<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow to update windows in VM-Series in the Private Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/allow-to-update-windows/m-p/558208#M162</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Looks good so far. The biggest issue I have found with windows updates is that Microsoft utilizes Akamai for content delivery. This often causes failures in a system attempting to get updates. However the client usually does get the updates, etc. Just keep an eye on the traffic that is getting blocked and see if you need to tune the policy you already have.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do not decrypt this traffic as it will break. Also remember that users will be able to put &lt;A href="http://www.microsoft.com" target="_blank" rel="noopener"&gt;www.microsoft.com&lt;/A&gt;&amp;nbsp;into a browser and get to the site (this is unavoidable). Also here is a list I have for MS update URLS:&lt;/P&gt;
&lt;P&gt;*.download.windowsupdate.com&lt;BR /&gt;*.manage.microsoft.com&lt;BR /&gt;*.officecdn.microsoft.com&lt;BR /&gt;*.update.microsoft.com&lt;BR /&gt;*.windowsupdate.com&lt;BR /&gt;*.windowsupdate.microsoft.com&lt;BR /&gt;blob.core.windows.net&lt;BR /&gt;bspmts.mp.microsoft.com&lt;BR /&gt;config.office.com&lt;BR /&gt;definitionupdates.microsoft.com&lt;BR /&gt;dl.delivery.mp.microsoft.com&lt;BR /&gt;download.microsoft.com&lt;BR /&gt;download.windowsupdate.com&lt;BR /&gt;go.microsoft.com&lt;BR /&gt;ntservicepack.microsoft.com&lt;BR /&gt;officecdn.microsoft.com&lt;BR /&gt;sccmconnected-a01.cloudapp.net&lt;BR /&gt;silverlight.dlservice.microsoft.com&lt;BR /&gt;test.stats.update.microsoft.com&lt;BR /&gt;windowsupdate.microsoft.com&lt;BR /&gt;wustat.windows.com&lt;BR /&gt;*.do.dsp.mp.microsoft.com&lt;BR /&gt;*.delivery.mp.microsoft.com&lt;BR /&gt;*.prod.do.dsp.mp.microsoft.com&lt;BR /&gt;*.wdcp.microsoft.com&lt;BR /&gt;*.wdcpalt.microsoft.com&lt;BR /&gt;*.wd.microsoft.com&lt;BR /&gt;*.download.microsoft.com&lt;BR /&gt;*.akamaiedge.net&lt;BR /&gt;*.akamaitechnologies.com&lt;BR /&gt;*.blob.core.windows.net&lt;BR /&gt;configmgrbits.azureedge.net&lt;BR /&gt;urs.microsoft.com&lt;BR /&gt;login.microsoftonline.us&lt;BR /&gt;download.visualstudio.microsoft.com&lt;BR /&gt;*.events.data.microsoft.com&lt;BR /&gt;aka.ms&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes some could be outdated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 15 Sep 2023 21:15:32 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2023-09-15T21:15:32Z</dc:date>
    <item>
      <title>Allow to update windows</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/allow-to-update-windows/m-p/557980#M161</link>
      <description>&lt;P&gt;Allow to update windows without allow accessing the internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created this URL Category too, and added to the policy:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;windowsupdate.microsoft.com/&lt;/P&gt;
&lt;P&gt;*.windowsupdate.microsoft.com/&lt;/P&gt;
&lt;P&gt;update.microsoft.com/&lt;/P&gt;
&lt;P&gt;*.update.microsoft.com/&lt;/P&gt;
&lt;P&gt;*.windowsupdate.com/&lt;/P&gt;
&lt;P&gt;*.download.windowsupdate.com/&lt;/P&gt;
&lt;P&gt;download.microsoft.com/&lt;/P&gt;
&lt;P&gt;*.download.microsoft.com/&lt;/P&gt;
&lt;P&gt;wustat.windows.com/&lt;/P&gt;
&lt;P&gt;ntservicepack.microsoft.com/&lt;/P&gt;
&lt;P&gt;stats.microsoft.com/&lt;/P&gt;
&lt;P&gt;amupdatedl.microsoft.com/&lt;/P&gt;
&lt;P&gt;*.events.data.microsoft.com/&lt;/P&gt;
&lt;P&gt;*.data.microsoft.com/&lt;/P&gt;
&lt;P&gt;smartscreen-prod.microsoft.com/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Look at my policy in the photo&amp;nbsp;please&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="01.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53728iFCBB9A914930378A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="01.jpg" alt="01.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 17:19:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/allow-to-update-windows/m-p/557980#M161</guid>
      <dc:creator>ahmadabdeen</dc:creator>
      <dc:date>2023-09-14T17:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Allow to update windows</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/allow-to-update-windows/m-p/558208#M162</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Looks good so far. The biggest issue I have found with windows updates is that Microsoft utilizes Akamai for content delivery. This often causes failures in a system attempting to get updates. However the client usually does get the updates, etc. Just keep an eye on the traffic that is getting blocked and see if you need to tune the policy you already have.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do not decrypt this traffic as it will break. Also remember that users will be able to put &lt;A href="http://www.microsoft.com" target="_blank" rel="noopener"&gt;www.microsoft.com&lt;/A&gt;&amp;nbsp;into a browser and get to the site (this is unavoidable). Also here is a list I have for MS update URLS:&lt;/P&gt;
&lt;P&gt;*.download.windowsupdate.com&lt;BR /&gt;*.manage.microsoft.com&lt;BR /&gt;*.officecdn.microsoft.com&lt;BR /&gt;*.update.microsoft.com&lt;BR /&gt;*.windowsupdate.com&lt;BR /&gt;*.windowsupdate.microsoft.com&lt;BR /&gt;blob.core.windows.net&lt;BR /&gt;bspmts.mp.microsoft.com&lt;BR /&gt;config.office.com&lt;BR /&gt;definitionupdates.microsoft.com&lt;BR /&gt;dl.delivery.mp.microsoft.com&lt;BR /&gt;download.microsoft.com&lt;BR /&gt;download.windowsupdate.com&lt;BR /&gt;go.microsoft.com&lt;BR /&gt;ntservicepack.microsoft.com&lt;BR /&gt;officecdn.microsoft.com&lt;BR /&gt;sccmconnected-a01.cloudapp.net&lt;BR /&gt;silverlight.dlservice.microsoft.com&lt;BR /&gt;test.stats.update.microsoft.com&lt;BR /&gt;windowsupdate.microsoft.com&lt;BR /&gt;wustat.windows.com&lt;BR /&gt;*.do.dsp.mp.microsoft.com&lt;BR /&gt;*.delivery.mp.microsoft.com&lt;BR /&gt;*.prod.do.dsp.mp.microsoft.com&lt;BR /&gt;*.wdcp.microsoft.com&lt;BR /&gt;*.wdcpalt.microsoft.com&lt;BR /&gt;*.wd.microsoft.com&lt;BR /&gt;*.download.microsoft.com&lt;BR /&gt;*.akamaiedge.net&lt;BR /&gt;*.akamaitechnologies.com&lt;BR /&gt;*.blob.core.windows.net&lt;BR /&gt;configmgrbits.azureedge.net&lt;BR /&gt;urs.microsoft.com&lt;BR /&gt;login.microsoftonline.us&lt;BR /&gt;download.visualstudio.microsoft.com&lt;BR /&gt;*.events.data.microsoft.com&lt;BR /&gt;aka.ms&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes some could be outdated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 21:15:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/allow-to-update-windows/m-p/558208#M162</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-09-15T21:15:32Z</dc:date>
    </item>
  </channel>
</rss>

