Hello,
I am checking a firewall log (Watchguard firebox) to monitor the network traffic for a windows LAN.
I need to filter out the network load related to Windows Updates.
The watchguard fields do not have sni in all records (sometime I have sni=download.microsoft.com, but sometimes sni is empty but destination IP is always available)
Is there a list of the IPs used for windows update?
( I did not manage to find it)
Is there another way to segregate the windows update traffic from other traffics?
Appreciate if you share your ideas.
Thank you.
Hello,
Anyone can advise?
Thank you.
