Jump to content

Possible to throttle Windows Updates with Watchguard Firewall ?

Hi,

 

Just as the title says, i need to find out if it is possible to limit the bandwidth of windows updates on a WatchGuard Firewall, I realize with every other firewall this is possible but Watchguard are generally annoying, I can't flash it to PFsense or anything that would make it nice and tasty as this is a work issue. 

 

Thanks Guys !

Chicken Nuggets

CPU - i7-4790k | CPU Cooler - Custom Loop | Motherboard -  MSI Z97 Gaming 5 | RAM - Mushkin Redline (2x4GB) 2400Mhz   Graphics Card - GTX Titan X(Maxwell)  | Power Supply - Super Flower 80+ Gold 650w Storage - Samsung 840 Evo 256gb + 750 Seagate Hybrid + 1TB WD Green + Raid 0 4X500GB + Raid 1 500GB HDD Case - HAF-X | Colour Theme - Orange & Black | Monitor - ACER Predator x34 Overclock to 100hz

Link to comment
Share on other sites

Link to post
Share on other sites

What about using group policy and setting BITS to throttle update bandwidth usage?

Current Network Layout:

Current Build Log/PC:

Prior Build Log/PC:

Link to comment
Share on other sites

Link to post
Share on other sites

Yeah i did think about that but apparently windows 10 still Blasts it way through that

Chicken Nuggets

CPU - i7-4790k | CPU Cooler - Custom Loop | Motherboard -  MSI Z97 Gaming 5 | RAM - Mushkin Redline (2x4GB) 2400Mhz   Graphics Card - GTX Titan X(Maxwell)  | Power Supply - Super Flower 80+ Gold 650w Storage - Samsung 840 Evo 256gb + 750 Seagate Hybrid + 1TB WD Green + Raid 0 4X500GB + Raid 1 500GB HDD Case - HAF-X | Colour Theme - Orange & Black | Monitor - ACER Predator x34 Overclock to 100hz

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Hayabusa1989 said:

Hi,

 

Just as the title says, i need to find out if it is possible to limit the bandwidth of windows updates on a WatchGuard Firewall, I realize with every other firewall this is possible but Watchguard are generally annoying, I can't flash it to PFsense or anything that would make it nice and tasty as this is a work issue. 

 

Thanks Guys !

just disable the update service ive given up trying to block or slow the updates . now you cant even force windows not to wake up randomly . you uncheck the wake this pc box and it auto ticks as soon as you close the window

main rig

Spoiler

 corsair 750d | evga 1000w g2 | Gigabyte x99 soc champ | 5820k 4.0GHz | 1tb wd blue | 250gb samsung 840 evo  | Crucial Ballistix Sport XT 16GB 8x2 DDR4-2400 | MSI GTX 970 x2 | monitor Acer B286HK 28" 4K | razor chroma blackwidow  | razor death adder chroma

CENTOS 7 SERVER (PLEX&docker stuff)

Spoiler

NZXT s220 | evga 500w 80+ | AMD FX 8320e | ASUS M5A78L-M/USB3 | 2x8gb non ecc ddr3 WD red 2TBx2 | seagate 160gb microcenter 8gb flashdrive OS

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, gamerking said:

just disable the update service ive given up trying to block or slow the updates . now you cant even force windows not to wake up randomly . you uncheck the wake this pc box and it auto ticks as soon as you close the window

wish this was a possibility but my boss wont allow us to do that for 20 computers.

Chicken Nuggets

CPU - i7-4790k | CPU Cooler - Custom Loop | Motherboard -  MSI Z97 Gaming 5 | RAM - Mushkin Redline (2x4GB) 2400Mhz   Graphics Card - GTX Titan X(Maxwell)  | Power Supply - Super Flower 80+ Gold 650w Storage - Samsung 840 Evo 256gb + 750 Seagate Hybrid + 1TB WD Green + Raid 0 4X500GB + Raid 1 500GB HDD Case - HAF-X | Colour Theme - Orange & Black | Monitor - ACER Predator x34 Overclock to 100hz

Link to comment
Share on other sites

Link to post
Share on other sites

Use group policy to setup DSCP rules on the windows update process/exe and then on your network equipment, the firewall or something else that supports QoS with DSCP, configure priority queues with the parameters you so wish.

 

Not to be a massive dick and touch on a pain point but FortiGate can just do this traffic shaping out of the box and natively detect windows update traffic, http://kb.fortinet.com/kb/viewContent.do?externalId=FD36831&sliceId=1. Maybe Watchguard can too?

 

See also https://forum.fortinet.com/tm.aspx?m=109872 for the mentioned native method and also a more manual method based on url/dns.

Link to comment
Share on other sites

Link to post
Share on other sites

Group Police Editor is a good idea, it can block updates and is doing it quite well on my PC. The only requirement is that you need Windows 10 Pro, Education or Enterprise.

HAL9000: AMD Ryzen 9 3900x | Noctua NH-D15 chromax.black | 32 GB Corsair Vengeance LPX DDR4 3200 MHz | Asus X570 Prime Pro | ASUS TUF 3080 Ti | 1 TB Samsung 970 Evo Plus + 1 TB Crucial MX500 + 6 TB WD RED | Corsair HX1000 | be quiet Pure Base 500DX | LG 34UM95 34" 3440x1440

Hydrogen server: Intel i3-10100 | Cryorig M9i | 64 GB Crucial Ballistix 3200MHz DDR4 | Gigabyte B560M-DS3H | 33 TB of storage | Fractal Design Define R5 | unRAID 6.9.2

Carbon server: Fujitsu PRIMERGY RX100 S7p | Xeon E3-1230 v2 | 16 GB DDR3 ECC | 60 GB Corsair SSD & 250 GB Samsung 850 Pro | Intel i340-T4 | ESXi 6.5.1

Big Mac cluster: 2x Raspberry Pi 2 Model B | 1x Raspberry Pi 3 Model B | 2x Raspberry Pi 3 Model B+

Link to comment
Share on other sites

Link to post
Share on other sites

On 16/12/2016 at 4:59 PM, leadeater said:

Not to be a massive dick and touch on a pain point but FortiGate can just do this traffic shaping out of the box and natively detect windows update traffic, http://kb.fortinet.com/kb/viewContent.do?externalId=FD36831&sliceId=1. Maybe Watchguard can too?

Haha don't worry i wont take it badly :P

Chicken Nuggets

CPU - i7-4790k | CPU Cooler - Custom Loop | Motherboard -  MSI Z97 Gaming 5 | RAM - Mushkin Redline (2x4GB) 2400Mhz   Graphics Card - GTX Titan X(Maxwell)  | Power Supply - Super Flower 80+ Gold 650w Storage - Samsung 840 Evo 256gb + 750 Seagate Hybrid + 1TB WD Green + Raid 0 4X500GB + Raid 1 500GB HDD Case - HAF-X | Colour Theme - Orange & Black | Monitor - ACER Predator x34 Overclock to 100hz

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×