The answer was in WSUS. I set the port to 8530. There was another site running on the same server and my thought was all internet goes out locally from the SA520, so having the sus set at port 80 was the issue.

When you choose WSUS as your source for Windows updates, you use Group Policy to point Windows 10 client devices to the WSUS server for their updates. From there, updates are periodically downloaded to the WSUS server and managed, approved, and deployed through the WSUS administration console or Group Policy, streamlining enterprise update windows - Use WSUS when local, MU when remote? (But still The WSUS server is available internally only (either VPN or LAN). We have some remote users who are almost never on-site and semi-frequently VPN into the network. Instead of having them download Windows Updates across the VPN, I'd like to accomplish the following: WSU VPN Jul 20, 2020 Get started with Windows Server Update Services (WSUS

Washington State University offers VPN access for those departments and users that require secure remote user access to specific, restricted university services and data. The VPN service provides authenticated and encrypted access to resources such as the administration of departmental servers, administrative systems and applications, and/or systems that house sensitive information.

How to re-register Windows client/server in WSUS Apr 16, 2018

On-premise patching solutions require a connection to an organization’s network from inside the firewall or a VPN connection for patching endpoints. When WSUS was first created, remote endpoints were scarce, but today, employees are using multiple devices to …

How to use WSUS Offline Update for Windows clients and Jun 05, 2018 Complete Guide to Install and Configure WSUS on Windows