> Source: [sk117432](https://support.checkpoint.com/results/sk/sk117432)

# sk117432 - Windows hosts are not able to download updates from Windows Server Update Services (WSUS) through Check Point Security Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk117432 |
| Date Created | 2017-06-05 |
| Last Modified | 2017-06-12 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Windows hosts are not able to download Windows Updates from [Windows Server Update Services (WSUS)](https://technet.microsoft.com/en-us/library/hh852340(v=ws.11).aspx) through Check Point Security Gateway / Cluster, although the HTTP traffic (TCP port 80) and HTTPS traffic (TCP port 443) are allowed by the Security Policy / Access Policy:

  Either it takes very long time for the hosts to download these updates, or the download fails with an "`Error: windows could not search for new updates error code 80072EE2`"
* If the relevant Security / Access rule is changed to allow any traffic (by removing all predefined / custom services), then Windows hosts are able to download Windows Updates as expected (fast and without any issues).

* Issue occurs even if only Firewall blade is enabled on Check Point Security Gateway / Cluster.

## Cause

By default, WSUS 6.2 and later (at least Windows Server 2012) uses TCP port 8530 for HTTP traffic and TCP port 8531 for HTTPS traffic. Meaning, the predefined Check Point services '`http`' and '`https`' are not enough for this traffic to pass.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
