Patch Management Solution

 View Only
  • 1.  Patch Management and Maintenance Windows

    Posted Feb 08, 2019 12:51 PM

    Can someone calrify how I would set up my default software update policy to run on weekends at 1:00am, but only allow the package itself to stage M-F 8:00pm-6:00am to prevent bandwidth issues?

    I set a maintenance window but the issue is the patch policy was executing immediately after the download of the package, then trying to install and reboot. Basically the software update poliy is overridden.

    I went to the eEfault software update policy and there are two options 1) Override the maintenance window settings when installing updates and 2) Override the maintenance window settings when preparing to install. I am not totally clear on what these do. I used the first option thinking it would at least download and stage the page, but then kick off on the normal schedule for the policy. Now my patch is just setting in a state of "pending".

    How do I control when the packages, more specifically software updates, go out? Is the only way with blockouts and not overrides?



  • 2.  RE: Patch Management and Maintenance Windows
    Best Answer

    Broadcom Employee
    Posted Feb 12, 2019 02:58 AM

    Hi Brandon!

    Open "Default Software Update Plug-in Policy" policy and click F1 keyboard button, then help page will be opened where you can find details about each option or check direct URL to this help page: https://help.symantec.com/cs/ITMS8.1/Patch/AeXNSPMAgentPolicy/title?locale=EN_US

    Part of help page as example below:

    Best regards,

    IP.