This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Exclude Windows Update from Data Transfer Limits

Hi

I work at a home for orphaned and abandoned children. We have a few PCs for the children to use and have a Sophos XG Firewall. The children have Sophos user accounts so that we can implement policies for the children. We also implement surfing and network traffic quotas.

Unfortunately, Windows Updates consume significant network traffic. If Windows Updates occur while one of the children is using a computer, it will consume all of their allowed network traffic.

In the past I have disabled the Windows Update service so that updates do not occur automatically when the children are using the computers. At a time when the children are not using the computers, I have logged into the computers with an admin account, started the Windows Update service, completed any available updates, then disabled the Windows Update service.

However, it seems that the Windows Update service can no longer be kept disabled. There have been several workarounds for this but it seems Microsoft keeps defeating these.

So if I cannot prevent Windows Updates occurring when the children are using the computers, then is there any way I can configure the XG firewall so that the data transferred for Windows Updates is not counted towards the children's Network Traffic quotas?

Thanks

David



This thread was automatically locked due to age.
Parents
  • Hey David,

     

    You could create a FW rule above the default rule that the children use for just the Windows update URLs and shape it during business / school hours

     

    This way its applied before the authenticated users and if you shape it  - it won't consume bandwidth.

     

    A WSUS might also help but the above should exclude it from quota and allow you to control it more.

Reply
  • Hey David,

     

    You could create a FW rule above the default rule that the children use for just the Windows update URLs and shape it during business / school hours

     

    This way its applied before the authenticated users and if you shape it  - it won't consume bandwidth.

     

    A WSUS might also help but the above should exclude it from quota and allow you to control it more.

Children
No Data