GFI LanGuard is able to use the repository of a WSUS server in the network.
When this feature is enabled, GFI LanGuard will use the WSUS server as an additional repository for updates. The updates will be copied directly from the WSUS Server to the target machines being remediated. GFI LanGuard will not copy the updates to its repository.
If an update is not available in WSUS repository and it is downloaded by GFI LanGuard, then the patch will be saved into GFI LanGuard repository and not the WSUS repository. In this situation, if the update is downloaded by WSUS at a later stage, the same update will be found in both repositories.
Note: For secure environments see the article: How to update GFI LanGuard if in a secure network
To configure this in GFI LanGuard, perform the following procedure:
- Open the GFI LanGuard configuration
- Click on the 'Configuration' tab
- Expand the 'Software Updates' node
- Right click the 'Patch Auto-Download' node and select 'Edit patch auto-download options...'
- Select the 'Patch Repository' tab and enable 'Use files downloaded by WSUS when available'
- Specify the path of the WSUS content folder
Configure the WSUS server as follows:
- Enable patch "Auto-approval"
- If the WSUS server resides on a different domain than the GFI LanGuard Attendant Service account you may have to use the following procedure to allow access:
- Enable the guest account.
- Add the everyone group to both the share and the security permissions.
- In the local security policy editor (secpol.msc) configure the following policies:
- Network Access: Named Pipes that can be accessed anonymously = (add) sharename
- Network Access: Shares that can be accessed anonymously = (add) sharename