In response to customers on the forums, we've been looking into ISA configuration for the Internet-based software update point. The following steps detail how Adam got this working on ISA 2006, and we will request that the ISA documentation How to Configure ISA SSL Bridging for System Center Configuration Manager Internet-Based Client Management is updated with this information. In summary:
· When you are using the WSUS Administration custom Web site rather than the default Web site, make sure you change the port number from 443 in the Web listener and the Web publishing rule. The default port number for the WSUS Administration custom Web site is 8531.
· WSUS does not use client authentication, so No Authentication should be configured in the Web listener. This is a different configuration from the other Internet-based site systems, and so will require a new HTTPS Web listener.
When you have followed the instructions in the ISA guide, use the instructions below to configure a new Web listener for the Internet-based software update point.
Update June 18th 2009: With the help and confirmation from Jason Jones (MVP Forefont), we have revised these instructions to no longer select a security group when creating the Web publishing rule.
- Carol
This posting is provided AS IS with no warranties and confers no rights.
To Create the Web Listener for the Internet-based Software Update Point:
a. If you want the Web listener to operate on a specific IP address within the selected network (recommended), perform the following actions: Select the required network, and then click Select IP Address.
b. On the <Network Name> Listener IP Selection page, select Specified IP addresses on the ISA Server computer in the selected network.
c. Select the required IP address, and then click Add. Repeat steps a through c for each network selected for this Web listener.
8. Click OK, and then click Next.
9. On the Listener SSL Certificates page, select Use a single certificate for this web listener, and then click Select Certificate.
10. On the Select Certificate dialog box, select the ISA Server Web listener certificate, click Select, and then click Next.
11. On the Authentication Settings page, select No Authentication from the Select how clients will provide credentials to ISA Server list.
12. Click Next, click Next, and then click Finish.
13. If you are prompted to enable the system policy that allows CRL downloads, click Yes.
To Modify the Web Listener for the Internet-based Software Update Point:
To Create the Web Publishing Rule for the Internet-based Software Update Point:
To Modify the Web Publishing Rule Port for the Internet-based Software Update Point:
To Save the Web Publishing Changes to ISA Policies for the Internet-based Software Update Point: