10-13-2017 11:40 AM
We bought 2X MX100 Security Appliance (retail price at $4999 each + License ). Currently running at the latest Stable firmware 12.24 and It blocks all device from downloading windows update and Adobe update even thou I whitelist all known Microsoft update sites. Meraki solution
1) Disable Amp ( Risk of getting Malware )
2) Upgrade firmware to V14 BETA. ( Running critical production network on BETA Firmware? )
Anyone have better workaround please help !
Solved! Go to Solution.
10-13-2017 01:41 PM
I am not sure what it was removed, there was nothing in there that was a privacy concern. Anyway, earlier I was testing with a Win 7 box, when I tested with a Win 10 box, bam right away Windows Update broke. I am running MX 12.24 on this MX 100, I moved the client over to my MX 250 running MX 14.XX and right away the updates started working. I can confirm there is an issue here and I was able to replicate it exactly as you described.
Ryan
10-13-2017 11:45 AM
I've deployed a lot of MX's - and they have never blocked Windows Updates without being configured to do so.
Have you configured are layer 7 firewall rules? Can you configured any content filtering rules?
10-13-2017 11:54 AM
Hi PhilipDath,
L7 only block All P2P, Video and Music and Gaming.
Content Filtering only blocks some category that has nothing to do with Microsoft update and Adobe update. ( Unless Microsoft uses P2P Protocol to push update? )
This only happens on my MX100. I have many MX65W with the same config without any issue.
I called Meraki support twice regarding this issue for a month now and they gve me the same answer.
Hope to hear back from some other MX100 users.
10-13-2017 12:05 PM
Try removing the L7 rules and see if that fixes it. If not put them back. Repeat with the contenting filtering rules.
One of those items should get it working again. Tell us which one it was.
10-13-2017 12:06 PM
Hello @enchesiah
I have an MX100 sitting as a cold spare to our MX250. I will fire this up and create a test network and try to duplicate the issue. When we had the MX100 in operation AMP was grabbing Console8 updates as malicious. I am assuming AMP is enabled and what are you IDS settings? Prevention and Balanced? Just want to duplicate your settings here.
10-13-2017 12:09 PM
Thanks for your help. IDS set to Prevention - balance.
10-13-2017 12:56 PM
Hello Again @enchesiah
I have a spare MX100 running 12.24 that I reset back to factory and I enabled AMP and IDS like you have, see screenshots. I also added the L7 rules you mentioned above. I happen to have an extra connection to the outside world with a public IP, so there is not a double NAT taking place here. I had no problem fetching updates from windows update servers or adobe updates. if this traffic was getting grabbed by IDS or by AMP, there would be a log of that event that is easy to find the in security center.
This very much sound like an issue with Content Filtering, more specifically IP/URL reputation as @Philip D'Ath mentioned.
"In firmware version 13.3, URL reputation was prioritized over IP reputation, as opposed to IP reputation being the deciding factor on previous firmware versions. If, for some reason, the IP has a different categorization then the URL, the client could be allowed through."
I can tell you that I am running MX 14.15 on an MX250 and I have not been adversely affected by this beta firmware in a production environment with 1000+ daily clients.
"If a client is being blocked from accessing a page, the easiest way to tell whether content filtering is blocking the traffic is to check your Event Log. When looking at the Security Appliance's network in the dashboard, navigate to Network-wide > Monitor > Event log. To help narrow down the scope, the event type 'Content filtering blocked URL' can be included in the 'Event type include' field."
I hope this helps.
Ryan
10-13-2017 12:08 PM
If you look in the event log for the network - what is the exact reason it gives for the blocking the traffic?
10-13-2017 12:14 PM
I dont think Event log shows whats being block on AMP. Any Idea what event to sort?
10-13-2017 12:17 PM
If you go:
Security Appliance/Security Centre/Events
Does anything come up?
10-13-2017 12:25 PM
10-13-2017 12:31 PM
And you are saying that if you disable AMP it starts working? If there is nothing in that log then it should mean that AMP is not blocking your traffic.
The beta firmware is pretty good. You are unlikely to find any issues if you upgrade to it.
10-13-2017 12:52 PM
10-13-2017 02:07 PM
We can probably solve this now we know the IDS is triggering.
Go:
Security Appliance/Threat Protection/Intrusion detection and prevention
Under "Whitelisted Rules" click "Whitelist an IDS rule". Select the rule that is firing above the in the log.
10-13-2017 12:31 PM
@enchesiah May I get a screen capture of your content filtering and layer 3 / 7 rules?
You are running MX 12.24 correct?
Ryan
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide