• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

DMZ rule/out, allow windows update servers only

Scheduled Pinned Locked Moved Firewalling
3 Posts 2 Posters 8.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J Offline
    jmack
    last edited by Sep 7, 2011, 11:15 AM Sep 7, 2011, 10:00 AM

    Hi,

    Is there a way to make sure that servers in DMZ are only able to communicate with WindowsUpdate servers on 80+443?
    (So no other sites 80/443 should be reachable)

    I've made aliases:

    • windowsupdate.microsoft.com
    • download.windowsupdate.com
    • download.microsoft.com

    But it seems the "wildcard-FQDN" are needed as well to get it function.

    • http://*.download.windowsupdate.com
    • http://*.windowsupdate.microsoft.com
    • https://*.windowsupdate.microsoft.com
    • http://*.update.microsoft.com
    • https://*.update.microsoft.com
    • http://*.windowsupdate.com

    Server = Pfsense 2.0 RC3 on Dell PE T110

    1 Reply Last reply Reply Quote 0
    • M Offline
      Metu69salemi
      last edited by Sep 7, 2011, 10:09 AM

      with proxy it would be doable

      if you're having AD, then it can be determined to use only wsus servers and that is all different story and forum

      1 Reply Last reply Reply Quote 0
      • J Offline
        jmack
        last edited by Sep 7, 2011, 10:44 AM

        It seems to work like this… forget the wildcards in FQDN's in aliases...
        (Only proof is, did one succesfull update with DMZ/2k8R2, 3 updates of yesterday)

        Add Alias "WinUpdate":

        • windowsupdate.microsoft.com
        • update.microsoft.com
        • windowsupdate.com
        • download.windowsupdate.com

        Add DMZ Firewall-rule:
        Proto Source Port Destination Port Gateway Queue

        • DMZserver * WinUpdate * * none

        Before I had protocol and ports specified, that seems have been too narrow... It seems to work now... But don't know why actually (compared with previous rule setup) Maybe some ICMP/ping is needed for startup of the updater?!?

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received