Topic researching and deploying windows server update services

Hướng dẫn chi tiết các bước nghiên cứu và triển khai Windows Server Update Services (WSUS) để quản lý hiệu quả các bản cập nhật cho hệ thống.

Chuyên ngành

Computer Science

Người đăng

Ẩn danh

Thể loại

final project

2021

58
2
0

Phí lưu trữ

30 Point

Tóm tắt

I. Tổng quan về Windows Server Update Services WSUS là gì

Trong môi trường doanh nghiệp hiện đại, việc đảm bảo an toàn thông tin và dữ liệu đóng vai trò sống còn. Một trong những phương pháp nền tảng để đạt được điều này là thường xuyên cập nhật các bản vá cho hệ điều hành Windows và phần mềm Microsoft. Windows Server Update Services (WSUS) chính là giải pháp được Microsoft phát triển để giải quyết bài toán này một cách tập trung và hiệu quả. Đây là một vai trò (role) trên hệ điều hành Windows Server, cho phép quản trị viên triển khai các bản cập nhật sản phẩm Microsoft mới nhất đến các máy tính trong mạng nội bộ. Thay vì mỗi máy trạm phải tự kết nối Internet để tải cập nhật, chúng sẽ kết nối đến một máy chủ WSUS trung gian. Điều này không chỉ giúp quản lý việc phân phối bản vá một cách có kiểm soát mà còn tối ưu hóa việc sử dụng băng thông Internet.

1.1. Vai trò và nguyên tắc hoạt động của máy chủ WSUS

Về cơ bản, WSUS hoạt động như một kho lưu trữ và phân phối bản cập nhật cục bộ. Một máy chủ WSUS trong mạng sẽ được cấu hình để kết nối đến Microsoft Update nhằm tải về thông tin về các bản cập nhật có sẵn. Máy chủ này được gọi là máy chủ upstream. Sau khi tải về, quản trị viên có thể xem xét, phê duyệt (approve) hoặc từ chối (decline) các bản cập nhật cho từng nhóm máy tính cụ thể. Các máy trạm (client) trong mạng nội bộ (LAN) sẽ được cấu hình, thường thông qua Group Policy, để kết nối đến máy chủ WSUS này thay vì kết nối trực tiếp ra Internet. Quy trình này giúp quản trị viên toàn quyền kiểm soát những bản vá nào được cài đặt, thời điểm cài đặt và trên những máy tính nào. Theo tài liệu nghiên cứu, mô hình này giúp "duy trì hiệu quả hoạt động, khắc phục các lỗ hổng bảo mật và duy trì sự ổn định của môi trường sản xuất".

1.2. Lợi ích chính khi triển khai Windows Server Update Services

Việc triển khai Windows Server Update Services mang lại ba lợi ích cốt lõi. Đầu tiên là quản lý cập nhật tập trung. Quản trị viên có thể quản lý và phân phối bản vá cho hàng trăm, thậm chí hàng ngàn máy tính từ một giao diện duy nhất. Thứ hai là tiết kiệm băng thông Internet. Tài liệu gốc nhấn mạnh: "Trước đây, tất cả các máy khách phải truy cập Internet để cập nhật... nhưng bây giờ chỉ có một máy chủ kết nối Internet để cập nhật trực tuyến trong khi các máy khách thực hiện cập nhật bên trong mạng LAN". Điều này cực kỳ quan trọng đối với các doanh nghiệp có nhiều máy tính hoặc đường truyền Internet hạn chế. Cuối cùng là tăng cường bảo mật và tuân thủ. Bằng cách đảm bảo tất cả máy tính được cập nhật bản vá kịp thời, WSUS giúp giảm thiểu rủi ro từ các lỗ hổng bảo mật đã biết và giúp tổ chức dễ dàng tuân thủ các chính sách bảo mật nội bộ.

II. Thách thức trong việc quản lý cập nhật thủ công hiện nay

Trước khi có các giải pháp tập trung như WSUS, việc quản lý cập nhật cho một hệ thống mạng lớn là một công việc đầy thách thức và tiềm ẩn nhiều rủi ro. Phương pháp cập nhật thủ công, nơi mỗi người dùng tự chịu trách nhiệm cho máy tính của mình, thường dẫn đến các vấn đề nghiêm trọng về bảo mật, hiệu suất mạng và khả năng kiểm soát của bộ phận IT. Việc không có một quy trình chuẩn hóa và tự động hóa khiến hệ thống dễ bị tấn công và khó duy trì sự ổn định. Những thách thức này chính là động lực thúc đẩy sự ra đời và phát triển của các hệ thống như Windows Server Update Services.

