Jump to content

Recommended Posts

Posted

Cant seem to workout what is causing the issue but we're having really high bandwidth usage since moving to windows 10. All traffic seems to be going out to a Akamai CDN node which we assume is hosting something for microsoft? maybe windows updates?

 

We've got all cloud content disabled via gpo

We've changed the lockscreen to our own image.

 

We are disabling the ips at a firewall level but need to move away from this as they keep changing.

We are unable to block the traffic via our web filtering as it does not allow you to block sites via the domain name which is annoying.

 

I have noticed the machines are updating themselves to 1607 from 1511 randomly so i assume this could be the reason fro the high bandwidth.

 

Cheers,

Jack

Posted

Oh and as a general thing:

 

Computer Configuration > Administrative Templates > Network > Background Intelligent Transfer Service (BITS)> Limit the maximum network bandwidth for BITS background transfers

 

My settings are:

 

Limit background transfer rate (kbps) to : 100 From : 7AM To : 9PM At all other times : Use all available unused bandwidth

Posted

I think its turning things off correctly but i need to triple check when i can get back to a pc as my mac wont dual boot into windows correctly at the moment.

 

And ill give the BITS trick a try.

 

Cheers

Jack

Posted

The other thing to check is in the Update settings. I'm not sure what the default is but there is an option to P2P updates to other machines on the Internet. If you have that on, then that will eat all your bandwidth too.

 

Managing Windows 10's New Peer Updating Capability Using GPO | Windows 10 content from Windows IT Pro

 

The setting in GPO is:

 

Computer Configuration > Administrative Templates > Windows Components > Delivery Optimization > Download Mode

 

I have it set to 'Enable WUDO (local peers only)' for my desktops and servers. I set it to 'Disable WUDO' for my laptops as they might be on VPN or offsite and I don't want to kill their connection.

  • Thanks 1
Posted
BTW you need both of the above policys set. If you don't the local WUDO will obliterate your LAN uplinks (I have clients with SSDs. So half a switch of those clients can saturate my 10Gbit uplinks unless I tell BITS to throttle).
  • Thanks 1
  • 4 weeks later...
Posted

Not tried the BITS setting but I have had to block three URLs that cause the problems. I have done all the other settings but did not make any difference until I blocked these addresses. Bandwidth instantly drops.

 

Would the BITS not affect the SCCM application deployment on devices?

Posted
Not tried the BITS setting but I have had to block three URLs that cause the problems. I have done all the other settings but did not make any difference until I blocked these addresses. Bandwidth instantly drops.

 

Would the BITS not affect the SCCM application deployment on devices?

 

I've tried it and it does. :(

  • 2 weeks later...
Posted

Just as an update everything i tried failed and traffic was still going out on those ips. In the end we've ended up creating local dns zones for am.microsoft.com and msn.com and pointing them to localhost.

 

This will do for now until we can block it at a level using something like smoothwall or something similar.

  • Thanks 1
Posted

We have had the same issue. I've created a policy in Smoothwall which blocks updates during the day. We have now also installed a new WSUS server which manages Windows 10 updates as our old one did not.

It's been a real problem!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...