Patch cache is a location within a customer environment where the probe downloads and stores Windows and third party patches for future distribution to the client devices as defined by the patch profile. Using the patch cache alleviates heavy network and bandwidth use when many devices downloading patch files by directing all patch downloads from a single local source.
A patch cache is typically one of the probes or the only probe in your customer's environment.
If you have a small group of devices you do not need a probe cache. You can set up a patch profile that instructs devices to go directly to Windows Update for their patches. For more information, see Patch management profiles.
If you have a large environment or have a number of roaming devices, increase the cache size to 60 GB from the default 40 GB. This ensures that required patches are available for the roaming devices when they connect with the network after a few weeks. You can also configure firewall rules to ensure roaming devices only connect to the local probe relative to the device's location.
Downloaded patches remain in the cache folder to ensure any new devices have immediate access to the required patches. To maintain cache size, Patch Manager deletes the oldest cached files as required when the cache storage is near capacity.
Modify the patch caching options
- At the SO or Customer level, click Configuration > Patch Management.
- In the Patch Caching section, click Manage Probes.
- Click the probe name and click the Caching tab.
- Set the probe caching parameters and click Save.
The Monitoring Data Persistence options are not related to the patch cache.
Once the probe reaches the cache size limit, it overwrites the oldest or newest data, depending on your configuration. The cache location can be any UNC path in your environment that can accommodate a large volume of data.
Google Chrome patching is not supported on Windows 2008 and Windows 2008 R2.
N-able recommends that you determine where you want to locate the cache and set it before patch management goes live in that environment. If you decide to change the location, N-able N-central begins moving the data to the new location immediately, which could cause issues if patch updates are occurring. Avoid changing the location multiple times in a short period of time, as it can cause patching issues.
Probes with patch caching enabled
When patch caching is enabled, the probe needs to have access to software vendor's web sites to download the installation software. The probe stores the installation software in the patch cache, and accesses it during patching maintenance window.
Adding the web sites below to the firewall allow list ensures that patching can run without interruption due to blocked downloads.
Agents only requires access to the Server In The Sky (https://sis.n-able.com or http://sis.n-able.com).
|Device Type||Vendor server URL|
Device with probe and caching enabled, or with agent without caching enabled.
Device with agent with caching enabled.