Blocking Windows Update via Router


Recommended Posts

Hi guys,

We've got a bit of an issue at the moment, we're using DeepFreeze to lock down our PCs on the call floor, the issue is that they're all redownloading Windows Updates automatically every morning. Now I'm going to go around and disable this so we can manually do it once every few months but immediately we need to have Windows Update blocked as our internet connection is barely functioning right now.

Can anyone tell me what Domains / Ports etc Windows Update on Windows XP uses?

Thanks

Chris

Link to comment
https://www.neowin.net/forum/topic/984862-blocking-windows-update-via-router/
Share on other sites

i believe update.microsoft.com is the hostname of the windows update servers, not sure about the port though, leme see if i can track it down (Y)

edit: windows update services use port 80 and 443, lol

http://technet.microsoft.com/en-us/library/bb490846.aspx

Windows update uses the following DNS for updates;

update.microsoft.com

windowsupdate.microsoft.com

you could block these at the firewall if your router supports DNS blocking that would be the simple option i guess.

If you have a Windows Server you could implement a group policy?

EDIT: Riggers beat me to it

Hey guys,

Blocking those two hostnames seams to have done the job for now, well enough at least. I'll update these PCs manually in a few weeks then disable Windows Update on them.

Which group policy are you guys talking about?

They're hooked up to a Server 2008 R2 Domain Controller.

Through Group policy you can control Windows Update, ideally you would do this with WSUS (free) to give you a centralized control of updates allowing you to control what does and what does not get installed

Then when you want to apply an update you OK it in WSUS and all the machines will download it per the scheduling you have already laid out

  On 24/03/2011 at 14:23, Teebor said:

Through Group policy you can control Windows Update, ideally you would do this with WSUS (free) to give you a centralized control of updates allowing you to control what does and what does not get installed

Then when you want to apply an update you OK it in WSUS and all the machines will download it per the scheduling you have already laid out

This, also you can have deepfreeze thaw during a scheduled time period so that updates can be applied. Say between 3am to 5am on thrusdays for example (a time that usually no one is working).

Yeah, controlling Windows Update via Group Policy isn't really worth it, nor is WSUS, When we move to a Windows Multipoint Server base or move from XP to 7 then I'll worry about such things. These machines are used for a basic Java app and nothing else, so updates are barely important, they're even firewalled off from 99.9% of the web.

I'll just let them be and disable automatic updates soon as I get time.

Spending time fixing up PCs from the dark ages isn't my concern, ensuring it doesn't affect the productivity of the office is my concern. lol.

  On 24/03/2011 at 15:59, Vegetunks said:

Yeah, controlling Windows Update via Group Policy isn't really worth it, nor is WSUS, When we move to a Windows Multipoint Server base or move from XP to 7 then I'll worry about such things. These machines are used for a basic Java app and nothing else, so updates are barely important, they're even firewalled off from 99.9% of the web.

I'll just let them be and disable automatic updates soon as I get time.

Spending time fixing up PCs from the dark ages isn't my concern, ensuring it doesn't affect the productivity of the office is my concern. lol.

30 min gets you wsus and the appropriate group policies in place (even to disable windows updates for those specific machines, this would take 5 min if you have a domain). Dunno how it isnt worth it. Dunno how WSUS isn't worth free.

computer configuration

admin templates

windows components

windows update

Configure automatic updates

"If the status is set to Disabled, any updates that are available on Windows Update must be downloaded and installed manually. To do this, go to http://windowsupdate.microsoft.com or click Start, click Programs (or click All Programs), and then click Windows Update."

This is a computer setting so it applies only to computers, add the computers that you want to apply this gpo to not the users within the group policy management console in active directory.

On the Domain Controller, Start, Administrative tools, Group Policy Management Console.

