x8024402c
2018-01-25 13:15:29:572 1408 3164 SLS FATAL: SLS:CSLSDownloader::GetUrlContent: DoFileDownload failed with 0x8024402c.
2018-01-25 13:15:29:572 1408 3164 SLS FATAL: GetResponse failed with hresult 0x8024402c...
2018-01-25 13:15:29:572 1408 3164 EP FATAL: EP: CSLSEndpointProvider::GetWUClientData - failed to get SLS data, error = 0x8024402C
2018-01-25 13:15:29:572 1408 3164 EP FATAL: EP: CSLSEndpointProvider::GetEndpointFromSLS - Failed to get client data, error = 0x8024402C
2018-01-25 13:15:29:572 1408 3164 EP FATAL: Failed to obtain 9482F4B4-E343-43B6-B170-9A65BC822C77 redir SecondaryServiceAuth URL, error = 0x8024402C
2018-01-25 13:15:29:572 1408 3164 Agent WARNING: Failed to obtain the authorization cab URL for service 7971f918-a847-4430-9279-4a52d1efe18d, hr=0
2018-01-25 13:15:29:572 1408 3164 Agent FATAL: Caller <NULL> failed to opt in to service 7971f918-a847-4430-9279-4a52d1efe18d, hr=0X8024402C
2018-01-25 13:15:29:572 1408 3164 IdleTmr WU operation (CSearchCall::Init ID 1) started; operation # 9; does use network; is not at background priority
2018-01-25 13:15:29:572 1408 3164 IdleTmr Incremented idle timer priority operation counter to 2
2018-01-25 13:15:29:760 1408 3164 Report *********** Report: Initializing static reporting data ***********
2018-01-25 13:15:29:760 1408 3164 Report * OS Version = 6.3.9600.0.0.196880
2018-01-25 13:15:29:760 1408 3164 Report * OS Product Type = 0x00000007
2018-01-25 13:15:29:760 1408 3164 Report * Computer Brand = Dell Inc.
2018-01-25 13:15:29:760 1408 3164 Report * Computer Model = PowerEdge R630
2018-01-25 13:15:29:760 1408 3164 Report * Platform Role = 4
2018-01-25 13:15:29:760 1408 3164 Report * AlwaysOn/AlwaysConnected (AOAC) = 0
2018-01-25 13:15:29:775 1408 3164 Report * Bios Revision = 2.6.0
2018-01-25 13:15:29:775 1408 3164 Report * Bios Name = 2.6.0
2018-01-25 13:15:29:775 1408 3164 Report * Bios Release Date = 2017-10-26T00:00:00
2018-01-25 13:15:29:775 1408 3164 Report * Bios Sku Number = SKU=NotProvided;ModelName=PowerEdge R630
2018-01-25 13:15:29:775 1408 3164 Report * Bios Vendor = Dell Inc.
2018-01-25 13:15:29:775 1408 3164 Report * Bios Family unavailable.
2018-01-25 13:15:29:775 1408 3164 Report * Bios Major Release = 2
2018-01-25 13:15:29:775 1408 3164 Report * Bios Minor Release = 6
2018-01-25 13:15:29:775 1408 3164 Report * Locale ID = 1033
2018-01-25 13:15:29:775 1408 3164 Handler Calculating current update level for this session
2018-01-25 13:15:31:041 1408 3164 Handler UH: Current cumulative update level calculated: package identity Package_for_KB3000850~31bf3856ad364e35~amd64~~6.3.1.8, display name KB3000850, support URL http://support.microsoft.com/?kbid=3000850, timestamp 01d30a579117b45c
2018-01-25 13:15:31:041 1408 3164 Handler Done calculating current update level for this session
2018-01-25 13:15:31:338 1408 3164 Agent *** START *** Queueing Finding updates [CallerId = AutomaticUpdatesWuApp Id = 1]
2018-01-25 13:15:31:338 1408 3164 AU <<## SUBMITTED ## AU: Search for updates [CallId = {C4E8A0EC-DB35-4F06-8CBB-94F2D46FEC20} ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}]
2018-01-25 13:15:31:338 1408 814 Agent *** END *** Queueing Finding updates [CallerId = AutomaticUpdatesWuApp Id = 1]
2018-01-25 13:15:31:338 1408 814 Agent *************
2018-01-25 13:15:31:338 1408 814 Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdatesWuApp Id = 1]
2018-01-25 13:15:31:338 1408 814 Agent *********
2018-01-25 13:15:31:338 1408 814 Agent * Online = Yes; Ignore download priority = No
2018-01-25 13:15:31:338 1408 814 Agent * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
2018-01-25 13:15:31:338 1408 814 Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2018-01-25 13:15:31:338 1408 814 Agent * Search Scope = {Machine & All Users}
2018-01-25 13:15:31:338 1408 814 Agent * Caller SID for Applicability: S-1-5-21-3243891630-2772889517-259860837-1001
2018-01-25 13:15:31:338 1408 814 Agent * RegisterService is set
2018-01-25 13:15:31:338 1408 814 EP Got WSUS Client/Server URL: "http://172.21.3.150:8530/ClientWebService/client.asmx"
2018-01-25 13:15:31:338 1408 814 Setup Checking for agent SelfUpdate
2018-01-25 13:15:31:338 1408 814 Setup Client version: Core: 7.9.9600.18696 Aux: 7.9.9600.18696
2018-01-25 13:15:31:338 1408 814 EP Got WSUS SelfUpdate URL: "http://172.21.3.150:8530/selfupdate"
2018-01-25 13:15:52:361 1408 814 Misc WARNING: Send failed with hr = 80072ee2.
