Configuring Microsoft Windows Server Update Services for the industrial zone

In order to get updates from the Microsoft update servers on the Internet down to systems in the industrial zone, we are going to install a server in the IDMZ. We will also create firewall rules that allow access from the WSUS server to the Internet and rules that allow access to the WSUS server in the IDMZ from systems on the industrial network in order to be able to run Windows updates. From a high-level view, this is what the solution will look like:

The following are instructions for getting this WSUS architecture set up.

Get Industrial Cybersecurity now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.