2.1. Rủi ro bảo mật từ việc cập nhật bản vá không đồng bộ

Thách thức lớn nhất của việc cập nhật thủ công là tình trạng không nhất quán. Tài liệu nghiên cứu chỉ rõ: "Người dùng không cập nhật các bản vá hoặc thực hiện cập nhật bản vá không đầy đủ, dẫn đến nguy cơ bị tấn công bởi các lỗ hổng bảo mật". Khi mỗi máy tính có một trạng thái cập nhật khác nhau, một lỗ hổng trên chỉ một máy có thể trở thành cửa ngõ cho kẻ tấn công xâm nhập vào toàn bộ mạng lưới. Quản trị viên hệ thống gần như không thể kiểm soát và đảm bảo rằng 100% các máy tính đều được vá lỗi kịp thời. Sự chậm trễ hoặc bỏ sót trong việc cập nhật bản vá an ninh quan trọng có thể dẫn đến mất mát dữ liệu, gián đoạn hoạt động kinh doanh và tổn hại uy tín của doanh nghiệp.

2.2. Vấn đề tiêu tốn băng thông và hiệu suất hệ thống

Khi mỗi máy tính trong mạng LAN tự động kết nối đến Microsoft Update để tải về các bản cập nhật, nó sẽ tạo ra một lưu lượng truy cập Internet quốc tế khổng lồ và lặp đi lặp lại. Một bản cập nhật có thể có dung lượng từ vài chục đến vài trăm Megabyte. Với một công ty có hàng trăm máy tính, tổng dung lượng tải về có thể lên đến hàng Gigabyte, gây lãng phí băng thông nghiêm trọng và làm chậm các hoạt động kinh doanh khác cần kết nối Internet. Hơn nữa, "trong trường hợp kết nối Internet chậm hoặc bị gián đoạn, việc cập nhật sẽ mất nhiều thời gian hơn, làm cho máy tính chạy chậm hơn". Điều này ảnh hưởng trực tiếp đến năng suất làm việc của người dùng cuối.

III. Hướng dẫn cài đặt Windows Server Update Services từ A Z

Việc triển khai WSUS là một quy trình kỹ thuật đòi hỏi sự chuẩn bị kỹ lưỡng và thực hiện theo từng bước cụ thể. Quá trình này bao gồm việc đáp ứng các yêu cầu về hệ thống, cài đặt vai trò WSUS thông qua Server Manager, và thực hiện các cấu hình ban đầu để dịch vụ có thể bắt đầu hoạt động. Mô hình triển khai phổ biến nhất bao gồm ba máy ảo: một máy Domain Controller (ADDS), một máy chủ để cài đặt WSUS, và một máy trạm (client) để kiểm thử. Việc tuân thủ đúng quy trình sẽ đảm bảo hệ thống quản lý cập nhật hoạt động ổn định và hiệu quả, giúp quản trị viên dễ dàng kiểm soát việc phân phối bản vá trong toàn bộ tổ chức.

3.1. Các yêu cầu về phần cứng và phần mềm cần chuẩn bị

Trước khi cài đặt, cần đảm bảo máy chủ đáp ứng các yêu cầu tối thiểu. Về phần cứng, Microsoft khuyến nghị bộ xử lý 1.4 GHz x64 (2 GHz hoặc nhanh hơn), tối thiểu 2GB RAM cộng thêm dung lượng cần thiết cho máy chủ và các dịch vụ khác, và ít nhất 40GB dung lượng đĩa trống. Dung lượng lưu trữ sẽ tăng lên tùy thuộc vào số lượng sản phẩm và loại cập nhật được chọn để đồng bộ. Về phần mềm, WSUS là một vai trò (role) của hệ điều hành Windows Server. Môi trường triển khai lý tưởng cần có Active Directory Domain Services (ADDS) để quản lý máy tính và người dùng, cho phép áp dụng chính sách một cách đồng bộ thông qua Group Policy Object (GPO). Việc chuẩn bị đầy đủ các yếu-tố-này là tiền đề cho một hệ thống WSUS hoạt động trơn tru.

