cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
45077
Views
6
Helpful
36
Replies

MX100 AMP Blocking Microsoft Update and Java Update

enchesiah
Level 2
Level 2

We bought 2X MX100 Security Appliance (retail price at $4999 each + License ). Currently running at the latest Stable firmware 12.24 and It blocks all device from downloading windows update and Adobe update even thou I whitelist all known Microsoft update sites. Meraki solution

1) Disable Amp ( Risk of getting Malware )

2) Upgrade firmware to V14 BETA. ( Running critical production network on BETA Firmware? )

Anyone have better workaround please help !

1 Accepted Solution

Accepted Solutions

@enchesiah

I am not sure what it was removed, there was nothing in there that was a privacy concern. Anyway, earlier I was testing with a Win 7 box, when I tested with a Win 10 box, bam right away Windows Update broke. I am running MX 12.24 on this MX 100, I moved the client over to my MX 250 running MX 14.XX and right away the updates started working. I can confirm there is an issue here and I was able to replicate it exactly as you described.

Ryan

View solution in original post

36 Replies 36

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

I've deployed a lot of MX's - and they have never blocked Windows Updates without being configured to do so.

Have you configured are layer 7 firewall rules? Can you configured any content filtering rules?

Hi PhilipDath,

L7 only block All P2P, Video and Music and Gaming.

Content Filtering only blocks some category that has nothing to do with Microsoft update and Adobe update. ( Unless Microsoft uses P2P Protocol to push update? )

This only happens on my MX100. I have many MX65W with the same config without any issue.

I called Meraki support twice regarding this issue for a month now and they gve me the same answer.

Hope to hear back from some other MX100 users.

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

Try removing the L7 rules and see if that fixes it. If not put them back. Repeat with the contenting filtering rules.

One of those items should get it working again. Tell us which one it was.

Hello @enchesiah

I have an MX100 sitting as a cold spare to our MX250. I will fire this up and create a test network and try to duplicate the issue. When we had the MX100 in operation AMP was grabbing Console8 updates as malicious. I am assuming AMP is enabled and what are you IDS settings? Prevention and Balanced? Just want to duplicate your settings here.

Thanks for your help. IDS set to Prevention - balance.

Hello Again @enchesiah

I have a spare MX100 running 12.24 that I reset back to factory and I enabled AMP and IDS like you have, see screenshots. I also added the L7 rules you mentioned above. I happen to have an extra connection to the outside world with a public IP, so there is not a double NAT taking place here. I had no problem fetching updates from windows update servers or adobe updates. if this traffic was getting grabbed by IDS or by AMP, there would be a log of that event that is easy to find the in security center.

This very much sound like an issue with Content Filtering, more specifically IP/URL reputation as @Philip D'Ath mentioned.

"In firmware version 13.3, URL reputation was prioritized over IP reputation, as opposed to IP reputation being the deciding factor on previous firmware versions. If, for some reason, the IP has a different categorization then the URL, the client could be allowed through."

I can tell you that I am running MX 14.15 on an MX250 and I have not been adversely affected by this beta firmware in a production environment with 1000+ daily clients.

"If a client is being blocked from accessing a page, the easiest way to tell whether content filtering is blocking the traffic is to check your Event Log. When looking at the Security Appliance's network in the dashboard, navigate to Network-wide > Monitor > Event log. To help narrow down the scope, the event type 'Content filtering blocked URL' can be included in the 'Event type include' field."

I hope this helps.

Ryan

image.pngimage.png

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

If you look in the event log for the network - what is the exact reason it gives for the blocking the traffic?

I dont think Event log shows whats being block on AMP. Any Idea what event to sort?

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

If you go:

Security Appliance/Security Centre/Events

Does anything come up?

I don't see anything special within that log. We have 100+ PC and all 100+ Pc cannot update windows when AMP is turn on . Meraki support solution is to update to the beta firmware which im not very comfortable doing... just looking for a workaround for now.


Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

And you are saying that if you disable AMP it starts working? If there is nothing in that log then it should mean that AMP is not blocking your traffic.

The beta firmware is pretty good. You are unlikely to find any issues if you upgrade to it.

Yes as soon as i disable AMP everything work. When i turn it on then Windows update stop working again. I think is a knows MX100 issue.

Here is what show up on the log but i dont think those are windows update

Oct 13 12:19:22 IDS Alert 209.66.87.99.IPYX-073920-004-ZYO.zip.zayo.com
209.66.87.99:80

S
Blocked
BROWSER-IEMicrosoft Edge xlink type confusion memory corruption attempt
Oct 13 12:09:00 IDS Alert a23-219-162-115.deploy.static.akamaitechnologies.com
23.219.162.115:80

S
Blocked
BROWSER-IEMicrosoft Edge xlink type confusion memory corruption attempt
Oct 13 12:04:00 IDS Alert a23-219-162-115.deploy.static.akamaitechnologies.com
23.219.162.115:80

S
Blocked
BROWSER-IEMicrosoft Edge xlink type confusion memory corruption attempt

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

We can probably solve this now we know the IDS is triggering.

Go:

Security Appliance/Threat Protection/Intrusion detection and prevention

Under "Whitelisted Rules" click "Whitelist an IDS rule". Select the rule that is firing above the in the log.

@enchesiah May I get a screen capture of your content filtering and layer 3 / 7 rules?

You are running MX 12.24 correct?

Ryan