2. 2
Agenda
» Disconnected Network Scenario
» Patch Management enhancements for Disconnected Operations
» The Challenge
» Installing servers from disconnected Network
» Creating Scope Objects on PAS for SAS
» Deploy SAS to connected Network
SOLARWINDS PATCH MANAGER
4. 4
SolarWinds Patch Manager
» SolarWinds Patch Manager is an affordable, easy to use tool
for simplifying and automating patch management across
tens of thousands of servers and workstations.
» It lets you leverage and extend the capabilities of Microsoft®
WSUS and SCCM to report, deploy, and manage Microsoft
and third-party patches.
SOLARWINDS PATCH MANAGER
5. 5
Patch Manager Enhancements for Disconnected
Operations
» Advantages of Patch Manager compared to WSUS:
• WSUS requires you to export all of the updates in the
catalog whereas Patch Manager allows you to export one,
some or all updates
• WSUS requires you to export metadata separately from the
installation files; Patch Manager allows you to bundle
them in the same CAB file for transport on removable
media
SOLARWINDS PATCH MANAGER
6. 6
The Challenge
» The Licensing challenge:
• A 250-node license for a two-client installation of Patch Manager might not be
the best solution for a disconnected network.
• If you were willing to forego telephone support for that connected server, you
could use a 50-node installation of Patch Manager, but not for a network as
small as a two-node network.
» The Eureka moment:
• We have found a work-around for you. Don’t buy a separate license for your
single-node connected network.
• With a bit of creative use of Patch Manager server roles, you can license that
connected server as a node of the license applied to the disconnected server.
• Let’s look at how this is done in the following slides.
SOLARWINDS PATCH MANAGER
7. 7
Installing Both Servers from Disconnected
Network
» On the disconnected network, install the Patch Manager
Primary Application Server (PAS).
» This is the server that will be used to manage the WSUS
server in the disconnected network, as well as the clients of
the disconnected network.
SOLARWINDS PATCH MANAGER
8. 8
Installing Both Servers from Disconnected
Network (Contd…)
» Further, on the disconnected network, install a Patch
Manager Secondary Application Server (SAS) with the
Management Server role.
» This server will be registered with the PAS, and as such, will
be automatically licensed for use by the license applied to
the PAS.
» Note that this can be either a physical system or a virtual
machine.
» When we’re ready to put this SAS in service, it’s just a matter
of transporting the physical system (or virtual machine files)
across the network gap and plugging it into the connected
network.
SOLARWINDS PATCH MANAGER
9. 9
Creating Scope Objects on PAS for SAS
SOLARWINDS PATCH MANAGER
» The PAS replicates all defined scope objects (Domains,
Workgroups, WSUS Servers, and Computers) to the SAS.
» In order to get the connected WSUS server registered on the
SAS, the WSUS server scope object must be created at the
PAS and replicated before moving the SAS to the connected
network.
» From the Patch Manager System Configuration node, in the
Details Pane, double-click on Scope Management. Click on
Add Rule, and select Update Services Server.
10. 10
Creating Scope Objects on PAS for SAS (Contd...)
» Use the “Enter the object to add” button to manually create an entry for the
connected WSUS server, and click on Save. In a couple of minutes, that scope
declaration will replicate to the SAS.
» You can access the Scope Management tool on the SAS to confirm. You may also
wish to add the Domain or Workgroup for the connected network.
SOLARWINDS PATCH MANAGER
11. 11
Deploy SAS to Connected Network
» Once the replication is completed and the SAS moved to the connected
network, the connected WSUS server can be registered on the SAS and
added to the management group defined on the SAS.
» Credentials, Credential Rings, Security Role memberships, and User
Preferences are all entities defined at each individual application server,
so you can create those directly on the SAS at any time, before or after
actual deployment to the connected network.
» If you’re not currently using Patch Manager and you have a
disconnected network environment, check it out.
SOLARWINDS PATCH MANAGER
12. 12
Next steps on Patch Management
» SolarWinds Patch Manager is an affordable, easy to use tool for
Microsoft® and third-party patch management across tens of thousands
of servers and workstations.
» It lets you leverage and extend the capabilities of Microsoft® WSUS and
SCCM to report, deploy, and manage Microsoft and third-party patches.
12
SOLARWINDS PATCH MANAGER
Check out the community dedicated to various
topics on Patch Management
Watch this video for an introduction
to SolarWinds Patch Manager
Try SolarWinds Patch Manager