Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows 10 Updates killing the network

I came across a post today and it mirrors my own experience with Windows 10 updates.

A single new Surface Pro killed our internet connection.

Whirlpool post
https://forums.whirlpool.net.au/forum-replies.cfm?t=2530363

My original question
https://community.sophos.com/products/xg-firewall/f/131/t/75586

Would love to know how to mitigate this.



This thread was automatically locked due to age.
Parents
  • Hi all, 

     

    we have same situation at our customers. On XG ver. 16.05.1 (recently migrated from Cyberoam)  periodically CPU climbs to 100% and jams all network. 

    Report points to au.download.windowsupdate.com  and huge amount of data being downloaded to several W10 machines..

    • Protect --> Web --> Exceptions --> Microsoft Windows Update --> IS SET to "ON",

    but even then CPU gets high because of some other „Antimalware definition update“ downloads. 

    Only thing that "helps" is blacklisting windowsupdate.com   domain...

    Has anyone found a solution to this? Is it possible that Sophos is unable to find a solution for half a year already?

     

    BR, 

    Rimas

  •  - You may be getting a different issue from the one highlighted above. The one highlighted above maxes out bandwidth not necessarily CPU. You can log into the advanced shell and run top to see which process is using the CPU in your situation.

  • I believe it's the same issue. When CPU is 100%, bandwidth is at maximum too.

    Top two processes are "avd" and  "snort".  

    But maybe I am wrong.

    DavidOkeyode - What different issue do you have in mind?

  • Can you go to Web, Exceptions, and confirm that the out-of-box exception for Windows Update is On.

     

    Note:  avd is antivirus.  snort is IPS and Application Control.

  • Two other thoughts.  If neither of these pan out, I don't know.

    1) Go to Back and Firmware, Pattern Updates.  Click on Update Now.  Wait and refresh, make sure there are no errors.

    2) Go to Log Viewer, Web Filter.  Change the action filter to Denied.  See if there is anything suspicious in there, such as to microsoft.

  • Well I think that this is could be a solution  in combination with the exclusion of Windows Update from Web, maybe not for all situations but currently seems to solve to my case.

    XG 115 with last firmware with 10 Win10, suddendly yestarday the band (not so much 10/10 Mbps) was destroyed in downloading. Since Decemeber never killed in this way.

    I start to disconnect each by eacy client PC win10 and the band was always killed. Finally the last one was the killing PC !!!

    Please try this test if you have fews PC: it is the truth. Unplug cable of the right PC (or more than one) and Internet works fine.

     

    So I checked how the windows update was set and I find "PCs on your local network and PCs on the Internet."

    Here’s how to change:

    1. Go to Start  , then Settings > Update & security > Windows Update, and then select Advanced options.
    2. On the Advanced options page, select Choose how updates are delivered, and then use the toggle to turn Delivery Optimization off. When turned off, you'll still get updates and apps from Windows Update and from the Windows Store.

    If you’d just like to stop downloading updates and apps from PCs on the Internet, select just PCs on my local network.

    Also to check if there is some update (also very smal) that doesn't successfully complete.

    But I also add the exception inside Firewall regarding Windows update but not sure who was responsable of the solution like temporal sequence.

     

    So check how the Windows update run and in any case add exclusion inside Firewall.

    I add also another idea: as the windows update could have "peer-to-peer functionality of Delivery Optimization" if we have some rule that block peer-to-peer that could hang the windows update process and the windows update start agian and again. Take a look also to the graphics use of the band I had continuous full trottle for like 10 minutes after 1-2 minute of relax and again start for about 10 miunte full use of the band. This could be a process of updating that start and when should fineshed it stop and strat again.

Reply
  • Well I think that this is could be a solution  in combination with the exclusion of Windows Update from Web, maybe not for all situations but currently seems to solve to my case.

    XG 115 with last firmware with 10 Win10, suddendly yestarday the band (not so much 10/10 Mbps) was destroyed in downloading. Since Decemeber never killed in this way.

    I start to disconnect each by eacy client PC win10 and the band was always killed. Finally the last one was the killing PC !!!

    Please try this test if you have fews PC: it is the truth. Unplug cable of the right PC (or more than one) and Internet works fine.

     

    So I checked how the windows update was set and I find "PCs on your local network and PCs on the Internet."

    Here’s how to change:

    1. Go to Start  , then Settings > Update & security > Windows Update, and then select Advanced options.
    2. On the Advanced options page, select Choose how updates are delivered, and then use the toggle to turn Delivery Optimization off. When turned off, you'll still get updates and apps from Windows Update and from the Windows Store.

    If you’d just like to stop downloading updates and apps from PCs on the Internet, select just PCs on my local network.

    Also to check if there is some update (also very smal) that doesn't successfully complete.

    But I also add the exception inside Firewall regarding Windows update but not sure who was responsable of the solution like temporal sequence.

     

    So check how the Windows update run and in any case add exclusion inside Firewall.

    I add also another idea: as the windows update could have "peer-to-peer functionality of Delivery Optimization" if we have some rule that block peer-to-peer that could hang the windows update process and the windows update start agian and again. Take a look also to the graphics use of the band I had continuous full trottle for like 10 minutes after 1-2 minute of relax and again start for about 10 miunte full use of the band. This could be a process of updating that start and when should fineshed it stop and strat again.

Children
No Data