We are looking for a resource that tells us how to
connected to the Windows Update site through a Firewall.

For example if we create an IPSec filter as follows

trust all 192.168.x.x
block all x.x.x.x

Everything outside the local network is blocked. However
I want to allow Windows Update. What IP
addresses/ports/protocls do I need to trust?