请教关于域组策略生效不生效的解决方法

查看:5911|回复:10
1.已安装完WSUS
2.在服务器上设置组策略。(计算机策略,配置自动更新 指定Intranet Microsoft更新服务器位置)
3.但在客户端怎么没反应呢,也提示不到什么更新。请教。
本帖最后由 不明飞行物 于
19:11 编辑
看一下系统分区Windows目录中的WindowsUpdate.log日志文件中有什么记录.
请把它发上来
面带微笑,春暖花开
11:56:00:203&&844 d60 PT WARNING: ReportEventBatch failure, error = 0x8024400D, soap client error = 7, soap error code = 300, HTTP status code = 200
11:56:00:203&&844 d60 PT WARNING: SOAP Fault: 0x00012c
11:56:00:203&&844 d60 PT WARNING:& &&&faultstring:System.Web.Services.Protocols.SoapException: Fault occurred
& &at Microsoft.UpdateServices.Internal.SoapUtilities.ThrowException(ErrorCode errorCode, String message)
& &at Microsoft.UpdateServices.Internal.Authorization.AuthorizationManager.CrackCookie(Cookie cookie)
& &at Microsoft.UpdateServices.Internal.Reporting.WebService.ReportEventBatch(Cookie cookie, DateTime clientTime, ReportingEvent[] eventBatch)
11:56:00:203&&844 d60 PT WARNING:& &&&ErrorCode:ConfigChanged(2)
11:56:00:203&&844 d60 PT WARNING:& &&&Message:
11:56:00:203&&844 d60 PT WARNING:& &&&Method:&&
11:56:00:203&&844 d60 PT WARNING:& &&&ID:fe37f437-c-99f2-1a50af853d68
11:56:00:203&&844 d60 Report WARNING: Reporter failed to upload events with hr = 8024400d.
12:13:17:062&&844 b84 PT WARNING: Cached cookie has expired or new PID is available
12:13:17:062&&844 b84 PT Initializing simple targeting cookie, clientId = -055a-497c-bad7-7decfedffd1b, target group = , DNS name =
12:13:17:062&&844 b84 PT& &Server URL =
12:13:31:703&&844 b84 PT WARNING: GetCookie failure, error = 0x8024400D, soap client error = 7, soap error code = 300, HTTP status code = 200
12:13:31:703&&844 b84 PT WARNING: SOAP Fault: 0x00012c
12:13:31:703&&844 b84 PT WARNING:& &&&faultstring:System.Web.Services.Protocols.SoapException: Fault occurred
& &at Microsoft.UpdateServices.Internal.SoapUtilities.ThrowException(ErrorCode errorCode, String message)
& &at Microsoft.UpdateServices.Internal.ClientImplementation.GetCookie(AuthorizationCookie[] authCookies, Cookie oldCookie, DateTime lastChange, DateTime currentClientTime, String protocolVersion)
& &at Microsoft.UpdateServices.Internal.Client.GetCookie(AuthorizationCookie[] authCookies, Cookie oldCookie, DateTime lastChange, DateTime currentTime, String protocolVersion)
12:13:31:703&&844 b84 PT WARNING:& &&&ErrorCode:ConfigChanged(2)
12:13:31:703&&844 b84 PT WARNING:& &&&Message:
12:13:31:703&&844 b84 PT WARNING:& &&&Method:&&
12:13:31:703&&844 b84 PT WARNING:& &&&ID:cf7969ff-700b-48ff-b983-279a84e1834d
12:13:31:750&&844 b84 PT WARNING: Cached cookie has expired or new PID is available
12:13:31:750&&844 b84 PT Initializing simple targeting cookie, clientId = -055a-497c-bad7-7decfedffd1b, target group = , DNS name =
12:13:31:750&&844 b84 PT& &Server URL =
12:13:31:828&&844 b84 Report Uploading 2 events using cached cookie, reporting URL =
12:13:31:843&&844 b84 Report Reporter successfully uploaded 2 events.
12:58:06:859&&844 790 AU AU received policy change subscription event
12:58:06:859&&844 790 AU AU Options changed from policy.
12:58:06:859&&844 790 AU ###########&&AU: Policy change processed&&###########
12:58:06:859&&844 790 AU& &# Policy changed, AU refresh required = No
12:58:06:859&&844 790 AU& &# WSUS server:
12:58:06:859&&844 790 AU& &# Detection frequency: 22
12:58:06:859&&844 790 AU& &# Approval type: Pre-download notify (Policy)
12:58:06:859&&844 790 AU AU settings changed through Policy.
12:58:24:750&&844 790 AU AU received policy change subscription event