3.2. Quy trình thêm Role WSUS trên Windows Server 2016

Quy trình cài đặt được thực hiện thông qua giao diện Server Manager. Đầu tiên, khởi chạy 'Add Roles and Features Wizard'. Sau khi qua các bước đầu tiên, tại mục 'Server Roles', chọn 'Windows Server Update Services'. Một cửa sổ sẽ hiện ra yêu cầu thêm các tính năng cần thiết như Web Server (IIS), hãy nhấn 'Add Features'. Trong các bước tiếp theo, trình cài đặt sẽ yêu cầu chọn các dịch vụ vai trò (Role Services). Hai lựa chọn chính là 'WID Connectivity' (sử dụng Windows Internal Database) và 'SQL Server Connectivity'. Đối với hầu hết các triển khai vừa và nhỏ, WID là đủ. Bước quan trọng tiếp theo là chỉ định một đường dẫn để lưu trữ các bản cập nhật đã tải xuống. Cần đảm bảo phân vùng này có đủ dung lượng trống. Cuối cùng, xác nhận các lựa chọn và nhấn 'Install' để bắt đầu quá trình cài đặt vai trò WSUS.

IV. Phương pháp cấu hình Group Policy để quản lý máy trạm

Sau khi cài đặt thành công máy chủ WSUS, bước tiếp theo và cũng là một trong những bước quan trọng nhất là cấu hình các máy trạm để chúng nhận diện và tải cập nhật từ máy chủ này. Phương pháp hiệu quả và được khuyến nghị nhất trong môi trường domain là sử dụng Group Policy (GPO). Bằng cách tạo và áp dụng một GPO cho các Organizational Unit (OU) chứa máy tính, quản trị viên có thể đồng loạt cấu hình hàng trăm máy tính mà không cần can thiệp thủ công trên từng máy. Việc này đảm bảo tính nhất quán, giảm thiểu sai sót và cho phép tự động hóa hoàn toàn quy trình cập nhật.

4.1. Tạo và liên kết GPO cho các máy tính trong miền Domain

Đầu tiên, trên máy Domain Controller, mở công cụ 'Group Policy Management'. Để dễ quản lý, nên tạo một OU mới (ví dụ: 'WSUS Clients') và di chuyển các đối tượng máy tính cần quản lý vào OU này. Sau đó, trong OU vừa tạo, nhấp chuột phải và chọn 'Create a GPO in this domain, and Link it here...'. Đặt một tên dễ nhận biết cho GPO mới, ví dụ 'WSUS Client Settings'. Việc liên kết GPO trực tiếp với OU chứa các máy tính cần áp dụng chính sách là cách làm khoa học, giúp quản trị viên dễ dàng theo dõi và tùy chỉnh chính sách cho từng nhóm máy tính khác nhau trong tổ chức mà không ảnh hưởng đến các máy tính khác trong Active Directory.

4.2. Thiết lập chính sách chỉ định máy chủ cập nhật nội bộ

Chính sách quan trọng nhất cần cấu hình là 'Specify intranet Microsoft update service location'. Để truy cập, hãy chỉnh sửa GPO vừa tạo, điều hướng đến 'Computer Configuration' -> 'Policies' -> 'Administrative Templates' -> 'Windows Components' -> 'Windows Update'. Tìm và mở chính sách này, chọn 'Enabled'. Trong phần Options, cần điền vào hai ô: 'Set the intranet update service for detecting updates' và 'Set the intranet statistics server'. Thông thường, cả hai ô này đều được điền cùng một địa chỉ của máy chủ WSUS, theo định dạng http://ten-may-chu-wsus:8530. Ví dụ: http://WSUS.mylab.local:8530. Cổng 8530 là cổng mặc định của WSUS. Chính sách này sẽ ra lệnh cho Windows Update Agent (WUA) trên máy trạm kết nối đến địa chỉ được chỉ định để kiểm tra và tải về cập nhật bản vá.

