You are both right.

Yes, if you attempt to impersonate the Windows update site it will not

Yes, you can redirect a request for to and let them use that for updates, so long as you don't
try to impersonate the Windows Update site.

My suggestion would be to use SquidGuard to redirect these users to a
page explaining that they should use the SUS site instead. This will
work just fine.=20

At 20.08 21/02/2004, Scott Phalen wrote:

>My original question is dealing with SQUID. All I am asking here is=20
>can a URL be redirected?
>I have been running MSUS for almost a year now. I TOO KNOW HOW IT

>75% of my clients are configured to get updates from my two servers. =20
>The other 25% go directly to Microsoft.
>Security Features in the Software Update Services solution
> Software Update Services. A server running SUS can download packages=20
>from either the public Microsoft Windows Update servers or from another

>server running SUS. During any of these downloads, there is no=20
>server-to-server authentication carried out. All content downloaded by=20
>SUS is signed by Microsoft. SUS does not trust any content that is not=20
>signed or is incorrectly signed. Since SUS 1.0 Service Pack 1 supports=20
>only Windows critical updates and security rollups, all content is=20
>checked to see that it has a been correctly signed by Microsoft.
> Automatic Updates client. The Automatic Updates client can download=20
>packages from either the public Windows Update site or from a server=20
>running SUS. Before installing any packages that have been downloaded,=20
>SUS checks to confirm that the package has been signed by Microsoft. If

>the package is not correctly signed, it will not be installed.

Ok, You say that You know all, so You don't need any recommendations
from me ... :-)

So, please try an let to know to the list if You are right.



