<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Get this, using Fiddler4 to in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013126#M7166</link>
    <description>&lt;P&gt;Get this, using Fiddler4 to analyze what traffic the Windows Media Creation Tool is trying to get to shows a session terminated by remote server to:&amp;nbsp;http://fg.ds.b1.download.windowsupdate.com/c/Upgr/2017/03/15063.0.170317-1834.rs2_release_clientcombinedsl_ret_x64fre_en-us_64317f9f897ab3cab7e45cbcafd139d30396c81f.esd&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;However if I copy and paste this into Google Chrome on the same machine, I get a download of a 2.9 GB file.&lt;/P&gt;
&lt;P&gt;Why would it not work in their tool, but the blocked connection is not blocked using the chrome browser?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;GET &lt;A href="http://fg.ds.b1.download.windowsupdate.com/c/Upgr/2017/03/15063.0.170317-1834.rs2_release_clientcombinedsl_ret_x64fre_en-us_64317f9f897ab3cab7e45cbcafd139d30396c81f.esd" target="_blank"&gt;http://fg.ds.b1.download.windowsupdate.com/c/Upgr/2017/03/15063.0.170317-1834.rs2_release_clientcombinedsl_ret_x64fre_en-us_64317f9f897ab3cab7e45cbcafd139d30396c81f.esd&lt;/A&gt; HTTP/1.1&lt;BR /&gt;Accept: */*&lt;BR /&gt;Accept-Encoding: identity&lt;BR /&gt;If-Unmodified-Since: Wed, 22 Mar 2017 11:27:14 GMT&lt;BR /&gt;Range: bytes=0-2147483646&lt;BR /&gt;User-Agent: Microsoft BITS/7.5&lt;BR /&gt;Connection: Keep-Alive&lt;BR /&gt;Host: fg.ds.b1.download.windowsupdate.com&lt;/P&gt;
&lt;P&gt;10:42:02:5201 Fiddler Running...&lt;BR /&gt;10:44:08:7697 fiddler.network.streaming&amp;gt; Streaming of response #5 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;BR /&gt;10:44:08:8636 fiddler.network.streaming&amp;gt; Streaming of response #6 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;BR /&gt;10:44:09:0200 fiddler.network.streaming&amp;gt; Streaming of response #7 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;BR /&gt;10:44:09:2076 fiddler.network.streaming&amp;gt; Streaming of response #8 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;BR /&gt;10:44:10:4118 fiddler.network.streaming&amp;gt; Streaming of response #9 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;BR /&gt;10:44:11:5848 fiddler.network.streaming&amp;gt; Streaming of response #10 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;BR /&gt;10:44:11:6004 fiddler.network.readresponse.failure&amp;gt; Session #10 was aborted System.OperationCanceledException Aborting orphan stream &amp;lt; An existing connection was forcibly closed by the remote host&lt;BR /&gt;10:44:12:8202 fiddler.network.streaming&amp;gt; Streaming of response #11 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Apr 2017 14:49:55 GMT</pubDate>
    <dc:creator>keithsauer507</dc:creator>
    <dc:date>2017-04-12T14:49:55Z</dc:date>
    <item>
      <title>How do you unblock Windows 10 media creation tool download or Windows 10 upgrade download?</title>
      <link>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013122#M7162</link>
      <description>&lt;P&gt;If I use the Windows 10 upgrade tool or the Media Creation tool, I always get an error that coincides with an issue downloading the data. &amp;nbsp;If I put a machine's IP address into the BYPASS list, these tools work great. &amp;nbsp;I'd rather not mess with bypass lists because you can forget an IP is in there, plus its messy and unwieldy to maintain. &amp;nbsp;I'd rather put the appropriate URL's in to allow this tool to work.&lt;/P&gt;
&lt;P&gt;So I used PUTTY and logged into our S170 and did grep, access logs and put in the IP address of my test machine. &amp;nbsp;I had Putty log all output to a text file and then run the Media Creation tool to download a Windows 10 ISO file. &amp;nbsp;I then opened this putty.log in Notepad++ and found all occurrences of denied. &amp;nbsp;I tried putting some Regex's into our allowed domains whitelist (Custom URL Categories) but its still blocking.&lt;/P&gt;
&lt;P&gt;([a-zA-Z]|[0-9])\.dl\.delivery\.mp\.microsoft\.com&lt;BR /&gt;[a-zA-Z]+\.windowsupdate\.com&lt;BR /&gt;[a-zA-Z]+\.symcd\.com&lt;BR /&gt;[a-zA-Z]+\.symcb\.com&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I then ran another logging session and the tool still errors out. &amp;nbsp;Here's a preview of some output:&lt;/P&gt;
