<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Microsoft Updates require inbound rules ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/microsoft-updates-require-inbound-rules/m-p/3054053#M1015166</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am facing a strange issue with regards to Microsoft Updates. I can see connection drops in the context explorer for Microsoft updates. In the logs I can see that there is inbound traffic that is being blocked by the FTD with the source port of 443 probably from microsoft update server. Since these updates are response to the request initiated from the internal networks shouldn't the inbound traffic be allowed automatically by the firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Another strange thing I found is we do not need to explicitly allow microsoft update or windows update as an application in the rules. just by allowing DNS, HTTP &amp;amp; HTTPS it works. I can't see microsoft update application as denied application in the application statistics dashboard.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Has anyone faced a similar issue with microsoft updates on FTD 6.2.0 version.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Vaibhav&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 13:26:56 GMT</pubDate>
    <dc:creator>vaibhav.parlekar1</dc:creator>
    <dc:date>2019-03-12T13:26:56Z</dc:date>
    <item>
      <title>Microsoft Updates require inbound rules ?</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-updates-require-inbound-rules/m-p/3054053#M1015166</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am facing a strange issue with regards to Microsoft Updates. I can see connection drops in the context explorer for Microsoft updates. In the logs I can see that there is inbound traffic that is being blocked by the FTD with the source port of 443 probably from microsoft update server. Since these updates are response to the request initiated from the internal networks shouldn't the inbound traffic be allowed automatically by the firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Another strange thing I found is we do not need to explicitly allow microsoft update or windows update as an application in the rules. just by allowing DNS, HTTP &amp;amp; HTTPS it works. I can't see microsoft update application as denied application in the application statistics dashboard.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Has anyone faced a similar issue with microsoft updates on FTD 6.2.0 version.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Vaibhav&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:26:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-updates-require-inbound-rules/m-p/3054053#M1015166</guid>
      <dc:creator>vaibhav.parlekar1</dc:creator>
      <dc:date>2019-03-12T13:26:56Z</dc:date>
    </item>
    <item>
      <title>If you're not able to</title>
      <link>https://community.cisco.com/t5/network-security/microsoft-updates-require-inbound-rules/m-p/3054054#M1015167</link>
      <description>&lt;P&gt;If you're not able to conclude what is the reason for drops from connection event and other then try firewall-engine-debug and initiate intended traffic from one of the machines. it would give more insight: Login to FTD device and run this command. Eg:&lt;/P&gt;
&lt;P&gt;&amp;gt; system support firewall-engine-debug&lt;/P&gt;
&lt;P&gt;Please specify an IP protocol:&lt;BR /&gt;Please specify a client IP address: 172.16.10.10&lt;BR /&gt;Please specify a client port:&lt;BR /&gt;Please specify a server IP address:&lt;BR /&gt;Please specify a server port: 443&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It's one of the beautiful commands to know what is happening with the traffic being sent. Hope you get some more info from this about the issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Dv&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 21:23:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/microsoft-updates-require-inbound-rules/m-p/3054054#M1015167</guid>
      <dc:creator>Dinesh Verma</dc:creator>
      <dc:date>2017-07-05T21:23:32Z</dc:date>
    </item>
  </channel>
</rss>

