Jump to content

Recommended Posts

Posted

Hi - we have recently moved to serve r2019 and Windows 10.

 

We used to have a helpful piece of software that scheduled the downloading and then installing of windows updates to times that wouldn't cause our internet connection to grind to halt when we are trying to use it. (e.g. to only run outside of 'business' hours)

 

Unfortunately the advice from our support people this time is:

There are a few policy's you can implement to delay them being installed but not for the downloads unfortunately.

Best thing to do is make sure workstations are left on the evening of Patch Tuesday and hopefully come Wednesday it'll be downloaded .

There must be a better way.

 

How can we sort this?

 

Thanks for your help

Posted

Its days are numbered sadly. I’ve got three or four 1909 clients in total, the rest are 1903 so not noticed this yet.

 

I don’t fancy the new system. The MS CDN already swamped our link pulling telemetry from clients, so had to manage it with our firewall.

Posted
It shows as "Windows 10 Vibranium and later"

 

Don't think you even need to change it do you? On ours the Vib options are upgrades/drivers only, thought the rest comes under the 1903+ one still

 

For example 2004 CU is available under 1903+ even without the others ticked

 

Steve

  • Thanks 1
Posted
Don't think you even need to change it do you? On ours the Vib options are upgrades/drivers only, thought the rest comes under the 1903+ one still

 

For example 2004 CU is available under 1903+ even without the others ticked

 

Steve

 

That's true, it's only upgrade & servicing drivers for Vibranium, we have 1903 & later ticked which is providing the updates for 1909 onwards

  • Thanks 1
Posted
Its days are numbered sadly. I’ve got three or four 1909 clients in total, the rest are 1903 so not noticed this yet.

 

I don’t fancy the new system. The MS CDN already swamped our link pulling telemetry from clients, so had to manage it with our firewall.

 

Weird, are you on isdn?

Posted

450 x 5Mb connections to the CDN meant that no, it didn’t need to be ISDN to get choked up - it’s 100Mb. This happened after moving to 1903, and I struggled to stop it with GP settings (though there are plenty related to this). My Pfsense is set to choke certain Akamai IP ranges to 5Mb total - works a treat. Have to be careful to avoid ones that O365 and Teams use!

 

I suspect I could scrub all of those rules now, as it will be a GP setting that I’ve since found inadvertently. If I moved away from WSUS I would definitely have to do this.

Posted
450 x 5Mb connections to the CDN meant that no, it didn’t need to be ISDN to get choked up - it’s 100Mb. This happened after moving to 1903, and I struggled to stop it with GP settings (though there are plenty related to this). My Pfsense is set to choke certain Akamai IP ranges to 5Mb total - works a treat. Have to be careful to avoid ones that O365 and Teams use!

 

I suspect I could scrub all of those rules now, as it will be a GP setting that I’ve since found inadvertently. If I moved away from WSUS I would definitely have to do this.

 

Out of curiosity what did you have to do to prevent this issue? We’ve been struggling with bandwidth hogging issues which appears to be coming from windows itself.

Posted

Pfsense combined with ntopng, placed as an Edge firewall with all traffic passing through it. That allowed me to see which IP ranges were hammering us. I then Googled the range to see what it was, then put in a rule to choke it. I had to do this many, many times until it fixed the issue - there are masses of Akamai ranges!

 

You would best describe this as a bodge. However, it did allow me to pinpoint the issue and it hasn’t been a problem for around 12 months now. I’m left with a free, powerful firewall.

Posted
You had a continuous 5Mb upload from every computer?

 

Yup. We lost WAN connectivity until I sorted it, such was the saturation. Last August was awful, never been so stressed. This was over weeks, not days.

 

I had shut down the analytics, update sharing off-LAN and anything else I could find, but in the end the firewall gave me some breathing space - within a day of installing it we had working systems and I could drill down on the issues.

 

I guess 1703 to 1903 increased the peer to peer and analytics stuff.

 

Do a forum search - wasn’t just me that got hit by this.

Posted

I remember you had issues with Store app updates downloading, and then someone said WSUS did store apps, but can't remember whether they ever explained how

 

Fun fact, every store app has its own registry hive. Much like Click to run apps

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...