4.3. Lên lịch tự động tải và cài đặt bản vá cho máy Client

Để tự động hóa hoàn toàn, cần cấu hình chính sách 'Configure Automatic Updates'. Trong cùng đường dẫn GPO, mở chính sách này và chọn 'Enabled'. Tại mục 'Configure automatic updating', có nhiều lựa chọn, nhưng lựa chọn phổ biến nhất là '4 - Auto download and schedule the install'. Tùy chọn này cho phép máy trạm tự động tải về các bản cập nhật đã được phê duyệt từ máy chủ WSUS và cài đặt chúng theo một lịch trình định sẵn. Quản trị viên có thể chỉ định ngày trong tuần và thời gian cài đặt, ví dụ như vào cuối tuần hoặc ngoài giờ làm việc để tránh làm gián đoạn công việc của người dùng. Việc lên lịch này giúp đảm bảo các bản vá bảo mật được triển khai một cách kịp thời và có hệ thống.

V. Bí quyết quản lý và đồng bộ hóa hiệu quả với máy chủ WSUS

Vận hành một hệ thống WSUS không chỉ dừng lại ở việc cài đặt và cấu hình ban đầu. Quá trình quản lý liên tục, bao gồm việc kiểm tra kết nối, phê duyệt bản cập nhật, và theo dõi trạng thái của các máy trạm, là yếu tố quyết định sự thành công của giải pháp. Một máy chủ WSUS được quản lý tốt sẽ trở thành một công cụ mạnh mẽ giúp duy trì bảo mật hệ thống và sự ổn định của mạng. Hiểu rõ các kịch bản triển khai khác nhau cũng giúp tổ chức lựa chọn mô hình phù hợp nhất với quy mô và cấu trúc của mình, từ một văn phòng nhỏ đến một tập đoàn đa quốc gia.

5.1. Kiểm tra kết nối và trạng thái báo cáo từ máy trạm

Sau khi áp dụng GPO, các máy trạm sẽ bắt đầu liên lạc với máy chủ WSUS. Trong giao diện quản lý WSUS, các máy tính mới sẽ xuất hiện trong nhóm 'Unassigned Computers'. Ban đầu, trạng thái của chúng có thể là 'Not yet reported'. Để buộc máy trạm gửi báo cáo trạng thái ngay lập tức, có thể chạy lệnh wuauclt /reportnow trên máy trạm. Nếu một máy tính không kết nối được, lệnh wuauclt /resetauthorization /detectnow có thể được sử dụng để thiết lập lại kết nối. Việc thường xuyên kiểm tra bảng điều khiển WSUS để xem trạng thái 'Installed/Not Applicable Percentage', 'Updates needing files', và 'Updates with errors' là rất quan trọng để phát hiện sớm các vấn đề và đảm bảo tất cả máy tính đều tuân thủ chính sách cập nhật.

5.2. Phê duyệt Approve và phân phối các bản cập nhật

Các bản cập nhật được đồng bộ từ Microsoft Update sẽ không tự động được phân phối cho máy trạm. Quản trị viên phải thực hiện bước phê duyệt. Trong giao diện WSUS, điều hướng đến mục 'Updates', quản trị viên có thể lọc các bản cập nhật theo nhiều tiêu chí như 'Critical Updates', 'Security Updates' hoặc các bản cập nhật chưa được phê duyệt. Sau khi xem xét và quyết định một bản cập nhật là cần thiết và an toàn, quản trị viên nhấp chuột phải vào nó và chọn 'Approve...'. Một hộp thoại sẽ hiện ra cho phép phê duyệt bản cập nhật này để cài đặt ('Approve for Install') cho một hoặc nhiều nhóm máy tính cụ thể. Quy trình phê duyệt này đảm bảo rằng chỉ những cập nhật bản vá đã được kiểm tra và xác nhận mới được triển khai ra môi trường sản xuất.

5.3. Các kịch bản triển khai WSUS cho từng quy mô mạng

Tài liệu nghiên cứu đã nêu bật sự linh hoạt của WSUS qua các kịch bản triển khai khác nhau. Đối với mạng nhỏ, một máy chủ WSUS duy nhất đồng bộ trực tiếp với Microsoft Update là đủ. Đối với các tổ chức lớn hơn có nhiều chi nhánh, có thể triển khai nhiều máy chủ. Mô hình 'Multiple Internally Synchronized WSUS Servers' là phổ biến nhất, trong đó một máy chủ trung tâm (upstream) kết nối Internet, và các máy chủ ở chi nhánh (downstream) đồng bộ từ máy chủ trung tâm này. Mô hình này giúp tiết kiệm băng thông WAN. Ngoài ra, còn có mô hình 'Disconnected WSUS Servers' cho các mạng có yêu cầu bảo mật cao, không kết nối Internet, nơi các bản cập nhật được xuất ra phương tiện lưu trữ và nhập vào máy chủ WSUS nội bộ theo cách thủ công.

Tóm tắt và mô tả trên trang này được tạo với sự hỗ trợ của AI từ nội dung tài liệu gốc; tài liệu do người dùng đóng góp và được kiểm duyệt trước khi xuất bản. Báo lỗi nội dung.

22/09/2025
Topic researching and deploying windows server update services

Trích đoạn nội dung tài liệu

DA NANG UNIVERSITY VIETNAM-KOREA UNIVERSITY OF INFORMATION AND COMMUNICATION TECHNOLOGY COMPUTER SCIENCE FACULTY FINAL PROJECT NETWORK ADMINISTRATION GROUP 09 TOPIC: RESEARCHING AND DEPLOYING WINDOWS SERVER UPDATE SERVICES Members: Tran Thi Kim Oanh - 19IT3 Nguyen Trung Hieu – 19IT3 Hoang Nguyen Viet Nam – 19IT3 Le Tran Thu Loan – 19IT3 Part Class: Network Administration (3) Instructor: Dr. Dang Quang Hien Da Nang, November 2021 DA NANG UNIVERSITY VIETNAM-KOREA UNIVERSITY OF INFORMATION AND COMMUNICATION TECHNOLOGY COMPUTER SCIENCE FACULTY FINAL PROJECT NETWORK ADMINISTRATION GROUP 09 TOPIC: RESEARCHING AND DEPLOYING WINDOWS SERVER UPDATE SERVICES Members: Tran Thi Kim Oanh - 19IT3 Nguyen Trung Hieu – 19IT3 Hoang Nguyen Viet Nam – 19IT3 Le Tran Thu Loan – 19IT3 Part Class: Network Administration (3) Instructor: Dr. Dang Quang Hien Da Nang, November 2021 PREFACE Information and data play an important role in production and business activities as well as the development of enterprises. One of the important methods to secure information and data is to regularly update patches for Windows operating system and Microsoft software on PCs and Servers.

However, with a relatively large number of PCs and Servers at agencies, the implementation of updating (updating) patches (hotfixes), upgrades for operating systems, and Microsoft's software is a something worthy of attention. Currently, updates for PCs and Servers in offices are largely done manually (updates are done by individual users). This leads to the following problems: o Users do not update patches or perform incomplete patch updates, leading to the risk of being attacked by security holes. The administrator has not been able to control the update status of users' patches, operating systems and Microsoft applications.

o Each user individually updates Microsoft's operating systems and programs, resulting in bandwidth consumption, especially international bandwidth. o In case the Internet connection is slow or interrupted, it will lead to updating operating systems, Microsoft programs for PC and Server take longer, making PC and Server run slower. Therefore, the main solution is to install an intermediate Server (WSUS Server) to update patches from the Internet, then PCs in the LAN connect to this Server to update patches. After implementing this solution, the following goals will be achieved: o All Client computers in the LAN are updated with timely patches, improving security and safety for user computers (Clients).

o The update time of the clients is scheduled in accordance with the LAN performance. o Saving bandwidth for Internet access: Previously, all clients had to access the Internet to update (each update had to download from a few dozen to several hundred Megabytes of data), but now there is only one server. Connect to the Internet to update online while the clients perform updates inside the LAN. Therefore, our group decided to implement the topic: "RESEARCHING AND DEPLOYING WINDOWS SERVER UPDATE SERVICES".

With the efforts and especially the dedicated and thoughtful help of the instructors, Dr. Dang Quang Hien, our group completed the subject project on time. Due to the limited time to do the project and the limited qualifications, it is inevitable that there will be shortcomings. I look forward to receiving comments from teachers as well as from students to improve this project.

