In Windows Server Update Services 3.0 (WSUS 3.0 SP2), the WSUS Setup automatically configures IIS to distribute the latest version of Automatic Updates to each client computer that contacts the WSUS server.
The best way to configure Automatic Updates depends on the network environment. In an environment that uses Active Directory directory service, you can use an existing domain–based Group Policy object (GPO) or create a new GPO. In an environment without Active Directory, use the Local GPO. In this step, you will configure Automatic Updates and then point the client computers to the WSUS server.
The following procedures assume that your network runs Active Directory. These procedures also assume that you are familiar with Group Policy and use it to manage the network.
For more information about Group Policy, refer to the Group Policy Tech Center Web site at http://go.microsoft.com/fwlink/?LinkID=47375.
I found this at the WSUS site in the deployment guide…
You COULD do a proxy redirrect (the sites that Automatic update uses are listin in the same document) at: