10-13-2017 11:40 AM
We bought 2X MX100 Security Appliance (retail price at $4999 each + License ). Currently running at the latest Stable firmware 12.24 and It blocks all device from downloading windows update and Adobe update even thou I whitelist all known Microsoft update sites. Meraki solution
1) Disable Amp ( Risk of getting Malware )
2) Upgrade firmware to V14 BETA. ( Running critical production network on BETA Firmware? )
Anyone have better workaround please help !
Solved! Go to Solution.
10-13-2017 12:47 PM
10-13-2017 12:44 PM
I think you might be affected by the IP Reputation/URL filtering issue. This was resolved in 13.3. I think you should upgrade to the beta firmware.
You can read about the issue here:
"Sometimes, sites will be blocked even though their URL category is not blocked. Usually this happens when the IP has a bad reputation but the URL reputation is good. This happens commonly with very large domains like Google that own many IP addresses and sometimes purchase new IP addresses that have not yet been re-categorized to take their new owner into consideration. In situations like this, these IPs sometimes have a category of 'Phishing and Other Frauds,' or various other categories that may actually be blocked:"
10-13-2017 12:56 PM
Meraki support told me that V13 will not even solve my issue. I have to schedule a firmware update and they need to manually push V14 for this issue to be resolve. But its on Bata. Scary. I just dont understand why Cisco Meraki cannot make a windows update to work on a stable firmware?
10-13-2017 12:56 PM
I would assign a group policy only to the server to disable AMP just for those devices. Then try windows update again.
10-13-2017 01:07 PM
Seen similar problem with MX64/65/84.
Found that it corrected by turning AMP off, waiting a bit (minutes) then turning it back on, this allowed updates to proceed.
Havent seen the problem in a while, so may have been covered in a recent update - we are running typically newer than stable release.
10-13-2017 01:23 PM
@enchesiah I wrote out a really lengthy reply and added screenshots, it now disappeared or was removed, did you get a chance to see that reply?
10-13-2017 01:36 PM
I saw it on my email and Im trying to reply and then its gone on the forum .. someone deleted it maybe for privacy issue? Its funny that it works for you but not me. I did not have the chance to look at your screenshot. I guess i have no choice but to upgrade to the new beta firmware... im sure it will work. Worst case Revert back to V12. Thank you again for all your help !!
10-13-2017 01:41 PM
I am not sure what it was removed, there was nothing in there that was a privacy concern. Anyway, earlier I was testing with a Win 7 box, when I tested with a Win 10 box, bam right away Windows Update broke. I am running MX 12.24 on this MX 100, I moved the client over to my MX 250 running MX 14.XX and right away the updates started working. I can confirm there is an issue here and I was able to replicate it exactly as you described.
Ryan
10-13-2017 01:46 PM
11-30-2018 08:11 AM
11-30-2018 12:21 PM
I understand the frustration, however I think it might be OK now to upgrade to 14.X if your willing. That seems to have fixed the issue based on others from this thread.
11-30-2018 12:24 PM
This will be the third *major* issue that we've encountered this year where the fix was installing beta firmware. That's nuts.
11-30-2018 12:29 PM
Disabling AMP for 10 min and enable it works for me. Try that.
10-13-2017 02:30 PM
10-13-2017 02:32 PM
Hello @CarolineS1,
Thank you for jumping in here and letting us know, so nice to have some Cisco Meraki presence here.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide