This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windowsupdate 0x80240437 0x80245006 TLS

Just for your info.

Windows 10 devices had trouble updating with resulting error 0x80245006

There were no usefull errors on my XG 18 firewall, just "HTTP parsing error encountered."

At that time I start changing firewall rules which did not help.

Then checked the Sophos Log viewer again with only the SSL/TLS inspection Module.

There were som Green/Blue slots, does not look like a error to me but checking the url's there were some Microsoft domains.

I have put these Microsoft Domains in the "Local TLS exclusion list" and Windows 10 devices start updating.

Why are those Domains not on Sophos TLS Exclusions list??

 

These are the domains I have put on "Local TLS exclusion list"  (don't think they all have to be there but worked for me)

slscr.update.microsoft.com, licensing.mp.microsoft.com, fe3cr.delivery.mp.microsoft.com, client.wns.windows.com, fe2cr.update.microsoft.com



This thread was automatically locked due to age.
Parents
  • Hi,

    you can do it a number of ways, one is the way you did or you can add extras to the existing web exception list which is probably better value for when you start to create your own dpi rules.

    i found the if I allowed all the updates through and then removed the general access firewall rule, the updates flow correctly.

    There was another thread on this subject earlier.

    ian

Reply
  • Hi,

    you can do it a number of ways, one is the way you did or you can add extras to the existing web exception list which is probably better value for when you start to create your own dpi rules.

    i found the if I allowed all the updates through and then removed the general access firewall rule, the updates flow correctly.

    There was another thread on this subject earlier.

    ian

Children