&lt;P&gt;Line 1816: 1491261293.366 0 10.7.3.7 TCP_DENIED/401 0 HEAD &lt;A href="http://webfilter/B0000D0000N0001N0001F0000S0000R0004/10.7.3.7/http://7.dl.delivery.mp.microsoft.com/filestreamingservice/files/69aeb898-49f8-4992-9c46-0a11c48a747e" target="_blank"&gt;http://webfilter/B0000D0000N0001N0001F0000S0000R0004/10.7.3.7/http://7.dl.delivery.mp.microsoft.com/filestreamingservice/files/69aeb898-49f8-4992-9c46-0a11c48a747e&lt;/A&gt; - NONE/- - OTHER-NONE-NONE-NONE-NONE-NONE-NONE &amp;lt;-,-,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-",-,"-",-,-,"-","-"&amp;gt; - "Microsoft-Delivery-Optimization/10.0"&lt;BR /&gt; Line 1817: 1491261293.370 0 10.7.3.7 TCP_DENIED/401 0 HEAD &lt;A href="http://webfilter/B0000D0000N0001N0001F0000S0000R0004/10.7.3.7/http://7.dl.delivery.mp.microsoft.com/filestreamingservice/files/69aeb898-49f8-4992-9c46-0a11c48a747e" target="_blank"&gt;http://webfilter/B0000D0000N0001N0001F0000S0000R0004/10.7.3.7/http://7.dl.delivery.mp.microsoft.com/filestreamingservice/files/69aeb898-49f8-4992-9c46-0a11c48a747e&lt;/A&gt; - NONE/- - OTHER-NONE-NONE-NONE-NONE-NONE-NONE &amp;lt;-,-,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-",-,"-",-,-,"-","-"&amp;gt; - "Microsoft-Delivery-Optimization/10.0"&lt;BR /&gt; Line 1818: 1491261294.108 0 10.7.3.7 TCP_DENIED/401 0 HEAD &lt;A href="http://webfilter/B0000D0000N0001N0001F0000S0000R0004/10.7.3.7/http://2.dl.delivery.mp.microsoft.com/filestreamingservice/files/69aeb898-49f8-4992-9c46-0a11c48a747e" target="_blank"&gt;http://webfilter/B0000D0000N0001N0001F0000S0000R0004/10.7.3.7/http://2.dl.delivery.mp.microsoft.com/filestreamingservice/files/69aeb898-49f8-4992-9c46-0a11c48a747e&lt;/A&gt; - NONE/- - OTHER-NONE-NONE-NONE-NONE-NONE-NONE &amp;lt;-,-,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-",-,"-",-,-,"-","-"&amp;gt; - "Microsoft-Delivery-Optimization/10.0"&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'll see if this forum lets me attach the whole putty log but if you have any ideas before I open a ticket with Cisco, please let me know what you did to allow this tool to download Windows 10 iso (or usb stick image or in place pc upgrade).&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 13:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013122#M7162</guid>
      <dc:creator>keithsauer507</dc:creator>
      <dc:date>2017-04-10T13:32:27Z</dc:date>
    </item>
    <item>
      <title>We aren't doing the "download</title>
      <link>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013123#M7163</link>
      <description>&lt;P&gt;We aren't doing the "download image from the web" thing, so this might not help... but we had issues with the MS Store in Win8/8.1...&lt;/P&gt;
&lt;P&gt;We didn't use bypass, we put the following in a custom category, created an identity that didn't require authentication, and set this category to not be decrypted.&lt;/P&gt;
&lt;P&gt;.apps.microsoft.com&lt;BR /&gt;.download.windowsupdate.com&lt;BR /&gt;.update.microsoft.com&lt;BR /&gt;.windowsupdate.com&lt;BR /&gt;.ws.microsoft.com&lt;BR /&gt;apps.microsoft.com&lt;BR /&gt;aq.v4.a.dl.ws.microsoft.com&lt;BR /&gt;crl.microsoft.com&lt;BR /&gt;watson.telemetry.microsoft.com&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 14:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013123#M7163</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2017-04-10T14:32:13Z</dc:date>
    </item>
    <item>
      <title>The WSA access log indicated</title>
      <link>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013124#M7164</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The WSA access log indicated it was blocked due to Proxy Authentication. Try to bypass proxy authentication to see if it helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Line 1816: 1491261293.366 0 10.7.3.7 TCP_DENIED/401 0 HEAD &lt;/SPAN&gt;&lt;A href="http://webfilter/B0000D0000N0001N0001F0000S0000R0004/10.7.3.7/http://7.dl.delivery.mp.microsoft.com/filestreamingservice/files/69aeb898-49f8-4992-9c46-0a11c48a747e" onmousedown="dataLayer.push({'event': 'eventTracker', 'eventCat': 'Outbound Links', 'eventAct': 'Click', 'eventLbl': 'webfilter/B0000D0000N0001N0001F0000S0000R0004/10.7.3.7/http:', 'eventVal': 0});"&gt;http://webfilter/B0000D0000N0001N0001F0000S0000R0004/10.7.3.7/http://7.d...&lt;/A&gt;&lt;SPAN&gt; - NONE/- - OTHER-NONE-NONE-NONE-NONE-NONE-NONE &amp;lt;-,-,-,"-",-,-,-,-,"-",-,-,-,"-",-,-,"-","-",-,-,-,-,"-","-","-","-","-","-",0.00,0,-,"-","-",-,"-",-,-,"-","-"&amp;gt; - "Microsoft-Delivery-Optimization/10.0"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 00:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013124#M7164</guid>
