Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows 10 Updates killing the network

I came across a post today and it mirrors my own experience with Windows 10 updates.

A single new Surface Pro killed our internet connection.

Whirlpool post
https://forums.whirlpool.net.au/forum-replies.cfm?t=2530363

My original question
https://community.sophos.com/products/xg-firewall/f/131/t/75586

Would love to know how to mitigate this.



This thread was automatically locked due to age.
  • I believe it's the same issue. When CPU is 100%, bandwidth is at maximum too.

    Top two processes are "avd" and  "snort".  

    But maybe I am wrong.

    DavidOkeyode - What different issue do you have in mind?

  • Can you go to Web, Exceptions, and confirm that the out-of-box exception for Windows Update is On.

     

    Note:  avd is antivirus.  snort is IPS and Application Control.

  • Two other thoughts.  If neither of these pan out, I don't know.

    1) Go to Back and Firmware, Pattern Updates.  Click on Update Now.  Wait and refresh, make sure there are no errors.

    2) Go to Log Viewer, Web Filter.  Change the action filter to Denied.  See if there is anything suspicious in there, such as to microsoft.

  • We had similar issues with Windows Updates on Win7 and Win 10 machines. Automatic updates would seem to get stuck and use 100's of GB in a day per machine and never update. Manual updates would fail also. I did add the exceptions seen in numerous threads in the forums. Even the Windows Update Exception that appeared with newer firmware did not work. After watching traffic on my firewall I saw two IP's that go to Verizon on behalf of Microsoft. I added one to my existing Protect>Web>exception rule. That allowed the update to start and not finish. The second IP allowed the update to finish.  After adding those IP's all my sites now update. I'm sure it will break again :) Hope this helps your issue.

     

    Here is what I have in Protect>Web>exception:

     

    Matching URLs:
    100.41.15.48
    100.41.15.50
    ^([A-Za-z0-9.-]*\.)?microsoft\.com/
    ^([A-Za-z0-9.-]*\.)?windows\.com/
    ^([A-Za-z0-9.-]*\.)?windowsupdate\.com/
     
     
     
  • Well I think that this is could be a solution  in combination with the exclusion of Windows Update from Web, maybe not for all situations but currently seems to solve to my case.

    XG 115 with last firmware with 10 Win10, suddendly yestarday the band (not so much 10/10 Mbps) was destroyed in downloading. Since Decemeber never killed in this way.

    I start to disconnect each by eacy client PC win10 and the band was always killed. Finally the last one was the killing PC !!!

    Please try this test if you have fews PC: it is the truth. Unplug cable of the right PC (or more than one) and Internet works fine.

     

    So I checked how the windows update was set and I find "PCs on your local network and PCs on the Internet."

    Here’s how to change:

    1. Go to Start  , then Settings > Update & security > Windows Update, and then select Advanced options.
    2. On the Advanced options page, select Choose how updates are delivered, and then use the toggle to turn Delivery Optimization off. When turned off, you'll still get updates and apps from Windows Update and from the Windows Store.

    If you’d just like to stop downloading updates and apps from PCs on the Internet, select just PCs on my local network.

    Also to check if there is some update (also very smal) that doesn't successfully complete.

    But I also add the exception inside Firewall regarding Windows update but not sure who was responsable of the solution like temporal sequence.

     

    So check how the Windows update run and in any case add exclusion inside Firewall.

    I add also another idea: as the windows update could have "peer-to-peer functionality of Delivery Optimization" if we have some rule that block peer-to-peer that could hang the windows update process and the windows update start agian and again. Take a look also to the graphics use of the band I had continuous full trottle for like 10 minutes after 1-2 minute of relax and again start for about 10 miunte full use of the band. This could be a process of updating that start and when should fineshed it stop and strat again.

  • Hi, all

     

    Murphdog's advise seems to be helping. After adding additional IP's, W10 updates began to download normally, there are no peaks of bandtwidth anymore. 

    I guess, it will work untill Microsoft decides to change these server IP's. Hope it will be solved by Sophos in next firmware update..

     

    BR, 

    Rimas

  • Many people like me have got fed up with auto updates of Windows 10. In earlier version, we used to get an option to turn off Windows updates and can set it as per our choice whenever we want to install updates. But I don't why Microsoft had done this with Windows 10.

     

    I got help from this website to disable automatic Windows update http://www.howali.com/2017/06/how-to-disable-turn-off-stop-windows-10-automatic-updates.html

     

    Check if it works for you.

     

    Regards,

    Tony John