04-03-2019 10:16 AM
Hi Team,
I have a question regarding opening up the clients to Microsoft updates. Before the clients are compliant they are only allowed access to the ISE server and dns/dhcp servers. Does that mean I have to modify the redirect ACL in the ASA to allow the Microsoft update servers or DACL from ISE? Also, Microsoft only provides FQDNs for the update servers. They do not provide any IP addresses and they also use wildcards. How can this be implemented in the ACLor DACL? Please advice.
Any help would be appreciated.
Regards
Gagan
04-03-2019 12:22 PM
04-03-2019 12:28 PM
Hi, I believe you can only check for Microsoft Updates from an internally hosted WSUS or SCCM server.
HTH
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide