NAP Client will fall into Remediation Zone every 22 hrs (NAP+WSUS)


using wsus update source nap clients. wsus server has 2 interfaces, 1 in production zone 1 in remediation zone.

when nap client running in production zone can see communication between nap client , wsus's production interface (i tried telnet port 8530 success.) base on monitoring of nap clients fall remediation zone every 22hrs , after few minutes, didn't install patch.

22hrs looks default value "the number of hours since client synchronized update source". (http://technet.microsoft.com/library/cc731260.aspx) nap clients able reach wsus in production zone attribute should not assessed.

any idea issue?

thanks!!!

hi,

a blog explains it.

this number of hours since last time client synched appropriate update server. assessed when joining network. if time since last online scan exceeds value, client deemed non-complaint.

nap faq: enforcing security updates (out-of-the-box)

http://blogs.technet.com/b/nap/archive/2008/04/24/nap-faq-enforcing-security-updates-out-of-the-box-2.aspx

hope helps.



Windows Server  >  Network Access Protection



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file