The problem is that after approving a test machine, setting the GPO and checking for new updates nothing happen, the client log reported: "0 updates detected" (full log in RED below),
Solution: after copying c:\wsus folder from the external server to internal server, exporting and importing (again) the database > clients can get updates.
How to perform export using WSUSutil.exe:
1 ) from external machine open command line and go to %drive%\Program Files\Update Services\Tools folder and type
wsusutil.exe export export_package.cab logfile.log
2) copy the c:\wsus folder to the internal server.
3) copy export_package.cab to the internal server (you don't need to copy the logfile.log)
4) on the internal server run:
wsusutil.exe import export_package.cab logfile.log
/////////////////////////////////////////////////////////////
2011-09-15 11:38:55:181 380 150c Agent *************
2011-09-15 11:38:55:196 380 1044 AU >>## RESUMED ## AU: Search for updates [CallId = {32CCAA2B-1A4D-4846-9C51-7F54E9A2E42F}]
2011-09-15 11:38:55:196 380 1044 AU # 0 updates detected
2011-09-15 11:38:55:196 380 1044 AU #########
2011-09-15 11:38:55:196 380 1044 AU ## END ## AU: Search for updates [CallId = {32CCAA2B-1A4D-4846-9C51-7F54E9A2E42F}]
2011-09-15 11:38:55:196 380 1044 AU #############
2011-09-15 11:38:55:196 380 1044 AU Successfully wrote event for AU health state:0ts.