This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Windows Update Firewall Rule

I'm having an issue with Windows update due to my firewall rules. Users can get out on 80,443, and a couple other application ports. Otherwise outgoing traffic is denied. I know there is a range of ports the the Windows update services uses so I attempted to add the FQDN of known update servers with any port allowed but that did not work. If I make an any out firewall rule for the affected workstation the updates flow.

Anyone have luck with this? Thanks in advance.



This thread was automatically locked due to age.
Parents Reply
  • Another forum user has had sucsess here:

    Might help you out?

    Welcome on board. What you can do is to allow the server to access 80/443 to download updates from Microsoft.
    You can create an object called "clientless" under Objects > Identity > Clientless Users and add your WSUS ip server. Now create a Policy (user policy) where only the clientless object you created can access 80/443 Microsoft website.
    Try to activate IPS rule and see if it breaks the connections (otherwise you need to create exception).

    If you want to be more specific, you can create a URL group under Objects > Content > URL Group where only Microsoft websites are allowed (
    Then create a Web Filter under Objects > Policies > Web Filter cloning from Deny all and add the URL group defined before.
    At the end create a Policy where user is clientless object going to WAN using 80/443 and as Web FIlter choose the filter you have created before.
    Note that this webfilter will allow the server to go only on specified url group created. All other traffic will be blocked (deny all except url specified).

