- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Problem with Windows Update
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Problem with Windows Update
Hi,
can anybody help/advise what to check/where to start with Win update problems?
Customer runing 6400 cluster on R81, https inspection on,
enabled_blades fw vpn urlf av appi ips identityServer SSL_INSPECT anti_bot ThreatEmulation mon Scrub
Reporting the problem with direct winupdate, local wsus updates are fine. By them difference between nonCP subnet vs CP controlled subnet are:
-servers cannot find updates/cannot update download most of time,
-updates found after seveal tries sometime,
-time to find/download update 10times longer behind CP
as far as know Update services should be bypasses implicitly + HTTPS policy contains rules:
log not shows any Microsoft related connections processed by inspection / blocked (little bit wierd log from TE which is not enabled for this subnet..), but in result have no idea where to look more.
Thanks for tips here,
LN
- Labels:
-
App Control
-
HTTPS Inspection
-
URL Filtering
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
First thing I would look at are drops in dashboard. Then, run zdebug on the firewall filtering for IP address of the affected machine...say IP is 10.10.10.35, you would do fw ctl zdebug + drop | grep 10.10.10.35 from expert mode of the firewall or whichever one is master, if cluster. If that does not show anything either, then I would dig deeper with tcpdump and fw monitor, also filter for specific IP.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Didn't directly checked fw ctl zdebug drops so far... but in Smartlog no any relevant drops.In additional don't think so its a hard network/firewalling error,
Looks to me as a intercepting problem (sometimes ok, sometimes not, tooks longer, problem running accross servers...), thats why suspecting URL filtering and HTTPS inspect
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Easiest way to tell is if you disable https inspection and test...never seen url filtering cause this, but logs would show it, for sure.
