That's because Microsoft uses some 3rd party 'load balancing' companies that
have servers all over the place, on multiple subnets. It's to minimize
spikes due to popular downloads or DDoS attacks. I guess you could put in
every IP that currently resolves to those DNS names, but of course this
could change on a regular basis and it's possible that these hosting
companies don't even notify Microsoft (since Microsoft has contracted it
out.)
One idea for you is to deploy SUS... which basically lets you have your own
Windows Update Server (while also giving you some control over which patches
get deployed.) Of course, your SUS server would need to be able to talk to
the Microsoft servers but you could just stick that box in a DMZ.
Want to reply to this thread or ask your own question?
You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.