This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS blocking incoming Windows Update Traffic to Clients

Hi,

 

the following IPs and Rules are blocked in incoming Traffic by XG IPS. It is incoming Windows Update Traffic.

Some Users report Issues downloading Updates from our internal WSUS. Downloading stops at 60% or 90% and so on.

Source Name Signature IDs
93.184.221.240
BROWSER-IE Microsoft Edge App-v vbs command attempt
48053, 2200901
2.20.190.27
BROWSER-IE Microsoft Edge App-v vbs command attempt
48053, 2200901
2.20.190.28
BROWSER-IE Microsoft Edge App-v vbs command attempt
48053, 2200901
2.20.189.211
BROWSER-IE Microsoft Edge App-v vbs command attempt

48053, 2200901

internal WSUS Server
BROWSER-IE Microsoft Edge App-v vbs command attempt

48053, 2200901

OS: SFOS 17.5.12 MR-12

IPS Patterns

9.17.30
-
19:08:29, Jul 28 2020


This thread was automatically locked due to age.
  • Hi,

    please do a search of the XG forum, there is a thread on this subject.

    you will need a allow all rule until the update is completed the the normal rules can be applied.

    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Hi,

    in fact there are several. I guess, there is nothing to wait for, as this seems to come up every few months or weeks.
    I've already allowed the rules but I don't like the idea to have this open in our LAN to WAN FW rule forever.

  • Hi,

    I understand, the issue went away after all the devices had finishing updating to the latest version.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.