The WSUS server definitely needs to be on the network that has access to Interet, since it needs to download the updates from Microsoft before serving the update clients.
Then, you'll need to find a way to allow the clients on the other network (the one w/o Internet access) to access the WSUS server.
This probably means you'll have to do inter-VLAN routing, w/ ACLs to allow WSUS access only.
Please rate the post if it helps.