Make a new group policy under the main domain name, edit the policy. I will provide screen shots in my next post, I will start getting them done now.

when you are in the group policy management console, you single click on the policy on right it displays scope tab, at the bottom of the scope tab there is security filtering. add computers in there. You will have to modify the object type to include computers to be able to add them.

then on a computer that is going to be effected by the group policy you can force it to apply by going to a command prompt and typing in:

gpupdate

to verify that this has been applied you can either use the gpresults command or going to start run rsop.msc and navigating to the windows update section. All pcs will follow suit within 15-45 min, you may want to schedule a one time thaw so that these updates can take place and be in there always, even after a reboot.

Very powerful the group policies are, I would suggest making group policies as granular as possible. They can really lock down a computer. The computer configuration section applies to computers, the user configuration section applies to users. If you change something to the computer configuration and try to apply that to users it will will not apply and if you change something in the user configuration and have that apply to computers it will not apply.

You can make groups and apply policies to groups (you can put computers in a group).

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • DayZ is getting a desert map with new Badlands expansion, set to be its biggest yet by Pulasthi Ariyasinghe It was only last year that developer Bohemia Interactive brought a snow-covered map to the multiplayer survival game DayZ with the Frostline expansion. The long-time supported, post-apocalyptic title is now aiming to take players to a region a little hotter with the next expansion. Touting extreme heat and war-scarred landscapes, the Badlands expansion is set to launch next year. Watch the announcement trailer above. Landing as the third expansion for DayZ, Badlands is set to deliver the biggest map ever developed for the hardcore survival experience. "With an enormous size of 267 km², DayZ Badlands introduces the largest official map in the game’s history," says the studio, describing the incoming content and setting. "Set west of Chernarus and bordering Takistan’s frontier, the terrain offers a desolate blend of cracked soil, sand-swept plains, and mountainous divides. Here, every inch of land tells a story of failed invasions, abandoned cities, and the silence that followed decades of war." The desert environment of the new Nasdara province brings its own survival elements for players to endure. This includes droughts and hydration management, as well as encounters with new types of infected zombies. New loot types, cosmetic items, and region-specific weapons are being added as a part of the expansion, too. As usual, with all the tools and environments in place, it will be the players who make up their own stories and adventures in the multiplayer title. Bohemia Interactive did not announce a release date for the DayZ Badlands expansion today, but it did attach a broad 2026 launch window to it. The expansion is being developed for PC, Xbox Series X|S, and PlayStation 5. While pricing information has not arrived yet either, judging by previous expansions, it may cost around $30 at launch.
    • NetLimiter 5.3.25.0 by Razvan Serea NetLimiter is an ultimate internet traffic control and monitoring tool designed for Windows. You can use NetLimiter to set download/upload transfer rate limits for applications or even single connection and monitor their internet traffic. Along with this unique feature, Netlimiter offers comprehensive set of internet statistical tools. It includes real-time traffic measurement and long-term per-application internet traffic statistics. Main NetLimiter features: NetLimiter shows list of all applications communicating over network it's connections, transfer rates and more. You can use NetLimiter to set download or upload transfer rate limits for applications, connections or groups of them. With limits you can easily manage your internet connection's bandwidth (bandwidth shaper or bandwidth controller) Statistical tool lets you to track your internet traffic history since you've installed NetLimiter. Additional network information: NetLimiter provides you with and additional information like WHOIS, traceroute etc. Rule scheduler, Remote administration, Connection blocker, Running as WinNT service, User rights, Chart, Advanced Rule editor and scheduler, Zone based traffic management... NetLimiter 5.3.25.0 changelog: Massive translation update. Many new text translated to all supported languages. (If