2018-01-25 13:15:52:361 1408 814 Misc WARNING: Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes used : <None>
2018-01-25 13:15:52:361 1408 814 Misc WARNING: Send request failed, hr:0x80072ee2
2018-01-25 13:15:52:361 1408 814 Misc WARNING: WinHttp: SendRequestUsingProxy failed for <http://172.21.3.150:8530/selfupdate/wuident.cab>. error 0x80072ee2
2018-01-25 13:15:52:361 1408 814 Misc WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072ee2
2018-01-25 13:15:52:361 1408 814 Misc WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072ee2
2018-01-25 13:15:52:361 1408 814 Misc WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072ee2
2018-01-25 13:15:52:361 1408 814 Misc WARNING: DownloadFileInternal failed for http://172.21.3.150:8530/selfupdate/wuident.cab: error 0x80072ee2
2018-01-25 13:15:52:361 1408 814 Setup FATAL: DownloadCab failed, err = 0x80072EE2
2018-01-25 13:15:52:361 1408 814 Setup WARNING: SelfUpdate check failed to download package information, err = 0x80072EE2
2018-01-25 13:15:52:361 1408 814 Setup FATAL: SelfUpdate check failed, err = 0x80072EE2
2018-01-25 13:15:52:361 1408 814 Agent * WARNING: Skipping scan, self-update check returned 0x80072EE2
2018-01-25 13:15:52:361 1408 814 DtaStor FATAL: CSusEseSession::DeleteSLSData failed, hresult 0x80248007
2018-01-25 13:15:52:361 1408 814 SLS WARNING: PurgeCache failed with hresult 0x80248007 ...
2018-01-25 13:15:52:361 1408 814 Agent WARNING: Failed to purge SLSClient with 0x80072ee2. Continuing...
2018-01-25 13:15:52:361 1408 814 Agent * WARNING: Exit code = 0x80072EE2
2018-01-25 13:15:52:361 1408 814 Agent *********
2018-01-25 13:15:52:361 1408 814 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdatesWuApp Id = 1]
2018-01-25 13:15:52:361 1408 814 Agent *************
2018-01-25 13:15:52:361 1408 814 Agent WARNING: WU client failed Searching for update with error 0x80072ee2
2018-01-25 13:15:52:361 1408 814 IdleTmr WU operation (CSearchCall::Init ID 1, operation # 9) stopped; does use network; is not at background priority
2018-01-25 13:15:52:361 1408 814 IdleTmr Decremented idle timer priority operation counter to 1
2018-01-25 13:15:52:361 1408 1ab4 AU >>## RESUMED ## AU: Search for updates [CallId = {C4E8A0EC-DB35-4F06-8CBB-94F2D46FEC20} ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}]
2018-01-25 13:15:52:361 1408 1ab4 AU # WARNING: Search callback failed, result = 0x80072EE2
2018-01-25 13:15:52:361 1408 1ab4 AU #########
2018-01-25 13:15:52:361 1408 1ab4 AU ## END ## AU: Search for updates [CallId = {C4E8A0EC-DB35-4F06-8CBB-94F2D46FEC20} ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}]
2018-01-25 13:15:52:361 1408 1ab4 AU #############
2018-01-25 13:15:52:361 1408 1ab4 AU All AU searches complete.
2018-01-25 13:15:52:361 1408 1ab4 AU # WARNING: Failed to find updates with error code 80072ee2
2018-01-25 13:15:52:361 1408 1ab4 AU AU setting next detection timeout to 2018-01-25 23:15:52
2018-01-25 13:15:52:361 1408 1ab4 AU Adding timer:
2018-01-25 13:15:52:361 1408 1ab4 AU Timer: 31DA7559-FE27-4810-8FF6-987195B1FD98, Expires 2018-01-25 23:15:52, not idle-only, not network-only
2018-01-25 13:15:52:361 1408 1ab4 AU Currently AUX is enabled - so not show any WU Upgrade notifications.
2018-01-25 13:15:52:361 1408 1ab4 AU WARNING: Failed to get Network Cost info from NLM, assuming network is NOT metered, error = 0x80240037
2018-01-25 13:15:52:361 1408 1ab4 AU WARNING: Failed to get Network Cost info from NLM, assuming network is NOT metered, error = 0x80240037