Setup a WSUS server and edit the policies on that required server to use the WSUS server to receive updates. If the AV you use is a corporate edition, then it too can have update servers setup on the network. If you use a hardware firewall, block all Internet activity of the IP and add the update servers of windows and AV as exceptions. Note that there might be 10~20 update server IPs for load balancing. Try to find out all possible update server addresses and add them to exception.