In regards to the two DCs, I've encountered connectivity issues when the network thinks there are multiple DCs on a single network. To be completely honest, I've not tried having redundancy for DCs, with the expection of having two NICs on a single DC. You might be better off getting advice on that from someone more knowledgable than I.
Back to your main issue, though, it's probably a global policy. Why it isn't affecting the other two machines, I can only attribute that towards the time of setup. I had originally setup all clients to receive updates from our WSUS server and not allow them to go to the Windows Update site itself. Any clients added to the network post-WSUS setup did not have this policy attached to them, so they were free to visit/use the Windows Update site. Wierd, but it wasn't a huge deal (we're better off having that option available).
Hope that was somewhat helpful.
_________________________
I swear, troubleshooting is a science: the best discoveries are always on accident...