Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows 10 Updates killing the network

I came across a post today and it mirrors my own experience with Windows 10 updates.

A single new Surface Pro killed our internet connection.

Whirlpool post
https://forums.whirlpool.net.au/forum-replies.cfm?t=2530363

My original question
https://community.sophos.com/products/xg-firewall/f/131/t/75586

Would love to know how to mitigate this.



This thread was automatically locked due to age.
Parents
  •   - This looks more like a Windows 10 issue than an XG firewall issue. Any reasons why you're not using the option to get updates from local PCs on your network in Windows 10? Start  --> Settings --> Update and Security --> Windows Updates --> Advanced Options --> Choose how updates are delivered --> PCs on my local network

    Also, if indeed Microsoft has removed the option to throttle Windows update traffic using BITS, and you're not using WSUS for bandwidth management, then you can follow the documentation that Sachin provided to create a traffic shaping policy - https://community.sophos.com/kb/en-US/123062

    i. Verify that an application list exists for Microsoft Updates already

    Object --> Content --> Application List --> Microsoft Updates

    ii. Create a new traffic shaping policy to apply the limits that you want
    Object --> Policies --> Traffic Shaping
    Policy Association --> Application
    Rule Type --> Limit
    Priority --> Lowest or whatever you want to set
    Bandwidth --> Set the percentage of the bandwidth that you want
    Bandwidth Usage Type --> Most likely Shared

    iii. Apply the traffic shaping policy to an application
    Object --> Policies --> Global App Traffic Shaping
    Expand Software Updates --> Look for Microsoft Updates --> Edit it and apply the newly created policy

    iv. Apply the traffic shaping policy to the Internet Access security policy
    Edit the security policy
    In the "Policy for User Applications" section, Change Application Control to "Allow All" and Select the option to "Apply Application-based Traffic Shaping Policy"

  • Hi all,

    this configuration doesn't work. We have a case open since four month

    For me this problem seem to be relative to AKAMAI. TS doesn't work with AKAMAI. So this problem isn't relative only windows update but all service that use AKAMAI. 

    The only solution is to block IP.

  • Hi Bruno,

    DM me the case#.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Reply Children
  • Hi Sachin,

    case number is #5886912.

    i had also open a thread in this forum "have anyone problem to apply traffic shaping limit bandwidth?" .

    WSUS and GPO are temporary solutions to work but don't resolve problem of TS in Sophos.

  • Hi Bruno,

    Thanks for the information. Can you capture some information and write down to support asap.

    Information needed for QoS:

    1. system diagnostics utilities connections v4 show dest_ip <IP>  --> This shows the bandwidth id, pls note what bw id is applied for the connection
    2. Screenshot of Packet capture on GUI. Refer : https://community.sophos.com/kb/en-us/123189
    3. System --> System Services --> Traffic shaping settings  -- Both the configuration and the Bandwidth usage info
    4. ipset -L bandwidthset -- Shows if ipsets are create

    Verify whether the QoS services are UP and running. Take SSH to XG and go to Advance Shell, execute the command: service bwm: status -ds nosync

    After capturing the  described information, please write to support and ask an escalation on the case. This is enough information for an escalation and you can reference them to the community post as well. 

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Hi Sachin,

    We are already in contact with Italian Support team of Sophos. We have already given them some of this information. The next week we will have a troubleshooting session with them and i will tell them to do this tests.

    For my point of view there are two problem:

    ì- Sophos doesn't classified traffic well (for example AKAMAI traffic for windows updates are in Http/S category );

    -Sophos doesn't apply TS policy to some traffic. I don't know why but the behavoir is this.

    i will keep you up date.

    best regards,

  • Hi Bruno,

    Please ask support to escalate the case and take all the necessary required information. If it is an issue in UTM, I need a JIRA to reach to developers.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Ciao Bruno please could you provide a short update?

    I am vvery interesting wichi will be the "global" solution.

    Currently it seems that everyone uses a different workaround.

    I had understood that the issue involves the feature SCAN, I mean the antivirus that scan all traffic so some users find a solution with a good exception rule in different way.

    In your case which workaround has worked?

    I try to collect the different workarounf and post just one that could be valid for all.

  • I jut want to say I'm having the same issue.  Small network, 15 users, half with Windows 10 AU.  Put in a XG125 and the Windows 10 clients starting killing our bandwidth (35Mb/5Mb).  One downloaded 160Gb of updates from au.download.microsoftupdate.com in a single day.  Funny thing is they have a 128Gb hard drive so I know that's not possible (and they have 90Gb free).  Seems related directly to the XG box because I have another site still running Microsoft TMG that is not having the issue. 

     

    I was able to put in a GPO to bandwidth limit the updates which is allowed with the anniversary update but they shouldn't need that.  It's like the downloads are getting stuck at the XG and keep getting requested again.  I turned on the exception for Microsoft Update and we'll see what happens.

     

    -Allan

  •  - Have you seem the recommended solution above? Limiting bandwidth will not help as the issue was caused by something different. You'll need to enable the exception that was mentioned in the above recommended answer. Thanks.

  • Limiting bandwidth through GPO did help but isn't the "correct" solution as I shouldn't have to.

     

    I just enabled the Windows Update exception and we'll see what happens tomorrow.

  • HI All, 

    Have you tried this , 

    In application filter , you would need to block application BITS . If you check your Reports you would notice that BITS would take a large bandwidth . 

    Hope this would help ,.

    Regards,

    Aditya Patel
    Global Escalation Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

  • But I WANT bits traffic so that doesn't exactly help.  Adding Microsoft update to the exceptions list so far however seems to be helping.