problema con GPO y Wsus

18/12/2008 - 21:49 por fran | Informe spam
Hola tengo el siguiente problema:

en un equipo en particular no se me aplica la GPO q cree para conectarlo con
mi server wsus (q se q funciona bien pq ya me esta viendo casi todos los PCs
de mi red).

cuando corro el diagnostico para clientes (ClientDiag.exe), al final me
aparece este error:

"Checking Connection to WSUS/SUS Server
AU does not have Policy Set
AU does not have Policy Set
UseWuServer is disabled . . . . . . . . . . . . . . . . FAIL"

Lei, q antes q nada debo saber si se estan aplicando la GPO, asi q corro un
gpresult /v, y me arroja esto:


****************************************************inicio del
reporte******************************************************************

Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001

Created On 18/12/2008 at 05:42:40 p.m.



RSOP results for IV\FAGUERO on FAGUERO : Logging Mode


OS Type: Microsoft Windows XP Professional
OS Configuration: Member Workstation
OS Version: 5.1.2600
Domain Name: IV
Domain Type: Windows 2000
Site Name: Default-First-Site-Name
Roaming Profile:
Local Profile: C:\Documents and Settings\faguero
Connected over a slow link?: No


COMPUTER SETTINGS

CNúGUERO,CN=Computers,DC=iv,DC=institutovida,DC=com,DC=ar
Last time Group Policy was applied: 18/12/2008 at 05:36:46 p.m.
Group Policy was applied from: slaf-is06.iv.institutovida.com.ar
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
Default Domain Policy
Local Group Policy

The following GPOs were not applied because they were filtered out
-
Prueba
Filtering: Denied (Security)

The computer is a part of the following security groups:
BUILTIN\Administrators
Everyone
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
FAGUERO$
Domain Computers

Resultant Set Of Policies for Computer:
-

Software Installations
-
N/A

Startup Scripts

N/A

Shutdown Scripts
-
N/A

Account Policies
-
GPO: Default Domain Policy
Policy: MinimumPasswordAge
Computer Setting: 1

GPO: Default Domain Policy
Policy: PasswordHistorySize
Computer Setting: 5

GPO: Default Domain Policy
Policy: LockoutDuration
Computer Setting: 4294967295

GPO: Default Domain Policy
Policy: ResetLockoutCount
Computer Setting: 99999

GPO: Default Domain Policy
Policy: MinimumPasswordLength
Computer Setting: 8

GPO: Default Domain Policy
Policy: LockoutBadCount
Computer Setting: 3

GPO: Default Domain Policy
Policy: MaximumPasswordAge
Computer Setting: 30

Audit Policy

GPO: Default Domain Policy
Policy: AuditPolicyChange
Computer Setting: Success, Failure

GPO: Default Domain Policy
Policy: AuditPrivilegeUse
Computer Setting: Failure

GPO: Default Domain Policy
Policy: AuditDSAccess
Computer Setting: Success, Failure

GPO: Default Domain Policy
Policy: AuditAccountLogon
Computer Setting: Success, Failure

GPO: Default Domain Policy
Policy: AuditObjectAccess
Computer Setting: Success, Failure

GPO: Default Domain Policy
Policy: AuditAccountManage
Computer Setting: Success, Failure

GPO: Default Domain Policy
Policy: AuditLogonEvents
Computer Setting: Success, Failure

GPO: Default Domain Policy
Policy: AuditSystemEvents
Computer Setting: Success, Failure

User Rights
N/A

Security Options
-
GPO: Default Domain Policy
Policy: RequireLogonToChangePassword
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: PasswordComplexity
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: ForceLogoffWhenHourExpire
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: ClearTextPassword
Computer Setting: Not Enabled

Event Log Settings

N/A

Restricted Groups
N/A

System Services

GPO: Default Domain Policy
ServiceName: Messenger
Startup: disabled

Registry Settings
N/A

File System Settings
N/A

Public Key Policies
-
N/A

Administrative Templates

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled

GPO: Local Group Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled

GPO: Local Group Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled


USER SETTINGS
CN=Francisco Aguero,CN=Users,DC=iv,DC=institutovida,DC=com,DC=ar
Last time Group Policy was applied: 18/12/2008 at 05:36:46 p.m.
Group Policy was applied from: slaf-is06.iv.institutovida.com.ar
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
Default Domain Policy
Prueba

