Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows 10 Updates killing the network

I came across a post today and it mirrors my own experience with Windows 10 updates.

A single new Surface Pro killed our internet connection.

Whirlpool post
https://forums.whirlpool.net.au/forum-replies.cfm?t=2530363

My original question
https://community.sophos.com/products/xg-firewall/f/131/t/75586

Would love to know how to mitigate this.



This thread was automatically locked due to age.
Parents
  • We had similar issues with Windows Updates on Win7 and Win 10 machines. Automatic updates would seem to get stuck and use 100's of GB in a day per machine and never update. Manual updates would fail also. I did add the exceptions seen in numerous threads in the forums. Even the Windows Update Exception that appeared with newer firmware did not work. After watching traffic on my firewall I saw two IP's that go to Verizon on behalf of Microsoft. I added one to my existing Protect>Web>exception rule. That allowed the update to start and not finish. The second IP allowed the update to finish.  After adding those IP's all my sites now update. I'm sure it will break again :) Hope this helps your issue.

     

    Here is what I have in Protect>Web>exception:

     

    Matching URLs:
    100.41.15.48
    100.41.15.50
    ^([A-Za-z0-9.-]*\.)?microsoft\.com/
    ^([A-Za-z0-9.-]*\.)?windows\.com/
    ^([A-Za-z0-9.-]*\.)?windowsupdate\.com/
     
     
     
Reply
  • We had similar issues with Windows Updates on Win7 and Win 10 machines. Automatic updates would seem to get stuck and use 100's of GB in a day per machine and never update. Manual updates would fail also. I did add the exceptions seen in numerous threads in the forums. Even the Windows Update Exception that appeared with newer firmware did not work. After watching traffic on my firewall I saw two IP's that go to Verizon on behalf of Microsoft. I added one to my existing Protect>Web>exception rule. That allowed the update to start and not finish. The second IP allowed the update to finish.  After adding those IP's all my sites now update. I'm sure it will break again :) Hope this helps your issue.

     

    Here is what I have in Protect>Web>exception:

     

    Matching URLs:
    100.41.15.48
    100.41.15.50
    ^([A-Za-z0-9.-]*\.)?microsoft\.com/
    ^([A-Za-z0-9.-]*\.)?windows\.com/
    ^([A-Za-z0-9.-]*\.)?windowsupdate\.com/
     
     
     
Children
  • Hi, all

     

    Murphdog's advise seems to be helping. After adding additional IP's, W10 updates began to download normally, there are no peaks of bandtwidth anymore. 

    I guess, it will work untill Microsoft decides to change these server IP's. Hope it will be solved by Sophos in next firmware update..

     

    BR, 

    Rimas