you find any translation problem, please contact us at support@netlimiter.com) More robust and reliable domain name filtering system, especially when using domain names without wildcards. More info about filters. Many minor internal fixes. Download: NetLimiter 5.3.25.0 | 10.3 MB (Shareware) View: NetLimiter Homepage | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Lol, that's where it's made and hosted, how else were they expecting the "cloud hosted" model to work? Alas, guess it's the same rule that every other service provider in the EU must follow; all data processing must be handled within EU borders. That's a welcome move for privacy. Deepseek's devs would have to find an EU host if they want to provide the service in the EU.
    • This is why the Year of the Linux Desktop has become vaporware imo
    • Save 76% on this lifetime subscription to SwifDoo PDF editor for Windows by Steven Parker Today's highlighted deal comes via our Apps + Software section of the Neowin Deals store, where you can save 76% on a lifetime subscription to SwifDoo PDF. SwifDoo PDF is a comprehensive PDF editor software that serves as the ultimate solution for all your PDF management needs. SwifDoo PDF for Windows comes with various features to help you organize your PDFs and get the most out of them. It provides you with standard editing features, including the ability to split and merge documents, edit their style, cut/insert text, and more. You can also convert to and from various formats, including Word and different image formats. It’s better to spend your time on other meaningful activities instead of frowning at an editable PDF, wondering if there’s something that can make PDF tasks easier. All the PDF tools you need Open/Create/Read PDF: Open/create PDFs from blank pages, images, files, scans, CAD, and HEIC in simple steps. Edit/Annotate PDF: Empower your productivity with edit/annotate PDFs, allowing you to mark up, insert text, highlight, and edit PDFs. Merge/Split PDF: Merge lots of PDF files or images into one file in your wanted order. Split or separate PDF pages into individual PDFs ideally. Compress PDF: Compress a PDF to reduce the file size by your desired compression level and image quality. Convert PDF: Convert and save PDF to Word DOC/DOCX, Excel, PowerPoint, JPG, HEIC, EPUB, CAD, and more formats and vice versa. Remove/ Add Watermark: Add predefined or custom, text or image watermarks to PDFs for protection. Remove watermarks from PDF pages in one click. Encrypt/ Sign PDF: Protect PDFs with passwords from being opened, copied, edited, or printed. Sign PDFs with handwritten or uploaded signatures. Print PDF: Print double-sided PDFs, print a PDF as a booklet or to grayscale and print PDFs with comments. Add Link/ Pages/ Images: Add links to PDFs to quickly access other pages, files or webpages. Add a file or pages to a PDF. Insert and edit images in PDFs. Advanced features Recognize Text in Scanned PDFs: Powerful OCR to recognize and extract text from scanned and image-based PDF documents to make them editable and searchable. Or, convert images and scanned PDFs to editable file formats such as Word using OCR, without losing the original formatting and layout. Batch Process PDFs: Support simultaneously batch converting between PDF to Word, Excel, PowerPoint, TXT, CAD, images, and HTML, and compressing numerous PDFs, while preserving the original formats and layouts without quality loss. Encrypt, split and print PDFs in bulks. Good to know Length of access: Lifetime Redemption deadline: redeem your code within 30 days of purchase Access options: PC (Windows only) Max number of device(s): 1 Only available to NEW users A single license key can be only activated once Version: 2.0.5.9 Updates included A SwifDoo PDF perpetual lifetime license normally costs $129, but you can pick this up for just $29.97 for a limited time - that represents a saving of $99 (76% off). For a full description, spec, and terms, click the link below. Get SwifDoo PDF editor for just $29.97, or learn more Although priced in U.S. dollars, this deal is available for digital purchase worldwide. We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
  • Recent Achievements

    • Week One Done
      emptyother earned a badge
      Week One Done
    • Week One Done
      DarkWun earned a badge
      Week One Done
    • Very Popular
      valkyr09 earned a badge
      Very Popular
    • Week One Done
      suprememobiles earned a badge
      Week One Done
    • Week One Done
      Marites earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      561
    2. 2
      ATLien_0
      176
    3. 3
      +FloatingFatMan
      169
    4. 4
      Xenon
      124
    5. 5
      Michael Scrip
      118
  • Tell a friend

    Love Neowin? Tell a friend!