Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows 10 Updates killing the network

I came across a post today and it mirrors my own experience with Windows 10 updates.

A single new Surface Pro killed our internet connection.

Whirlpool post
https://forums.whirlpool.net.au/forum-replies.cfm?t=2530363

My original question
https://community.sophos.com/products/xg-firewall/f/131/t/75586

Would love to know how to mitigate this.



This thread was automatically locked due to age.
  • Ciao Bruno please could you provide a short update?

    I am vvery interesting wichi will be the "global" solution.

    Currently it seems that everyone uses a different workaround.

    I had understood that the issue involves the feature SCAN, I mean the antivirus that scan all traffic so some users find a solution with a good exception rule in different way.

    In your case which workaround has worked?

    I try to collect the different workarounf and post just one that could be valid for all.

  • I jut want to say I'm having the same issue.  Small network, 15 users, half with Windows 10 AU.  Put in a XG125 and the Windows 10 clients starting killing our bandwidth (35Mb/5Mb).  One downloaded 160Gb of updates from au.download.microsoftupdate.com in a single day.  Funny thing is they have a 128Gb hard drive so I know that's not possible (and they have 90Gb free).  Seems related directly to the XG box because I have another site still running Microsoft TMG that is not having the issue. 

     

    I was able to put in a GPO to bandwidth limit the updates which is allowed with the anniversary update but they shouldn't need that.  It's like the downloads are getting stuck at the XG and keep getting requested again.  I turned on the exception for Microsoft Update and we'll see what happens.

     

    -Allan

  •  - Have you seem the recommended solution above? Limiting bandwidth will not help as the issue was caused by something different. You'll need to enable the exception that was mentioned in the above recommended answer. Thanks.

  • Limiting bandwidth through GPO did help but isn't the "correct" solution as I shouldn't have to.

     

    I just enabled the Windows Update exception and we'll see what happens tomorrow.

  • HI All, 

    Have you tried this , 

    In application filter , you would need to block application BITS . If you check your Reports you would notice that BITS would take a large bandwidth . 

    Hope this would help ,.

  • But I WANT bits traffic so that doesn't exactly help.  Adding Microsoft update to the exceptions list so far however seems to be helping.

  • I'm troubleshooting the same issue at a customer site, 1 day a week al sales people are in the office and the network is very slow, all windows 10 machines.

     

    I've anabled the windows updates exeptions and wil let you know

  • I'm on the same crazy situation with Windows 10 updates which I temporarily solved with the fix above.  Two days later, the problem is back.  I'm thinking how can this possibly be?  Then I go to the same setting, and the Windows Update exception is Off.  What the heck!

    The strange thing is, the same client also does some SFTP transfers through scripting, and that stopped working when the XG was installed.  I got it fixed by allowing only that host out with a rule that disabled FTP scanning.  They were good for a day or two, then reported the same problem.  I go to the rule and THE SCANNING IS BACK ON!

    No one there even knows how to log onto the XG.  How are settings reverting back?  This is crazy.

  • Hi all, 

     

    we have same situation at our customers. On XG ver. 16.05.1 (recently migrated from Cyberoam)  periodically CPU climbs to 100% and jams all network. 

    Report points to au.download.windowsupdate.com  and huge amount of data being downloaded to several W10 machines..

    • Protect --> Web --> Exceptions --> Microsoft Windows Update --> IS SET to "ON",

    but even then CPU gets high because of some other „Antimalware definition update“ downloads. 

    Only thing that "helps" is blacklisting windowsupdate.com   domain...

    Has anyone found a solution to this? Is it possible that Sophos is unable to find a solution for half a year already?

     

    BR, 

    Rimas

  •  - You may be getting a different issue from the one highlighted above. The one highlighted above maxes out bandwidth not necessarily CPU. You can log into the advanced shell and run top to see which process is using the CPU in your situation.