- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-17-2022 08:13 PM - edited 11-17-2022 08:16 PM
Hello, you can create a Policy, allow apps ssl, web-browser, and microsoft update app ( Microsoft Update use port 80/443 ) and create a custom category URL, with allowed microsoft update subdomains, put in the URL category in the secure policy.
microsoft update subdomains/FQDN:
Whit that only allow ssl/https and microsft update app to the destination for the Microsoft update services. You can doit the same for Sophos.
Of course it will allow access to the servers to the Internet, but only at the level of the destination in the URL custom category, and nothing else. Additional to protect add profile security policy. And then with another rule close all the rest of the servers access, a total deny of all the rest and above/free the policy of ms-update, web-browser, ssl only to the URLs in question (ms-update and sophos).
Cheers