<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What ACL to allow Windows Update without browsing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/what-acl-to-allow-windows-update-without-browsing/m-p/745128#M1005337</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Although this is for WSUS you could try these sites:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://technet2.microsoft.com/windowsserver/en/library/9d55bda5-9eb9-46d2-a204-62034936eb131033.mspx?mfr=true" target="_blank"&gt;http://technet2.microsoft.com/windowsserver/en/library/9d55bda5-9eb9-46d2-a204-62034936eb131033.mspx?mfr=true&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to the link : Configure the Firewall Between the WSUS Server and the Internet &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 May 2007 10:58:14 GMT</pubDate>
    <dc:creator>h.parsons</dc:creator>
    <dc:date>2007-05-11T10:58:14Z</dc:date>
    <item>
      <title>What ACL to allow Windows Update without browsing</title>
      <link>https://community.cisco.com/t5/network-security/what-acl-to-allow-windows-update-without-browsing/m-p/745125#M1005334</link>
      <description>&lt;P&gt;About 1/2 the PCs in my company should not have the ability to browse.  I want them to be able to run windows update.   Google gave me lots to look at.  But, I can't find a list of IPs complete enought to work.  I figure someone (many someones) must have done this before.  What ACLs are necessary to get Windows Update to work?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-acl-to-allow-windows-update-without-browsing/m-p/745125#M1005334</guid>
      <dc:creator>hetteldorf</dc:creator>
      <dc:date>2019-03-11T10:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: What ACL to allow Windows Update without browsing</title>
      <link>https://community.cisco.com/t5/network-security/what-acl-to-allow-windows-update-without-browsing/m-p/745126#M1005335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I really doubt you will ever come across a complete list of those servers. Compiling and publishing such a list would undoubtedly invite nefarious activity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are a couple of things you might want to look at alternatively.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Build a web proxy and use a combination of authentication and access control list to restrict outbound access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Use N2H2 based URL filtering, your PIX/ASA should have built in support for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Build your own WSUS server that lives on a dmz network that all workstations can talk to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2007 22:13:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-acl-to-allow-windows-update-without-browsing/m-p/745126#M1005335</guid>
      <dc:creator>laurent.geyer</dc:creator>
      <dc:date>2007-05-08T22:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: What ACL to allow Windows Update without browsing</title>
      <link>https://community.cisco.com/t5/network-security/what-acl-to-allow-windows-update-without-browsing/m-p/745127#M1005336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Plan on setting up a WSUS server, but was hoping for a quick temporary fix.  I guess quick and dirty and security don't mix.&lt;/P&gt;&lt;P&gt;Thanks for the info.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2007 11:47:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-acl-to-allow-windows-update-without-browsing/m-p/745127#M1005336</guid>
      <dc:creator>hetteldorf</dc:creator>
      <dc:date>2007-05-09T11:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: What ACL to allow Windows Update without browsing</title>
      <link>https://community.cisco.com/t5/network-security/what-acl-to-allow-windows-update-without-browsing/m-p/745128#M1005337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Although this is for WSUS you could try these sites:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://technet2.microsoft.com/windowsserver/en/library/9d55bda5-9eb9-46d2-a204-62034936eb131033.mspx?mfr=true" target="_blank"&gt;http://technet2.microsoft.com/windowsserver/en/library/9d55bda5-9eb9-46d2-a204-62034936eb131033.mspx?mfr=true&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to the link : Configure the Firewall Between the WSUS Server and the Internet &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 10:58:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-acl-to-allow-windows-update-without-browsing/m-p/745128#M1005337</guid>
      <dc:creator>h.parsons</dc:creator>
      <dc:date>2007-05-11T10:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: What ACL to allow Windows Update without browsing</title>
      <link>https://community.cisco.com/t5/network-security/what-acl-to-allow-windows-update-without-browsing/m-p/745129#M1005338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like that should work.  If not then WSUS is the only real answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2007 15:00:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-acl-to-allow-windows-update-without-browsing/m-p/745129#M1005338</guid>
      <dc:creator>hetteldorf</dc:creator>
      <dc:date>2007-05-14T15:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: What ACL to allow Windows Update without browsing</title>
      <link>https://community.cisco.com/t5/network-security/what-acl-to-allow-windows-update-without-browsing/m-p/745130#M1005339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not quite sure how that helps. The link doesn't include a list of hosts that you could use to restrict TCP/80,443 access to.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2007 15:05:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-acl-to-allow-windows-update-without-browsing/m-p/745130#M1005339</guid>
      <dc:creator>laurent.geyer</dc:creator>
      <dc:date>2007-05-14T15:05:17Z</dc:date>
    </item>
  </channel>
</rss>