Da Nang, November 2021 THANK YOU We would like to sincerely thank the enthusiastic help of the instructor Dr. Dang Quang Hien, who oriented, guided and supported our team during the implementation of this project. We would also like to thank the teachers and lecturers in the University of Information and Communication Technology - UD for providing me with the necessary knowledge to carry out this project. We would also like to thank my family and friends who always encouraged and supported me during my study and research, and contributed valuable experiences during the implementation of this thesis.

We wish the teachers good health, good work, continue to teach and train the young generation successfully. We sincerely thank you! COMMENTS OF INSTRUCTOR. Da Nang, November 2021 Instructor Dr. Dang Quang Hien CONTENT PREFACE.5 LIST OF PICTURES.3 LIST OF ABBREVIATIONS.

1 Objectives of the study.3 WSUS Server Role Description.4 Using Windows PowerShell to Manage WSUS.5 Benefits of WSUS.6 Advantages and disadvantages.7 How to extend WSUS.3 WSUS Deployment Scenarios. STEP BY STEP.1 Install Window Server Update Services (WSUS).2 User Policy Configuration.3 Manage computers in LAN and WSUS Server.33 Check the connection of computers in the LAN to the WSUS Server Check the initial WSUS Server configuration.33 Check WSUS Server Version.35 Synchronize updates from Microsoft Server to WSUS Server.37 Download updates from Microsoft Server to WSUS Server.38 Check the update status of PCs and Servers in LAN.42 Check the update status of PCs and Servers in LAN on WSUS Server.46 LIST OF PICTURES Figure 1. Windows Server Update Services. 1 Paradigms of topic.

2 Single WSUS Server (Small-Sized or Simple Network). 3 Multiple Independent WSUS Servers. 4 Multiple Internally Synchronized WSUS Servers. 5 Disconnected WSUS Servers.

1 Install Window Server Update Services. 2 Install Window Server Update Services. 3 Install Window Server Update Services. 4 Install Window Server Update Services.

5 Install Window Server Update Services. 6 Install Window Server Update Services. 7 Install Window Server Update Services. 8 Install Window Server Update Services.

9 Install Window Server Update Services. 10 Install Window Server Update Services. 11 Install Window Server Update Services. 12 Install Window Server Update Services.

13 Install Window Server Update Services. 14 Install Window Server Update Services. 15 Install Window Server Update Services. 16 Install Window Server Update Services.

17 Install Window Server Update Services. 18 Install Window Server Update Services. 19 Install Window Server Update Services. 20 Install Window Server Update Services.

21 Install Window Server Update Services. 22 Install Window Server Update Services. 23 Install Window Server Update Services. 24 Install Window Server Update Services.

25 Install Window Server Update Services. 26 Install Window Server Update Services. 27 Install Window Server Update Services. 28 Install Window Server Update Services.

29 Install Window Server Update Services. 30 Install Window Server Update Services. 31 User Policy Configuration. 32 User Policy Configuration.

33 User Policy Configuration. 34 User Policy Configuration. 35 User Policy Configuration. 36 User Policy Configuration.

37 User Policy Configuration. 38 User Policy Configuration. 39 User Policy Configuration. 40 Manage computers in LAN and WSUS Server.

41 Manage computers in LAN and WSUS Server. 42 Manage computers in LAN and WSUS Server. 43 Manage computers in LAN and WSUS Server. 44 Manage computers in LAN and WSUS Server.

45 Manage computers in LAN and WSUS Server. 46 Manage computers in LAN and WSUS Server. 47 Manage computers in LAN and WSUS Server. 48 Manage computers in LAN and WSUS Server.

49 Manage computers in LAN and WSUS Server. 50 Manage computers in LAN and WSUS Server. 51 Manage computers in LAN and WSUS Server. 52 Manage computers in LAN and WSUS Server.

53 Manage computers in LAN and WSUS Server. 54 Manage computers in LAN and WSUS Server. 55 Manage computers in LAN and WSUS Server. 56 Manage computers in LAN and WSUS Server.

