Sophos Client Firewall: how to add a rule to allow Windows updates
Issue
How to add a rule to the Sophos Client Firewall to allow Windows updates.
The component of Windows that manages updates is svchost.exe, which actually launches wuauclt.exe as a hidden process. This is why it is wuauclt.exe that must be added to the 'Checksums', and 'Applications' lists.
Note : As there are security implications to allowing hidden processes, access is restricted to the three Windows update URLs.
Sophos product and version
Client Firewall
Operating systems
Windows 2000+
Windows Server 2000+
What to do
Add hidden process
- Open the 'Sophos Client Firewall Configuration Editor'
- Click the 'Processes' tab
- Click the top 'Add' button - the 'Open' dialog opens
- Navigate to (one of the following) :
C:\WINDOWS\system32- for Windows XP (etc.)C:\WINNT\system32- for Windows 2000 (etc.)
- Locate and double-click
svchost.exe- it will be added to the list of Windows components allowed to launch hidden processes
Add checksum
- Click the 'Checksums' tab
- Click the 'Add' button - the 'Open' dialog opens
- Navigate to (one of the following) :
C:\WINDOWS\system32- for Windows XP (etc.)C:\WINNT\system32- for Windows 2000 (etc.)
- Locate and double-click
wuauclt.exe- it will be added to the list of Windows components the 'Firewall Client' recognises by their checksums
Add application rule
- Click the 'Applications' tab
- Double-click
wuauclt.exe- the 'Application Rules' dialog opens - Click the 'Add' button
- In field 1 (rule name) - type
svchost.exe - In field 2 (events) - check the 'Where the direction is' checkbox
- In field 4 (rule description) - click the 'Undefined' link - the 'Direction' dialog opens
- In the 'Direction' dialog - check the 'Outbound' checkbox
- In field 2 (events) - check the 'Where the remote address is' checkbox
- In field 4 (rule description) - click the 'Undefined' link - the 'Select Address' dialog opens
- Click 'Domain name'
- In the upper field - type
update.microsoft.com - Click the 'Add' button
- In the upper field - type
download.microsoftupdates.com - Click the 'Add' button
- In the upper field - type
windowsupdate.microsoft.com - Click the 'Add' button
- Click the 'OK' button - the 'Select Address' dialog closes
- In the 'Add Rule' dialog - click the 'OK' button - the 'Add Rule' dialog closes
- In the 'Application Rules' dialog - click the 'OK' button - the 'Application Rules' dialog closes
Technical information
The built rule will appear (more or less) as follows in the 'Application Rules' dialog :
Where the protocol is TCP
and the direction is outbound
and the remote address is
update.microsoft.com,
download.microsoftupdates.com,
windowsupdate.microsoft.com
Allow it
If you need more information or guidance, then please contact technical support.
- Article ID: 17444
- Created: 10 Oct 2006
- Last updated: 9 Oct 2008