The following GPOs were not applied because they were filtered out
-
Local Group Policy
Filtering: Not Applied (Empty)

The user is a part of the following security groups:
-
Domain Users
Everyone
BUILTIN\Administrators
BUILTIN\Users
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users
LOCAL
G_SISTEMASALTA
G_TECNOLOGIA
G_INSTITUTODESALTA

Resultant Set Of Policies for User:


Software Installations
-
N/A

Public Key Policies
-
N/A

Administrative Templates

GPO: Prueba
Setting:
Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop
State: Enabled

GPO: Prueba
Setting:
Software\Microsoft\Windows\CurrentVersion\Policies\System
State: Enabled

GPO: Prueba
Setting:
Software\Microsoft\Windows\CurrentVersion\Policies\System
State: Enabled

GPO: Prueba
Setting:
Software\Microsoft\Windows\CurrentVersion\Policies\System
State: Enabled

Folder Redirection

N/A

Internet Explorer Browser User Interface
-
N/A

Internet Explorer Connection
-
N/A

Internet Explorer URLs
-
N/A

Internet Explorer Security
N/A

Internet Explorer Programs

*******************************************************fin del
reporte***************************************************************

Hay dos cosas q me llaman la atencion:
una q dice q el tipo de dominio es windows 2000, cuando en realidad es 2003.
Ademas hace relacion a una GPO llamada Prueba q era justamente eso, y q
elimine hace varios dias.

No se como hacer para q este equipo en cuestion, "vea" la GPO q aplica el
WSUS.

Agradeceria alguna ayuda!

PD: la GPO q deberia aplicar se llama "Wsus sistemas" y ni siquiera se
menciona...
 

Leer las respuestas

#1 Desiderio Ondo.
23/12/2008 - 11:52 | Informe spam
Hola, Fran:

Para que una GPO a nivel de dominio se aplique en una determinada
workstation, ha de cumplirse 2 condiciones básicas (entre otras):
.- <workstation> ha de estar registrado en el entorno de dominio.
Es muy importante revisar que la configuración <DNS> sea correcta
para ello y/o comprobar que la cuenta de máquina es operativa (la
consola DSA.msc del <DC> te podrá dar información al respecto).

.- GPO ha de estar habilitado para dicha <workstation>, ya sea para
el objeto de cuenta de máquina y/o objeto de usuario que logue en
el mismo.

En todo caso, por lo que veo en el .log, se están aplicando las GPO
"Default Domain Policy" y "Local Group Policy", denegándose que se
aplique la "Prueba" por falta de credenciales, lo que me hace pensar
que existen algunos problemas con la cuenta de máquina...

Así a primeras, insisto en que mires el tema de las DNS's...
·
Ya nos contarás cómo te ha ido...
==Desiderio Ondo | Ing. en Informática.
Certificado ITIL | MCSE MS-w2K3.
http://pantuflo.escet.urjc.es/~desitech


"fran" wrote:

Hola tengo el siguiente problema:

en un equipo en particular no se me aplica la GPO q cree para conectarlo con
mi server wsus (q se q funciona bien pq ya me esta viendo casi todos los PCs
de mi red).

cuando corro el diagnostico para clientes (ClientDiag.exe), al final me
aparece este error:

"Checking Connection to WSUS/SUS Server
AU does not have Policy Set
AU does not have Policy Set
UseWuServer is disabled . . . . . . . . . . . . . . . . FAIL"

Lei, q antes q nada debo saber si se estan aplicando la GPO, asi q corro un
gpresult /v, y me arroja esto:


****************************************************inicio del
reporte******************************************************************

Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001

Created On 18/12/2008 at 05:42:40 p.m.



