RAVASMARTSOLUTIONS - TECH TIPS Troubleshooting Proactive Updates Server Setup Purpose Troubleshooting technology is a time consuming process. Being proactive help prevent problems, thus saving time and resources. One of the most common problems on a network is keeping your networked computers updated with the latest patches. This tech tip shows how the Desktop Authority Server is setup for Patch Management. This product is used to deploy any software updates including: Windows MS Office Java And much more! Figure 1 - First it analyzes to see if the PC needs any patches Author: Rick Rava Page 1 of 13 Revised: 10/16/2010
Figure 2 - Next it installs the needed patches Author: Rick Rava Page 2 of 13 Revised: 10/16/2010
Setup of Distribution/Download Servers (One Time Only) Purpose: All patch downloads from the ScriptLogic web site servers (which is the gatekeeper for all patches from MS, Adobe, etc) are downloaded to the following servers. All PCs in this building then get their patches from the SASDDAPMLE server (instead of going across the T1 for updates which would not have enough bandwidth for many of these patches!) This is accomplished on the Desktop Authority Server. Then on the server go to Deployment Options then Server Manager (need to setup the new servers and configure the items below): 3 Distribution Servers for Each Building Example of Good Performance Design: 3 Distribution Servers Per Buildings SASDDAPMHS (DA Patch Management Deployment/Distribution Server). SASDDAPMLE (DA Patch Management Deployment/Distribution Server). SASDDAPMSE (DA Patch Management Deployment/Distribution Server). Author: Rick Rava Page 3 of 13 Revised: 10/16/2010
Example of Poor Performance Design In order to keep our Domain Controllers (SASDDC1 and SASDDC2 and SASDDC3) performing well, we need to not download the patches to the domain controllers or use the domain controllers to distribute the patches. The following is an example of doing that (which we do not want to do)! Author: Rick Rava Page 4 of 13 Revised: 10/16/2010
Poor Performance Do not do! To correctly set this up, do the following one time: Correct Setup Domain Admin Account Right-click on Update Service for the item and set up as above Author: Rick Rava Page 5 of 13 Revised: 10/16/2010
Right-click STOP - Remove from DCs This results in: Proper Setup of Patch Management Note that there are 3 download and distribution servers Patch Distribution do not use Go to Patch Distribution this is not to be used since we use Deployment by Criteria for our Profiles and Elements! Leave everything unchecked! Do not use & leave blank Author: Rick Rava Page 6 of 13 Revised: 10/16/2010
Verifying that the Patch Management Servers are Communicating to the DA Web Update Servers If you RDP to a patch management distribution server there is a folder where the updates are stored: The following is an example from SASDDAPMHS \\sasddapmhs\c$\program Files (x86)\scriptlogic\update Service\Cache\Patch Downloaded patches to a the HS Patch Author: Rick Rava Page 7 of 13 Revised: 10/16/2010
Setup of Profile(s) Setup the Validation Logic as follows: Once per day plus building Use Custom Function to run this once per day per computer Function for 1 time per day per computer Note: Code for Function slvaloncepermachineperday("hspatchguid") For each element in DA, the parameter must be unique. For example HS is HSPatchGuid. SE is SEPatchGuid. Etc. Author: Rick Rava Page 8 of 13 Revised: 10/16/2010
Settings for Deployment Always use Deploy by Criteria Select specific location distribution server Ensure that patches are installed before logoff English only Pre-Download to distribution servers to improve performance Setting for Do Not Reboot please note that by using DA inactivity to reboot after hours, the patches are installed Author: Rick Rava Page 9 of 13 Revised: 10/16/2010
Never Reboot After setting up the above, now you need to select which patches to download and install to the PCs. Author: Rick Rava Page 10 of 13 Revised: 10/16/2010
Author: Rick Rava Page 11 of 13 Revised: 10/16/2010
CAUTION: Editing Profile(s) Caution: After selecting Yes on the Reload, you will need to be patient and let everything load When editing a profile if you are prompted to Load always select Yes and wait for this to complete If you do not respond Yes, all of your patch selection criteria will be erased! This will result in no patches being selected for deployment The following is what you should see: Author: Rick Rava Page 12 of 13 Revised: 10/16/2010
This is what you should see your selection criteria Author: Rick Rava Page 13 of 13 Revised: 10/16/2010