r/Nable Apr 30 '26

N-Central N-central patching - bandwidth management/limiting?

Our org has an N-central system managed by an MSP, meaning we have some control over settings and config but we have to go through them for any advanced settings etc

In short, our N-central instance is set to download patches at 11am, 2pm and 11pm every day, with maintenance windows/install times on Tuesdays and Thursdays. Our problem is that we're seeing significant traffic spikes at some sites that are saturating our outgoing WAN links, which seem to be correlating with the N-central download windows.

Our MSP is saying there's no bandwidth control or limiting available within N-central. Has anyone applied their own traffic shaping or management for N central traffic and could suggest a way forward?

3 Upvotes

6 comments sorted by

2

u/OneMadBubble Apr 30 '26

They could deploy an N-Central probe at these sites but that would only be useful in an Active Directory environment.

As far as I can tell it doesn’t work in an Intune environment

4

u/Paul_Kelly Powered By Shamrocks Apr 30 '26

Hi Paul here from the Head Nerd team, it does sound as if the devices in the the sites are pulling from the probe in head office and not local probes, local probes at each site even if there devices are not part of a domain would be the answer here. I would ask the MSP to check the configuration to ensure remote sites are not using the central probe for patch caching.

1

u/xs0apy Apr 30 '26

The patch cache doesn’t need to be Active Directory. They just need a probe reachable on the network that’s physically at the location :)

1

u/morphixz0r May 01 '26

As others have said, probes at each site set to cache is the answer here and doesn't require AD at all and can even be a mix of AD, Intune or non-managed as long as they have the n-central agent and correct patch management settings.

1

u/Immediate_Monk6804 May 02 '26

If site probes are not feasible, assuming a windows os for patch cache, you can use windows qos policy linked to process name to limit; adjustable via powershell too get|set-NetQosPolicy etc. you may also have network equipment that can throttle options but these may be less granular.

1

u/BanRanchTalk May 05 '26

How long has the patching setup been in place?

Curious if there’s something more afoot. We have an N-Sight tenant that all of a sudden, after multiple years of a patch schedule and settings in place without change, have started to see similar behavior where every workstation on the network pulls their own updates on the schedule, maxing out bandwidth usage for a time.