KB5014692 (Jun 22 update) and network failure

Ross Hemingway 91 Reputation points
2022-06-15T10:31:43.787+00:00

Server 2019 std desktop, using hyper v.

It seems (for me anyway) that the KB5014692 monthly update causes a network stack failure. After an install / reboot, it runs and serves OK for 5 mins, and then the network response quits. Uninstalled and reinstalled the update twice to confirm this.

From a console via iDrac, Watching wireshark, the server (host OS) receives the initial SYN, issues an ACK, the client sends back the next ACK and the next packet.... (sofar all normal)... but the server goes deaf at this point and issues nothing more. Then sometime later both ends re-transmit, but nobody is listening at the server end.

Affects all traffic, all ports but only after 5 mins of normal running. Feels like some buffer or counter not correctly coded.

Anyone else?

Update June 28th, 2022.

Microsoft now acknowledges this (RRAS / NAT) issue in known issues :

https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019#2853msgdesc

... and repaired it with "out of band" fix in KB5014669 :

https://support.microsoft.com/en-us/topic/june-23-2022-kb5014669-os-build-17763-3113-preview-e9aae102-e21c-4f6d-89e0-ed0a82a793dc

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,768 questions
Windows Network
Windows Network
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.Network: A group of devices that communicate either wirelessly or via a physical connection.
759 questions
{count} votes

10 answers

Sort by: Most helpful
  1. Ross Hemingway 91 Reputation points
    2022-06-21T01:04:23.86+00:00
    0 comments No comments

  2. Jurriaan van Doornik 26 Reputation points
    2022-06-23T11:47:30.013+00:00

    While we are in the process of building RRAS up for our environment (and the ones working on that bit of the environment have been referred by me to this thread), I ran into this issue on our 2019 build 1809 server running our backup solution. Getting dropped a load of notifications on backup failures out of the blue (mostly centered on connection errors).

    The application starts and is accessable as a web-page from my client system normally. Getting an RDP session to the server also isn't an issue... But as soon as I start an actual backup it apparently does something in the background.

    The webpage drops dead with the notification : Site unreachable: ERR_CONNECTION_RESET
    The RDP at that point is also dropped

    After about 2 minutes a refresh of the web-page and a re-establishment of the RDP session seems to work normally again, and the backup at that point seems to be active. And the only thing done yesterday was installing this specific fix (KB5014692) yesterday on both servers.

    As an aside, as part of the disk-verification mechanism used by the application both HyperV and RRAS services are installed and active on both servers. So that does tie in with the reports on RRAS and possibly HyperV.

    I've deinstalled this update and that does seem to sort the problem. So far I have not run into problems on any of our other servers (RRAS or otherwise, tho I did emphasize this issue seems to only hit RRAS installed servers), but I've given notice to most everyone involved that this patch may be causing issues, so they're not stuck wondering how and what but can atleast try if a deinstallation sorts the issue.

    If it does I hope Microsoft will get on this, and sort this issue for the next CU in July.

    0 comments No comments

  3. Martin Richter 1 Reputation point
    2022-06-24T06:37:44.387+00:00

    Same problems here.
    Windows Server 2019.

    VPN Access was broken. NAT works.
    Trying uninstalling the KB5014692 never fiishes. Waited 60minutes at "100% uninstalling".
    Finally got a Backup for the HyperV Image.

    Works again.
    Disabled Udates now.


  4. Martin Richter 1 Reputation point
    2022-07-07T07:42:57.52+00:00

    After disabling all updates on Jun 24 2022 and restoring a backup of the VM I reenabled updates again today.

    First update KB5014692 came in and everything was broken again. RDP, VPN, IIS.... reboot was required after the update.
    Than update KB5014699 was installed, after this update everything was running again.

    0 comments No comments

  5. danno 0 Reputation points
    2023-01-22T16:45:04.65+00:00

    Still don't have RRAS/VPN capability on the Windows 2019 server - this is an AWS Lightsail server. Here's what I had tried:

    • uninstalling KB5014692 - kept failing uninstall, even after trying things like clearing out the update catalog, using command line wusa ..., etc.
    • No ability to take simple images of an AWS server and restore from external disk, can only take 'snapshots' and create new instance from it. This takes all day to recover from since all software licensing becomes invalidated, so passed on this (didn't need VPN at this time). Besides, because it's an AWS server, don't have complete control to prevent the reinstall. Also, don't know how to block this 'bad' update, but allow future updates. Windows Server doesn't allow 'hiding' of updates.
    • Now, the VPN is needed again and I'm trying to avoid the difficulty of configuring a 3rd party VPN (such as OpenVPN), especially since the built-in VPN (using L2TP/IpSec) was working prior to KB5014692.
    • checked this reference: - https://www.bleepingcomputer.com/news/microsoft/recent-windows-server-updates-break-vpn-rdp-rras-connections/ - checked ipnat.sys - has even newer version than what's mentioned here
    • can't install KB5014699 - it's blocked with error 'this update not applicable...'. Shouldn't need to do this if the concept of 'cumulative updates' applies, since several months worth of cumulative updates have been installed since 6/2022.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.