      <dc:creator>Tao Yang</dc:creator>
      <dc:date>2017-04-11T00:20:50Z</dc:date>
    </item>
    <item>
      <title>Ok that is an interesting way</title>
      <link>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013125#M7165</link>
      <description>&lt;P&gt;Ok that is an interesting way to go about setting it up. &amp;nbsp;I configured that new authentication policy to not do any type of authorization, and the identity is flagged on a URL list with these in. &amp;nbsp;However I am still getting blocked and when I check the blocked transaction in the UI, it seems to be on &lt;A href="http://ctldl.windowsupdate.com" target="_blank"&gt;http://ctldl.windowsupdate.com&lt;/A&gt; with Block - Policy as the disposition. &amp;nbsp;There are some ocasional download.windowsupdate.com in there as well but with .windowsupdate.com in the URL list why wouldn't this be allowed?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 14:25:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013125#M7165</guid>
      <dc:creator>keithsauer507</dc:creator>
      <dc:date>2017-04-12T14:25:25Z</dc:date>
    </item>
    <item>
      <title>Get this, using Fiddler4 to</title>
      <link>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013126#M7166</link>
      <description>&lt;P&gt;Get this, using Fiddler4 to analyze what traffic the Windows Media Creation Tool is trying to get to shows a session terminated by remote server to:&amp;nbsp;http://fg.ds.b1.download.windowsupdate.com/c/Upgr/2017/03/15063.0.170317-1834.rs2_release_clientcombinedsl_ret_x64fre_en-us_64317f9f897ab3cab7e45cbcafd139d30396c81f.esd&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;However if I copy and paste this into Google Chrome on the same machine, I get a download of a 2.9 GB file.&lt;/P&gt;
&lt;P&gt;Why would it not work in their tool, but the blocked connection is not blocked using the chrome browser?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;GET &lt;A href="http://fg.ds.b1.download.windowsupdate.com/c/Upgr/2017/03/15063.0.170317-1834.rs2_release_clientcombinedsl_ret_x64fre_en-us_64317f9f897ab3cab7e45cbcafd139d30396c81f.esd" target="_blank"&gt;http://fg.ds.b1.download.windowsupdate.com/c/Upgr/2017/03/15063.0.170317-1834.rs2_release_clientcombinedsl_ret_x64fre_en-us_64317f9f897ab3cab7e45cbcafd139d30396c81f.esd&lt;/A&gt; HTTP/1.1&lt;BR /&gt;Accept: */*&lt;BR /&gt;Accept-Encoding: identity&lt;BR /&gt;If-Unmodified-Since: Wed, 22 Mar 2017 11:27:14 GMT&lt;BR /&gt;Range: bytes=0-2147483646&lt;BR /&gt;User-Agent: Microsoft BITS/7.5&lt;BR /&gt;Connection: Keep-Alive&lt;BR /&gt;Host: fg.ds.b1.download.windowsupdate.com&lt;/P&gt;
&lt;P&gt;10:42:02:5201 Fiddler Running...&lt;BR /&gt;10:44:08:7697 fiddler.network.streaming&amp;gt; Streaming of response #5 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;BR /&gt;10:44:08:8636 fiddler.network.streaming&amp;gt; Streaming of response #6 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;BR /&gt;10:44:09:0200 fiddler.network.streaming&amp;gt; Streaming of response #7 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;BR /&gt;10:44:09:2076 fiddler.network.streaming&amp;gt; Streaming of response #8 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;BR /&gt;10:44:10:4118 fiddler.network.streaming&amp;gt; Streaming of response #9 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;BR /&gt;10:44:11:5848 fiddler.network.streaming&amp;gt; Streaming of response #10 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;BR /&gt;10:44:11:6004 fiddler.network.readresponse.failure&amp;gt; Session #10 was aborted System.OperationCanceledException Aborting orphan stream &amp;lt; An existing connection was forcibly closed by the remote host&lt;BR /&gt;10:44:12:8202 fiddler.network.streaming&amp;gt; Streaming of response #11 to client failed: An existing connection was forcibly closed by the remote host. Leaking aborted.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 14:49:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013126#M7166</guid>