57 Manage computers in LAN and WSUS Server.44 LIST OF ABBREVIATIONS ID Abbreviations The Meaning Of The Acronym 1 WSUS Windows Server Update Services 2 PC Personal Computer 3 LAN Local Area Network 4 SUS Software Update Services 5 WUA Windows Update Agent 6 SSL Secure Sockets Layer 7 RAM Random Access Memory 8 IT Information Technology 9 ADDS Active Directory Domain Services 10 GPO Group Policy Object Group 09 - RESEARCHING AND DEPLOYING WINDOWS SERVER UPDATE SERVICES PREAMBLE The reason for choosing the topic One of the important methods to secure information and data is to regularly update patches for Windows operating system and Microsoft software on PCs and Servers. However, with a relatively large number of PCs and Servers at agencies, the implementation of updating (updating) patches (hotfixes), upgrades for operating systems, and Microsoft's software is a something worthy of attention. Currently, updating for PCs and Servers in offices is largely done manually (updates are done by each user individually). Therefore, our group decided to implement the topic:"RESEARCHING AND DEPLOYING WINDOWS SERVER UPDATE SERVICES".

Objectives of the study The main solution is to install an intermediate Server (WSUS Server) to update patches from the Internet, then PCs in the LAN connect to this Server to update patches. After implementing this solution, the following goals will be achieved: All Client computers in the LAN are updated with timely patches, improving security and safety for user computers (Clients). The update time of the clients is scheduled in accordance with the LAN performance. Saving bandwidth for Internet access: Previously, all clients had to access the Internet to update (each update had to download from a few dozen to several hundred Megabytes of data), but now there is only one server.

Connect to the Internet to update online while the clients perform updates inside the LAN. Header task This application was created to bring convenience to users as well as to make it easier for large enterprises to manage, fix errors and update new updates for computer systems. Expected results o Knowledge of VMWare, Windows server 2016 operating system. o Understand and understand how it works, as well as deploy and install WSUS o Finalize the topic, deploy and install WSUS 1 Group 09 - RESEARCHING AND DEPLOYING WINDOWS SERVER UPDATE SERVICES After finishing a project, the indispensable thing is a written report on your topic and project presentation slides.

The detailed report presents a reasonable table of contents layout. Structure of the report Chapter 1. Step by step 2 Group 09 - RESEARCHING AND DEPLOYING WINDOWS SERVER UPDATE SERVICES CHAPTER 1.1 WSUS Definition Windows Server Update Services (WSUS) enables information technology administrators to deploy the latest Microsoft product updates. WSUS is a Windows Server server role that can be installed to manage and distribute updates.

A WSUS server can be the update source for other WSUS servers within the organization. The WSUS server that acts as an update source is called an upstream server. In a WSUS implementation, at least one WSUS server in the network must connect to Microsoft Update to get available update information. Windows Server Update Services Using WSUS, a server administrator can approve updates to be downloaded and then installed by groups classifying any number of computers at routinely-scheduled intervals.

WSUS also supports selecting and approving updates at any given time, useful for security issues that must be addressed immediately. Other features of WSUS include: o Automatic approval of frequently updated security classifications (like antivirus definitions released several times a day). o Update management of every Microsoft product released ever. 3 Group 09 - RESEARCHING AND DEPLOYING WINDOWS SERVER UPDATE SERVICES o Management of multiple update classifications at once - Security updates, Windows upgrades, generic updates, software drivers, and even security or management tools.

o Automatic sorting of computers into management groups via Group Policy settings. o Email notifications for update statuses (success and failure to download or install) and timely report roll-ups for scheduled security reviews. o SSL-capable dashboard application for managing WSUS and showing updated information 1.2 History The first version of WSUS was called SUS. At first, it only provided hotfixes and patches for Microsoft operating systems.

SUS runs on the Windows Server operating system and downloads updates for specified versions of Windows from the remote Windows Update website operated by Microsoft. Customers can then download updates from this internal server, instead of connecting directly to Windows Update. Microsoft originally planned to end support for SUS on December 6, 2006, but based on user feedback, the deadline was extended to July 10, 2007. WSUS builds on SUS by expanding the range of software it can update.

The WSUS infrastructure enables automatic download of updates, hotfixes, service packs, device drivers, and feature packs to customers in one hosted from a central server or a multi- server system.3 WSUS Server Role Description Windows Server Update Services (WSUS) enables information technology administrators to deploy the latest Microsoft product updates.

Nội dung được bảo vệ bản quyền — Tải xuống đầy đủ