14 September 2011

Unable to use Windows Updates on Windows Server 2008 R2 SP1 behind a WatchGuard Firewall


I recently installed Windows 2008 R2 Enterprise SP1 on an older Dell PowerEdge 2950. Dell does not make a server update and build utility for 2008 R2 on old PowerEdges. I manually initialized the RAID-5 array and booted to the 2008 install DVD. Windows found all the hardware and everything seemed to be running great until I was unable to successfully install Windows Updates with error 80072EFE. After 3 days of searching everywhere, a MS Knowledgebase article that explained the 80072EFE error as ERROR_INTERNET_CONNECTION_ABORTED.

We have two HTTP policies set in our WatchGuard XTM510 firewall. One is very restrictive and applies to most clients and devices on our network. The second policy is much less restrictive and allows more liberal access to http resources. We only use the second policy when there is an access issue for a user that we cannot resolve by adding application types of bypassed URLs to the policy.

Windows 2008 R2 SP1's Windows Update components must be more "sensitive" to the deep inspection that takes place in our first policy. Windows Updates would fail everything under policy 1, but when I added the server's host IP to policy 2, the updates ran perfectly.