Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows 10 Updates killing the network

I came across a post today and it mirrors my own experience with Windows 10 updates.

A single new Surface Pro killed our internet connection.

Whirlpool post
https://forums.whirlpool.net.au/forum-replies.cfm?t=2530363

My original question
https://community.sophos.com/products/xg-firewall/f/131/t/75586

Would love to know how to mitigate this.



This thread was automatically locked due to age.
  • Hi Sachin,

    case number is #5886912.

    i had also open a thread in this forum "have anyone problem to apply traffic shaping limit bandwidth?" .

    WSUS and GPO are temporary solutions to work but don't resolve problem of TS in Sophos.

  • Hi Bruno,

    Thanks for the information. Can you capture some information and write down to support asap.

    Information needed for QoS:

    1. system diagnostics utilities connections v4 show dest_ip <IP>  --> This shows the bandwidth id, pls note what bw id is applied for the connection
    2. Screenshot of Packet capture on GUI. Refer : https://community.sophos.com/kb/en-us/123189
    3. System --> System Services --> Traffic shaping settings  -- Both the configuration and the Bandwidth usage info
    4. ipset -L bandwidthset -- Shows if ipsets are create

    Verify whether the QoS services are UP and running. Take SSH to XG and go to Advance Shell, execute the command: service bwm: status -ds nosync

    After capturing the  described information, please write to support and ask an escalation on the case. This is enough information for an escalation and you can reference them to the community post as well. 

    Thanks

  • Hi Sachin,

    We are already in contact with Italian Support team of Sophos. We have already given them some of this information. The next week we will have a troubleshooting session with them and i will tell them to do this tests.

    For my point of view there are two problem:

    ì- Sophos doesn't classified traffic well (for example AKAMAI traffic for windows updates are in Http/S category );

    -Sophos doesn't apply TS policy to some traffic. I don't know why but the behavoir is this.

    i will keep you up date.

    best regards,

  • Hi Bruno,

    Please ask support to escalate the case and take all the necessary required information. If it is an issue in UTM, I need a JIRA to reach to developers.

    Thanks

  • I've tried a bunch of things, like bandwidth management traffic shaping based on web category, application , etc. and nothing works for me on our network. Unfortunately, this hunt and peck style of support and troubleshooting is a head scratcher. Maybe more folks don't notice a problem because they've got a better internet connection, but the XG Firewall crushes our network. 

    The only thing that works is blocking the windows update urls in URL GROUP and adding that to our firewall policy. Of course, that means nobody gets windows updates so hopefully the XG is doing a REALLY good job of blocking threats. I'm actually now going through the trouble of setting up a WSUS server to shovel updates out that way. 

    PS- the windows 10 option of delivering updates to PCs on the LAN must be a placebo option, because it's not working. 

  • I've tried EVERYTHING! This only seems to happen on W10 machines attempting to do updates. It just stays downloading FOR HOURS upon HOURS! I found out the hard way by upgrading 10 laptops. Not until I unplugged them from the network do they stop chewing from Windows update. So I removed the Sophos XG as my edge...Guess what...All the problems went away. So I thought I would give it another go on a different WAN other than production and the same issue exist for Windows 10 updates.

    FYI...The Sophos XG is a brand new appliance...There is one Allow All outbound rule and that's it. The same thing applies for a SOPHOS XG SOHO Appliance on MR3.

    Adam

  • If you're on v16, you can resolve by doing the following:

    Disable Anti-Virus Scanning for Windows 10 clients by using the option below
    • WebAdmin --> Protect --> Web --> Exceptions --> Microsoft Windows Update --> Set to "ON"

    I'll write up how to create the same exception for v15.

  • But simple updating the network adapter driver can relieve you from the pain.

  • I had the same problem, I fixed the issue by going to;

    Within my Sophos UTM 220 appliance, go to Web Protection-->Filtering Options---> Exceptions tab there should be a pre-made Microsoft update exception. Make sure its turned on.

    But more importantly, make sue that the ANTIVIRUS tick box is checked.

    Good luck,

    Elfed.