Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How do I allow Windows Updates / App Updates in Windows 10

When Malware scanning is turned on in my XG430 Firewall, my new Windows 10 workstations grind to a halt, even if I have WSUS server set and the Store Disabled in Group Policy.  I see 100% CPU Utilization on the workstation and it is unusable for days.  If I turn off FTP, HTTP, and HTTPS malware scanning, then the new workstations perform just fine.

What are the best settings to stop this from happening without turning off the Malware Scanning?



This thread was automatically locked due to age.
Parents
  • HI Stevan , 

    I would like to know if Malware scanning is referred as IPS policy or HTTPS SSL Decryption scanning . Now you would need to check if there is any drop in IPS fo your Windows 10 system . Check the log Viewer and Select IPS , filter the logs for your Workstation host address check for Source and Destination , If there is a Drop then check the signature and allow that signature in IPS policy applied on the Firewall rule . 

    Secondly , if there is no drop on the IPS then may check if HTTPS decryption is the cause for your issue . If so then you would need to check the URLs your workstation on the web filter logs and bypass them by creating a Custom category and add in HTTPS scanning exceptions . 

    You may refer the link https://community.sophos.com/kb/en-us/123360 

    You can bypass the scanning of specific websites in the web category, by creating a separate custom web category of that website(s) from Protection > Web Protection > Custom Web Category or Objects > Content > Custom Web Category.

    Hope this would resolve your issue 

    Thanks and Regards 

    Aditya Patel | Network and Security Engineer.

  • Thanks for your reply.  I am referring to the Malware Scanning section in my default rule that I have created for our organization.

    Policies --> I edit the rule --> Malware Scanning --> Turn off HTTP and FTP (HTTPS is already off)

    The problem with bypassing the "sites" is that I don't know which sites to bypass as there seems to be differing information on the internet as to the source of Windows Update for different versions of the Operating System.  It also seems that Windows 10 contacts other sites in order to update Apps from the Microsoft Store.

    If you have any insight into the sites to bypass I would surely like to know which ones and where to put those bypass rules.

    Thanks!

Reply
  • Thanks for your reply.  I am referring to the Malware Scanning section in my default rule that I have created for our organization.

    Policies --> I edit the rule --> Malware Scanning --> Turn off HTTP and FTP (HTTPS is already off)

    The problem with bypassing the "sites" is that I don't know which sites to bypass as there seems to be differing information on the internet as to the source of Windows Update for different versions of the Operating System.  It also seems that Windows 10 contacts other sites in order to update Apps from the Microsoft Store.

    If you have any insight into the sites to bypass I would surely like to know which ones and where to put those bypass rules.

    Thanks!

Children