<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows Update issues - Windows 10 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/windows-update-issues-windows-10/m-p/176609#M55206</link>
    <description>&lt;P&gt;I am currently troubleshooting an issue on PAN-OS 8.0.4 regarding the ability for Windows 10 / Windows Server 2016 to update via Windows Update. &amp;nbsp;Windows Update for Windows 7 is working fine, however any time I try to download updates&amp;nbsp;on Windows 10 (Creators Update) it fails unless i add a the&amp;nbsp;subnets&amp;nbsp;below to exclude them from decryption. &amp;nbsp;As the App-ID &lt;STRONG&gt;ms-update&lt;/STRONG&gt; does not decrypt by default, I'm wondering if there has been a change in data stream which is causing some Windows Update traffic to be identified as &lt;STRONG&gt;ssl&lt;/STRONG&gt; rather than &lt;STRONG&gt;ms-update&lt;/STRONG&gt;. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Subnets excluded to get this to work:&amp;nbsp;64.4.0.0/18,&amp;nbsp;65.52.0.0/14&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;X.X.X.X--&amp;gt;64.4.54.18 76370000... 169 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 &lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;X.X.X.X--&amp;gt;65.55.252.202 59010000... 209 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA &lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else seen this issue as of recently? &amp;nbsp;I am trying to avoid opening up these entire subnets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Matt&lt;/P&gt;</description>
    <pubDate>Thu, 14 Sep 2017 22:01:19 GMT</pubDate>
    <dc:creator>mlinsemier</dc:creator>
    <dc:date>2017-09-14T22:01:19Z</dc:date>
    <item>
      <title>Windows Update issues - Windows 10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-update-issues-windows-10/m-p/176609#M55206</link>
      <description>&lt;P&gt;I am currently troubleshooting an issue on PAN-OS 8.0.4 regarding the ability for Windows 10 / Windows Server 2016 to update via Windows Update. &amp;nbsp;Windows Update for Windows 7 is working fine, however any time I try to download updates&amp;nbsp;on Windows 10 (Creators Update) it fails unless i add a the&amp;nbsp;subnets&amp;nbsp;below to exclude them from decryption. &amp;nbsp;As the App-ID &lt;STRONG&gt;ms-update&lt;/STRONG&gt; does not decrypt by default, I'm wondering if there has been a change in data stream which is causing some Windows Update traffic to be identified as &lt;STRONG&gt;ssl&lt;/STRONG&gt; rather than &lt;STRONG&gt;ms-update&lt;/STRONG&gt;. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Subnets excluded to get this to work:&amp;nbsp;64.4.0.0/18,&amp;nbsp;65.52.0.0/14&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;X.X.X.X--&amp;gt;64.4.54.18 76370000... 169 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 &lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;X.X.X.X--&amp;gt;65.55.252.202 59010000... 209 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA &lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else seen this issue as of recently? &amp;nbsp;I am trying to avoid opening up these entire subnets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Matt&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2017 22:01:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-update-issues-windows-10/m-p/176609#M55206</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2017-09-14T22:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Update issues - Windows 10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-update-issues-windows-10/m-p/179750#M55722</link>
      <description>&lt;P&gt;Perhaps this was fixed in 8.0.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a fix listed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN-77171&lt;/P&gt;&lt;P&gt;Fixed an issue where the firewall discarded sessions that required the TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 cipher for SSL decryption&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 06:00:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-update-issues-windows-10/m-p/179750#M55722</guid>
      <dc:creator>PhilH</dc:creator>
      <dc:date>2017-10-03T06:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Update issues - Windows 10</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-update-issues-windows-10/m-p/180048#M55800</link>
      <description>&lt;P&gt;Add these url`s to no-decrypt:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*.mp.microsoft.com/&lt;BR /&gt;*.microsoft.com&lt;BR /&gt;fe2.w2.microsoft.com&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 12:52:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-update-issues-windows-10/m-p/180048#M55800</guid>
      <dc:creator>JoneSkj</dc:creator>
      <dc:date>2017-10-04T12:52:34Z</dc:date>
    </item>
  </channel>
</rss>