RSOP results for IV\FAGUERO on FAGUERO : Logging Mode


OS Type: Microsoft Windows XP Professional
OS Configuration: Member Workstation
OS Version: 5.1.2600
Domain Name: IV
Domain Type: Windows 2000
Site Name: Default-First-Site-Name
Roaming Profile:
Local Profile: C:\Documents and Settings\faguero
Connected over a slow link?: No


COMPUTER SETTINGS

CNúGUERO,CN=Computers,DC=iv,DC=institutovida,DC=com,DC=ar
Last time Group Policy was applied: 18/12/2008 at 05:36:46 p.m.
Group Policy was applied from: slaf-is06.iv.institutovida.com.ar
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
Default Domain Policy
Local Group Policy

The following GPOs were not applied because they were filtered out
-
Prueba
Filtering: Denied (Security)

The computer is a part of the following security groups:
BUILTIN\Administrators
Everyone
BUILTIN\Users
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
FAGUERO$
Domain Computers

Resultant Set Of Policies for Computer:
-

Software Installations
-
N/A

Startup Scripts

N/A

Shutdown Scripts
-
N/A

Account Policies
-
GPO: Default Domain Policy
Policy: MinimumPasswordAge
Computer Setting: 1

GPO: Default Domain Policy
Policy: PasswordHistorySize
Computer Setting: 5

GPO: Default Domain Policy
Policy: LockoutDuration
Computer Setting: 4294967295

GPO: Default Domain Policy
Policy: ResetLockoutCount
Computer Setting: 99999

GPO: Default Domain Policy
Policy: MinimumPasswordLength
Computer Setting: 8

GPO: Default Domain Policy
Policy: LockoutBadCount
Computer Setting: 3

GPO: Default Domain Policy
Policy: MaximumPasswordAge
Computer Setting: 30

Audit Policy

GPO: Default Domain Policy
Policy: AuditPolicyChange
Computer Setting: Success, Failure

GPO: Default Domain Policy
Policy: AuditPrivilegeUse
Computer Setting: Failure

GPO: Default Domain Policy
Policy: AuditDSAccess
Computer Setting: Success, Failure

GPO: Default Domain Policy
Policy: AuditAccountLogon
Computer Setting: Success, Failure

GPO: Default Domain Policy
Policy: AuditObjectAccess
Computer Setting: Success, Failure

GPO: Default Domain Policy
Policy: AuditAccountManage
Computer Setting: Success, Failure

GPO: Default Domain Policy
Policy: AuditLogonEvents
Computer Setting: Success, Failure

GPO: Default Domain Policy
Policy: AuditSystemEvents
Computer Setting: Success, Failure

User Rights
N/A

Security Options
-
GPO: Default Domain Policy
Policy: RequireLogonToChangePassword
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: PasswordComplexity
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: ForceLogoffWhenHourExpire
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: ClearTextPassword
Computer Setting: Not Enabled

Event Log Settings

N/A

Restricted Groups
N/A

System Services

GPO: Default Domain Policy
ServiceName: Messenger
Startup: disabled

Registry Settings
N/A

File System Settings
N/A

Public Key Policies
-
N/A

Administrative Templates

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled

GPO: Local Group Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled

GPO: Local Group Policy
Setting: Software\Policies\Microsoft\Windows\WindowsUpdate
State: Enabled

GPO: Local Group Policy
Setting:
Software\Policies\Microsoft\Windows\WindowsUpdate\AU
State: Enabled


USER SETTINGS
CN=Francisco Aguero,CN=Users,DC=iv,DC=institutovida,DC=com,DC=ar
Last time Group Policy was applied: 18/12/2008 at 05:36:46 p.m.
Group Policy was applied from: slaf-is06.iv.institutovida.com.ar
Group Policy slow link threshold: 500 kbps

Applied Group Policy Objects
Default Domain Policy
Prueba

The following GPOs were not applied because they were filtered out
-
Local Group Policy
Filtering: Not Applied (Empty)

The user is a part of the following security groups:
-
Domain Users
Everyone
BUILTIN\Administrators
BUILTIN\Users
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users
LOCAL
G_SISTEMASALTA
G_TECNOLOGIA
G_INSTITUTODESALTA

Resultant Set Of Policies for User:


Software Installations
-
N/A

Public Key Policies
-
N/A

Administrative Templates

GPO: Prueba
Setting:
Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop
State: Enabled

GPO: Prueba
Setting:
Software\Microsoft\Windows\CurrentVersion\Policies\System
State: Enabled

GPO: Prueba
Setting:
Software\Microsoft\Windows\CurrentVersion\Policies\System
State: Enabled

Preguntas similares