Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Microsoft updates blocked despite being excluded from web filtering - am I fixing this right?

I've added every manner of exclusion for everything from microsoft.com and sub-domains as well as windowsupdate.com and subdomains but it wasn't prevent blocking updates.

After reading posts that seem to suggest this is an "undocumented feature" introduced in 9.6 I think (I'm on 9.7) and saying a Transparent Mode Skiplist had to be added, I did that.

Problem is I had to put my internal network on the source hosts/net skip list for it to work. Does that not mean I've effectively turned off web filtering for my internal network? If so, that seems to defeat the purpose. Is there a better way to do this? 



This thread was automatically locked due to age.
Parents
  • no wrong!
    ATTENTION!
    that is not an "and" but an "or" link within the transparent-mode-skiplist.
    The rules disable the proxy for all connections from "inside" (internal network) and create firewall rules for these connections.
    So all your users reach unfiltered to all destinations.

    the destination definitions don#t use domain-names .. .but the IP's behind the definition.
    Please check .. only the IP's within the definition (mouse-over) are used. 

    MS-updates are not so simple, because sometimes IP-Adresses are used - outside from every domain-definition.

    Amodin's exception list could work for the latest updates.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • I had the following exceptions, but they didn't work:

    I also have the following, which itself should prevent block if I'm understanding things (and I may not bee since I'm new to sophos and it's not working)

    Despite all the above the web filtering was blocking http://au.download.microsoff.com, reason="range", which is why I added http to the existing exception but that didn't fix it.

    If I don't have the internal network in the skiplist, it doesn't work, but I did think it was an 'or", meaning I had just turned off web filtering.

    I added the telemetry sites (thanks) but the block isn't one any of those sites...

  • The exception I have in Web Protection doesn't have any 'and' statements in them at all, they are just the listed sites I have in my screenshot, and no filter action for Microsoft for mine.  The only thing that comes to mind off hand is Country Blocking, and I had to make an exception for a while because one of my computers was trying to go to China for updates.  Ultimately, redoing the computer stopped that, haha.

    Can you paste the log error from Web Protection logs?

    XG 19.5 GA 64-bit | Intel Xeon 4-core v3 1225 3.20Ghz
    16GB Memory | 500GB SSD HDD | GB Ethernet x5

Reply
  • The exception I have in Web Protection doesn't have any 'and' statements in them at all, they are just the listed sites I have in my screenshot, and no filter action for Microsoft for mine.  The only thing that comes to mind off hand is Country Blocking, and I had to make an exception for a while because one of my computers was trying to go to China for updates.  Ultimately, redoing the computer stopped that, haha.

    Can you paste the log error from Web Protection logs?

    XG 19.5 GA 64-bit | Intel Xeon 4-core v3 1225 3.20Ghz
    16GB Memory | 500GB SSD HDD | GB Ethernet x5

Children