NAP Client will fall into Remediation Zone every 22 hrs (NAP+WSUS)
using wsus update source nap clients. wsus server has 2 interfaces, 1 in production zone 1 in remediation zone.
when nap client running in production zone can see communication between nap client , wsus's production interface (i tried telnet port 8530 success.) base on monitoring of nap clients fall remediation zone every 22hrs , after few minutes, didn't install patch.
22hrs looks default value "the number of hours since client synchronized update source". (http://technet.microsoft.com/library/cc731260.aspx) nap clients able reach wsus in production zone attribute should not assessed.
any idea issue?
thanks!!!
hi,
a blog explains it.
this number of hours since last time client synched appropriate update server. assessed when joining network. if time since last online scan exceeds value, client deemed non-complaint.
nap faq: enforcing security updates (out-of-the-box)
hope helps.
Windows Server > Network Access Protection
Comments
Post a Comment