本帖最后由 mqlbeyond 于
14:03 编辑
只有管理员才能更新系统吗?
1.刚才用域普通用户,一直都无法更新
2.注销,换域admin用户,马上提示系统有更新。
使命的召唤-全能IT艺术家 ...
晕倒.普通用户就想执行系统权限?呵呵~
一剑舞动惊四方,IT本是我所长 (R)丁胖胖
那要想在域环境中部署WSUS服务,所有客户端还必须要有管理员权限去执行吗?
岂不是太危险了!微软估计也没这么傻吧!:lol
中级工程师
在组策略里设备允许非管理员用户接收更新通知
问题已解决。
虚拟机网络不通导致不能联系域控制器,经排错更改网络都可互ping,WSUS部署一切正常。谢谢大家。
我也遇到同样问题,无法解决
什么问题呢?
服务端能看到客户端,也能看到客户端需要的补丁个数,但是客户端不能下载更新(就是客户端更新的哪个图标不出来),多次运行wuauclt /detectnow,客户端也没有出现提示更新。
我在想是不是因为服务器刚部署才一天,服务端下载更新文件没有下载完导致的不更新,服务端的“需要更新文件下载状态共40G,当前共下载6G”
多次运行wuauclt /detectnow 产生的日志
& & & & 11:44:58:750& & & & 1308& & & & 4d8& & & & Agent& & & && &* Found 0 updates and 45
evaluated appl. rules of 624 out of 995 deployed entities
& & & & 11:44:58:765& & & & 1308& & & & 4d8& & & & Agent& & & & *********
& & & & 11:44:58:765& & & & 1308& & & & 4d8& & & & Agent& & & & **&&END&&**&&Agent: Finding updates [CallerId = AutomaticUpdates]
& & & & 11:44:58:765& & & & 1308& & & & 4d8& & & & Agent& & & & *************
& & & & 11:44:58:781& & & & 1308& & & & cf8& & & & AU& & & & &&##&&RESUMED&&## AU: Search for updates [CallId = {4EDFB83C-778E-B-A6DC93ADADF5}]
& & & & 11:44:58:781& & & & 1308& & & & cf8& & & & AU& & & && &# 0 updates detected
& & & & 11:44:58:781& & & & 1308& & & & cf8& & & & AU& & & & #########
& & & & 11:44:58:781& & & & 1308& & & & cf8& & & & AU& & & & ##&&END&&##&&AU: Search for updates [CallId = {4EDFB83C-778E-B-A6DC93ADADF5}]
& & & & 11:44:58:781& & & & 1308& & & & cf8& & & & AU& & & & #############
& & & & 11:44:58:781& & & & 1308& & & & cf8& & & & AU& & & & Featured notifications is disabled.
& & & & 11:44:58:781& & & & 1308& & & & cf8& & & & AU& & & & AU setting next detection timeout to组策略和控制台_百度文库
两大类热门资源免费畅读
续费一年阅读会员,立省24元!
组策略和控制台
上传于|0|0|暂无简介
你可能喜欢查看:318|回复:0
拓扑如图,现在想让10.64.37.35这台电脑上网从AR2出去,在AR1上做了策略路由,但是没成功,请帮忙看一下啥原因。AR1配置如下:
&AR1&dis cur
[V200R005C20SPC200]
sysname AR1
drop illegal-mac alarm
ip local policy-based-route pbr1
wlan ac-global carrier id other ac id 0
pki realm default
enrollment self-signed
acl number 3005&&
rule 0 permit ip source 10.64.37.35 0
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default&&
domain default_admin&&
local-user admin password irreversible-cipher %@%@wHE|3YbZ%9fEeZX;);|GtGtGm$.W&Jg;ZW_4Dh&5-BzIGtJt%@%@
local-user admin privilege level 3
local-user admin service-type telnet terminal http
firewall zone Local
priority 128
interface MEth0/0/0
interface GigabitEthernet0/0/0
ip address 10.64.207.2 255.255.255.252
interface GigabitEthernet0/0/1
ip address 10.64.252.134 255.255.255.252
interface GigabitEthernet0/0/2
interface GigabitEthernet0/0/3
interface GigabitEthernet0/0/3.121
description to S5700
dot1q termination vid 121
ip address 10.64.207.49 255.255.255.252
interface XGigabitEthernet0/0/0
interface XGigabitEthernet0/0/1
interface Cellular0/0/0
interface NULL0
snmp-agent local-engineid FCE33CA76F5A
ip route-static 0.0.0.0 0.0.0.0 10.64.207.1
ip route-static 0.0.0.0 0.0.0.0 10.64.252.133 preference 80
ip route-static 10.64.37.0 255.255.255.0 10.64.207.50
user-interface con 0
authentication-mode password
set authentication password cipher %@%@B:$1&rUXd,KCK}&q8Q5G,.&'d`N79s)2nYCSaZ5:k4aI.&*,%@%@
user-interface vty 0 4
authentication-mode aaa
policy-based-route pbr1 permit node 0
if-match acl 3005
apply ip-address next-hop 10.64.252.133
(42.32 KB)查看:1625|回复:2
高级工程师
请教各位:
组策略的执行顺序是否为:
域组策略--》OU策略--》子OU策略,---》本地策略,
所以最后本地策略会覆盖OU的策略成为优先级最高的呀?
我忘记了本地策略是最高还是最低的了。
本地-&站点-&域-&OU-&子OU
如果策略有冲突,则后应用的生效
高级工程师
谢谢指导。

我要回帖

更多关于 组策略生效时间 的文章

 

随机推荐