Jump to content
  • Announcements

    • Rodion Nagornov

      Долгое сохранение сообщений || Delays while posting (click here to read the full text RU/EN)   09/20/2017

      Due to some technical reasons visual delays are possible while message sending. Actually your message is published immediately - just interface works long. In such case, please, do not re-send your message immediately! Press F5 to reload the page and check if your message/topic is published. || По техническим причинам возможно визуально долгое отправление сообщений на форуме. Фактически ваше сообщение публикуется мгновенно - долго отрабатывает графика. В случае подобной ситуации, пожалуйста, сначала обновите страницу (F5) и проверьте, появилось ли ваше сообщение. Не пытайтесь сразу отправить его заново.
Ian James

Windows 10 Updates Issues

Recommended Posts

I have the following setup.

KSC 10.4.343
KES 10.3.0.6294
Networks Agent 10.4.343
Commercial License

We have setup KSC to act as a WSUS server for our Windows 10 clients (1703) (Part of a much bigger picture, no policies or tasks are inherited outside of this structure ), so I have set up a network agent policy as attached to user the server for third party and windows updates.

The third party updates are being applied to the windows 10 machines and wsus seems to be syncing with Microsoft as it has consumed nearly 200 gigs since turning it on. (We sync Office 2007, Windows 10 and Office 365 Client only).

Our issues are as follows.

1, The task to check for vulns works and results are returned, updates are listed in the device as required. The task to install the updates switches to downloading and stays there at 0%. Task never completes... unless I remove the windows update elements of the task. Then the third party apps are updated and the task complete. Is there a reason it is doing this?

2, The KasperskyLab Adminket folder on the client has grown from 500 meg on the machines that just do the third party patching to 60 gigs on the windows 10 clients. Looks like it is trying to completely download the wsus folder from the server. This isn't acceptable and seems to be some kind of issue, is there a way to reduce this folders size on the client computers, a task or something?

 

I have attached as much as I think you need here, if you need anything else, please feel free to shout.

Kas10AVPol.klp

Kas10NAPol.klp

VulnInst.JPG

Share this post


Link to post

Hi,

 

Цитата

 Task never completes... unless I remove the windows update elements of the task

Are these updates are available for download using any other method?

Цитата

 This isn't acceptable and seems to be some kind of issue, is there a way to reduce this folders size on the client computers, a task or something?

 Could you please provide us with a listing of that folder?

Share this post


Link to post
20 minutes ago, Nikolay Arinchev said:

Hi,

 

Are these updates are available for download using any other method?

 Could you please provide us with a listing of that folder?

If I take out the settings for WSUS via KSC and point the computer at Windows update it finds them all and installs fine. (Tried on test PC same windows image)

It also lists the in the available updates in the device properties. (see Images below) All updates approved and are listed as available to install on this PC.

Folder contents are available via the One Drive link for next few days.

https://elegantresorts-my.sharepoint.com/personal/ian_james_elegantresorts_ie/_layouts/15/guestaccess.aspx?docid=008af8a66fb8747beb014da98a1bc2315&authkey=Ae1eCHmbgg5GX74gGhuiVf4&expiration=2017-10-31T00%3a00%3a00.000Z

 

Updates.JPG

Edited by Ian James

Share this post


Link to post

In that case please collect admin server traces + network agent from admin server traces + host network agent traces while the task is started.

Please notice, that all these traces should be collected simultaneously for at least 15 minutes in a row.

Please use any file sharing resource to upload data and provide us with a link.

Thank you!

Share this post


Link to post

Sorry for the slow reply, 1709 got released and had to managed the update roll out.

 

Anyway, seems the issue was either with our image (most likely) or 1703. The issue has gone away under 1709.

Thanks

Share this post


Link to post

Hi there,

We are using the FDE on the KES 10.  However, A several machines (installed FDE) can not update the windows 10 update version 1703 among automatically.. A machine was installed by parameter manually in the command prompt. Our customer want to install this windows update 1703 version all of these computers from the KSC.

How can we deploy by remotely?

 

Thank you...

Share this post


Link to post

Hi again,

No, we did not. Is there any other way? So, if we turn protection off, can we do the update?

 

Thank you....

Share this post


Link to post

To upgrade on the computer encrypted with FDE, launch the upgrade of the operating system with the /reflectdrivers parameter: setup.exe /reflectdrivers <path to the folder with the cm_km, klfde, and klfdedmp drivers>.
Before starting the upgrade, create a folder and copy the following files to it: cm_km.inf, cm_km.sys, klfde.cat, klfde.inf, klfde.sys, klfdedmp.cat, klfdedmp.inf, klfdedmp.sys.

https://support.kaspersky.com/13036#block1

Thank you!

Share this post


Link to post

Hi again,

We have applied this solution and installed it via manually.However, How can we install from KSC by remotely for 50 computers? 

Otherwise, can we set the task to update the entire machines remotely, without decrypting the encryption?

Thank you...

Share this post


Link to post

Hi,

Цитата

Otherwise, can we set the task to update the entire machines remotely, without decrypting the encryption?

That is not possible.

Цитата

How can we install from KSC by remotely for 50 computers? 

If you do use System management at KSC than you can accept these updates and install them to all 50 PCs.

Thank you!

Share this post


Link to post
3 minutes ago, Nikolay Arinchev said:

Hi,

Thank you for reply.

 

4 minutes ago, Nikolay Arinchev said:

Hi,

 

Got it. We can install that update via Software Updates. So, Is it necessary active of the WSUS?

Thank you...

4 minutes ago, Nikolay Arinchev said:

 

 

Hi,

Thank you for reply.

 

Got it. We can install that update via Software Updates. So, Is it necessary active of the WSUS?

 

Thank you...

Share this post


Link to post

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×