Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How do I allow Windows Updates / App Updates in Windows 10

When Malware scanning is turned on in my XG430 Firewall, my new Windows 10 workstations grind to a halt, even if I have WSUS server set and the Store Disabled in Group Policy.  I see 100% CPU Utilization on the workstation and it is unusable for days.  If I turn off FTP, HTTP, and HTTPS malware scanning, then the new workstations perform just fine.

What are the best settings to stop this from happening without turning off the Malware Scanning?



This thread was automatically locked due to age.
Parents
  •  

     

    Hello,
    I created a rule a few months ago to exactly solve this problem:
     
    Rule Name
    Updates MS Office 365 und WSUS
    Action
    AcceptDropReject
     
    Source
    Source Zones
    • LAN
    Add New Item 
    Source Networks and Devices
    • Client_LAN_172
    Add New Item 
     
    During Scheduled Time
    All the Time 
     
    Destination & Services
    Destination Zones
    • WAN
    Add New Item 
    Destination Networks
    • MS WSUS FQDN Group
    Add New Item 
     
    Services
    • HTTP
    • HTTPS
    Add New Item 
     
    Identity
    Match known users


    Malware Scanning
    Scan FTP

    Scan HTTP

    Decrypt & Scan HTTPS
    Advanced
     
     
     
     
     
     
     
    User Applications
    Intrusion Prevention
    None 
    Traffic Shaping Policy
    None 
    Web Policy
    None 
    Apply Web Category based Traffic Shaping Policy
    Application Control
    None 
    Apply Application-based Traffic Shaping Policy
     
     
    You need to create this group:
     
    • MS WSUS FQDN Group : 
    • windowsupdate.com
    • microsoft.com
    • windowsupdate.microsoft.com
    • update.microsoft.com
    • download.windowsupdate.com

    Please add the HTPPS exception  as well:

     

    URL pattern matches
     
      • ^([A-Za-z0-9.-]*\.)?microsoft\.com/
      • ^([A-Za-z0-9.-]*\.)?windowsupdate\.com/
     
    Br,
    Sascha
     
     


  • Thanks, I will try those suggestions and get back to you.

Reply Children
No Data