      <dc:creator>keithsauer507</dc:creator>
      <dc:date>2017-04-12T14:49:55Z</dc:date>
    </item>
    <item>
      <title>Do you have range requests</title>
      <link>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013127#M7167</link>
      <description>&lt;P&gt;Do you have range requests enabled?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 15:33:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013127#M7167</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2017-04-12T15:33:47Z</dc:date>
    </item>
    <item>
      <title>enabled in what... WSA?  What</title>
      <link>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013128#M7168</link>
      <description>&lt;P&gt;enabled in what... WSA? &amp;nbsp;What page is that on and what does it do?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 16:54:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013128#M7168</guid>
      <dc:creator>keithsauer507</dc:creator>
      <dc:date>2017-04-12T16:54:20Z</dc:date>
    </item>
    <item>
      <title>See Eric's answer here:</title>
      <link>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013129#M7169</link>
      <description>&lt;P&gt;See Eric's answer here:&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/discussion/11608631/ironport-wsa-rangerequestdownload-option&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It used to be in the CLI...&amp;nbsp; I know in 9.1 its in Security Services/Web Proxy, at the bottom.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 17:39:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013129#M7169</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2017-04-12T17:39:23Z</dc:date>
    </item>
    <item>
      <title>Ah ok I see it is currently</title>
      <link>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013130#M7170</link>
      <description>&lt;P&gt;Ah ok I see it is currently disabled. &amp;nbsp;I am a little cautious to enable it if AMP and Virus scanning is going to have a harder time finding malware and virus signatures. &amp;nbsp;I don't get why this has to be a global option. &amp;nbsp;If I had my way I would turn it on for the Microsoft Updates Identity but leave it off for everything else.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I got the ISO file I needed by allowing the direct link to the Windows 10 .ESD file that I found the Media Creation Tool was trying to pull via google chrome. &amp;nbsp;Googling how to convert an ESD file to ISO file lead me to an article along with download links to a tool that does this.&lt;/P&gt;
&lt;P&gt;I'll experiment with this just to see if it makes a difference, but I'll likely put it back to disabled to stay secure. &amp;nbsp;I don't know if anyone from Cisco is reading this forums, but guys... you really should be putting this checkbox under each identity for more granular control. &amp;nbsp;This all or nothing approach just does not work.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;EDIT: &amp;nbsp;Thats what it was Ken. &amp;nbsp;You are a valuable asset to this community! &amp;nbsp;You've helped me in the past on various posts and I can't thank you enough. &amp;nbsp;The Media creation tool is actually working now. &amp;nbsp;I am cautious about leaving this on however because security is very important to the team. &amp;nbsp;Again I just can't believe Cisco would make this an all or nothing setting. &amp;nbsp;That does not seem to be the right direction for this feature. &amp;nbsp;I will inquire TAC about if that can be changed before leaving Cisco WSA for an alternate solution in the 2018 budget year. &amp;nbsp;If they don't change it, they dug their grave.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 18:29:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/how-do-you-unblock-windows-10-media-creation-tool-download-or/m-p/3013130#M7170</guid>
      <dc:creator>keithsauer507</dc:creator>
      <dc:date>2017-04-12T18:29:26Z</dc:date>
    </item>
  </channel>
</rss>

