Note: In this document, the term Closed Network is used to describe any environment where the Patch Manager Plus server does not have direct Internet access. This includes secured internal networks, DMZ, and fully air-gapped environments. The patch management workflow described here is determined by Internet connectivity restrictions, not by network placement or topology.
When the Patch Manager Plus server is deployed in an environment without direct Internet access, core patching functions—such as vulnerability database synchronization, automatic patch downloads, and vendor update retrieval—cannot be performed online.
This limitation applies to closed networks, where outbound Internet connectivity is intentionally blocked, irrespective of where the server is placed. A Demilitarized Zone (DMZ) is one such placement scenario. A DMZ is a segmented network zone positioned between an internal network and external or untrusted networks, designed to host systems that require strict access control and isolation. While DMZs can allow tightly controlled Internet access, they are frequently configured without outbound connectivity in high-security environments, effectively operating as closed networks.
In more restrictive setups, such as air-gapped networks, the Patch Manager Plus server is fully isolated, with no physical or logical connectivity to external networks.
Although these environments differ in network topology and isolation level, they share a common constraint: the Patch Manager Plus server cannot communicate directly with external update sources. As a result, patching and vulnerability remediation must be performed using offline or manual workflows. The following steps explain how to manually synchronize vulnerability data, download required patches using an Internet-connected system, and deploy them to the target computers within the restricted environment.