<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't Connect To Windows Update in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-Connect-To-Windows-Update/m-p/191011#M35271</link>
    <description>&lt;P&gt;Forgot to say, this is important, you do need blades&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;mentioned enabled on the gateway.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 30 Aug 2023 01:43:27 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-08-30T01:43:27Z</dc:date>
    <item>
      <title>Can't Connect To Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-Connect-To-Windows-Update/m-p/189906#M35009</link>
      <description>&lt;P&gt;Hi everyone we've restricted our Windows domain controllers from accessing the internet and I've been a sked to allow Windows Update to function. I tried creating a rule with the windows update and update optimization applications with the source of our domain controllers to destination internet (DNS such is a different rule) but no dice.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I updated the rule and created a network group using this &lt;A href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/deploy/2-configure-wsus#211-configure-your-firewall-to-allow-your-first-wsus-server-to-connect-to-microsoft-domains-on-the-internet" target="_self"&gt;page&lt;/A&gt; from Microsoft and added http and https. Yet we still can't connect I just see random IP addresses from Microsoft dropping I know that checkpoints aren't great when it comes to resolving wildcard domain names.&lt;/P&gt;&lt;P&gt;Its unfortunate that more updateable objects are available for download in this situation but I'm kind of banging my head at this now and wanted to post something to see if anyone else had luck opening the&amp;nbsp; required URLs and such for Windows update to function.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for reading.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wsus2.png" style="width: 517px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22138iF06B2E47A11F2139/image-size/large?v=v2&amp;amp;px=999" role="button" title="wsus2.png" alt="wsus2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wsus.png" style="width: 961px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22137i7A838EAB1CDAF8BC/image-size/large?v=v2&amp;amp;px=999" role="button" title="wsus.png" alt="wsus.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wsus3.png" style="width: 837px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22139iBBFFCDB1C5AD17EB/image-size/large?v=v2&amp;amp;px=999" role="button" title="wsus3.png" alt="wsus3.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 21:10:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-Connect-To-Windows-Update/m-p/189906#M35009</guid>
      <dc:creator>rotto841</dc:creator>
      <dc:date>2023-08-18T21:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect To Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-Connect-To-Windows-Update/m-p/191005#M35269</link>
      <description>&lt;P&gt;Hi, couple comments:&lt;/P&gt;
&lt;P&gt;1. FQDN Domain Objects won't work here since you need to resolve for all *.download.microsoft.com instead of just .download.microsoft.com.&lt;BR /&gt;2.&amp;nbsp;Updatable Objects are dependent on the underlying vendor (in this case Microsoft) providing the relevant information in a programmatically readable way so it can be consumed by our gateways.&lt;BR /&gt;3. "Windows Update" and the services http/https are redundant insofar as they both include http/https.&lt;/P&gt;
&lt;P&gt;You can include the relevant domains in a Custom Application/Site object, which will be used as a service.&lt;BR /&gt;This requires: R80.40+, Categorize HTTPS Inspection enabled (it is by default), and App Control.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 00:42:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-Connect-To-Windows-Update/m-p/191005#M35269</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-30T00:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect To Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-Connect-To-Windows-Update/m-p/191010#M35270</link>
      <description>&lt;P&gt;Easiest way I always found to fix this issue is add custom url filtering group with *microsoft* and *windowsupdate* in it and dont even bother with updatable objects. Push policy, problem solved.&lt;/P&gt;
&lt;P&gt;Reap the benefits : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 01:15:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-Connect-To-Windows-Update/m-p/191010#M35270</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-30T01:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect To Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-Connect-To-Windows-Update/m-p/191011#M35271</link>
      <description>&lt;P&gt;Forgot to say, this is important, you do need blades&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;mentioned enabled on the gateway.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 01:43:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-Connect-To-Windows-Update/m-p/191011#M35271</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-30T01:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect To Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-Connect-To-Windows-Update/m-p/219253#M41898</link>
      <description>&lt;P&gt;Hi Rock,&lt;/P&gt;&lt;P&gt;I too have to disable an internet rule that will impact Windows updates. I need to find a solution to block all internet traffic and only allow Windows updates to continue.&lt;/P&gt;&lt;P&gt;When I tried to add the custom domain into the URL filtering, it kept saying the domain must start with a "."&lt;/P&gt;&lt;P&gt;Any pointers?&lt;/P&gt;&lt;P&gt;I'm new and learning.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 08:26:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-Connect-To-Windows-Update/m-p/219253#M41898</guid>
      <dc:creator>momoo168</dc:creator>
      <dc:date>2024-07-01T08:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect To Windows Update</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-Connect-To-Windows-Update/m-p/219302#M41911</link>
      <description>&lt;P&gt;A Domain object does not work in the way you are attempting to use it.&lt;BR /&gt;What we're discussing is a Custom Application/Sites object where this IS allowed.&lt;BR /&gt;However, doing it in a wildcard fashion like this will allow stuff you probably do not want to allow.&lt;/P&gt;
&lt;P&gt;There are a couple of Updatable Objects that might be useful here:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Microsoft Updates -- HTTPS Bypass&lt;/LI&gt;
&lt;LI&gt;Microsoft Updates -- SmartAccel&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk131852" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk131852&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 16:20:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-Connect-To-Windows-Update/m-p/219302#M41911</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-01T16:20:59Z</dc:date>
    </item>
  </channel>
</rss>

