Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows update on secondary / backup link

We have 2 x WAN links, one as a primary the second as a backup.  we have found windows update killing our primary link of late so would like to send all windows update based traffic on the secondary/backup link.  

We are running a Sophos XG 16.05.8 MR-8

I have crated a traffic shaping Qos policy then applied this policy against the traffic shaping defaults for software updates so that i can ensure it won't kill the backup link should we ever have to fail the primary link over...

 

however i can't seem to work out how to create a firewall rule to send traffic to windows update - 

any suggestions appreciated or if you feel i've taken the wrong approach i'm open to suggestions.

 

Thanks in advance



This thread was automatically locked due to age.
Parents
  • My experience is without an AD, so this might be a guide only.

    Set a higher priority rule that points at the MS update sites and have its gateway your backup link.

    You might also consider upgrading to mr9 or v17.0 MR-5 if you do not use IPSEC?

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • My experience is without an AD, so this might be a guide only.

    Set a higher priority rule that points at the MS update sites and have its gateway your backup link.

    You might also consider upgrading to mr9 or v17.0 MR-5 if you do not use IPSEC?

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

Children