Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DMZ rule/out, allow windows update servers only

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 8.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jmack
      last edited by

      Hi,

      Is there a way to make sure that servers in DMZ are only able to communicate with WindowsUpdate servers on 80+443?
      (So no other sites 80/443 should be reachable)

      I've made aliases:

      • windowsupdate.microsoft.com
      • download.windowsupdate.com
      • download.microsoft.com

      But it seems the "wildcard-FQDN" are needed as well to get it function.

      • http://*.download.windowsupdate.com
      • http://*.windowsupdate.microsoft.com
      • https://*.windowsupdate.microsoft.com
      • http://*.update.microsoft.com
      • https://*.update.microsoft.com
      • http://*.windowsupdate.com

      Server = Pfsense 2.0 RC3 on Dell PE T110

      1 Reply Last reply Reply Quote 0
      • M
        Metu69salemi
        last edited by

        with proxy it would be doable

        if you're having AD, then it can be determined to use only wsus servers and that is all different story and forum

        1 Reply Last reply Reply Quote 0
        • J
          jmack
          last edited by

          It seems to work like this… forget the wildcards in FQDN's in aliases...
          (Only proof is, did one succesfull update with DMZ/2k8R2, 3 updates of yesterday)

          Add Alias "WinUpdate":

          • windowsupdate.microsoft.com
          • update.microsoft.com
          • windowsupdate.com
          • download.windowsupdate.com

          Add DMZ Firewall-rule:
          Proto Source Port Destination Port Gateway Queue

          • DMZserver * WinUpdate * * none

          Before I had protocol and ports specified, that seems have been too narrow... It seems to work now... But don't know why actually (compared with previous rule setup) Maybe some ICMP/ping is needed for startup of the updater?!?

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.