gshaw Posted January 30, 2019 Posted January 30, 2019 We've just noticed a huge traffic spike on our network from what looks like client PCs trying to go out directly to Microsoft for updates, despite being configured to use WSUS via GPO. Put a block rule in place for a while to stop the traffic but need to find the root cause. Only seems to be a recent thing, has anyone noticed any changes since the last round of updates?
AlanD Posted January 30, 2019 Posted January 30, 2019 Are you sure its updates.. and not telemetry... Which seems to be microsfts equivalent for tracking everyone and everything...
crc-ict Posted January 30, 2019 Posted January 30, 2019 We had the same thing here a few months ago. Completely took out our 100Mb leased line. It's related to the 'peer-to-peer' updates functionality in Windows 10. You can fix it by disabling BITS Peercaching via GPO. These are the settings I used to cure it: 4
gshaw Posted January 31, 2019 Author Posted January 31, 2019 (edited) Are you sure its updates.. and not telemetry... Which seems to be microsfts equivalent for tracking everyone and everything... With 1TB of data transfer yesterday it wouldn't so much be telemetry as a data dump All of that was disabled via GPO when I set up our Win 10 policies and until a few days ago not had anything like this level of traffic. Seems to have been triggered by the last round of patches. We had the same thing here a few months ago. Completely took out our 100Mb leased line. It's related to the 'peer-to-peer' updates functionality in Windows 10. You can fix it by disabling BITS Peercaching via GPO. These are the settings I used to cure it: [ATTACH=CONFIG]51997[/ATTACH] Thanks, have put these on this morning, going to watch during the course of the day to see if the number of hits on the firewall rule I put in yesterday to Deny the traffic reduces. I've never seen our 1Gb line saturated but yesterday I watched the traffic graph go up to 100% usage and stay there Edited January 31, 2019 by gshaw
crc-ict Posted January 31, 2019 Posted January 31, 2019 I've never seen our 1Gb line saturated but yesterday I watched the traffic graph go up to 100% usage and stay there Yes, it's scary isn't it?! When I was researching this, I read that the default settings allow use of the maximum available bandwidth!! I don't know what triggers it, as ours was obviously not the same round of updates as yours, but I do know that it happened on a Wednesday, the day after a Patch Tuesday...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now