?
Solved

Windows Server security/ Virus Definition update methods.

Posted on 2003-12-09
2
Medium Priority
?
595 Views
Last Modified: 2010-04-11
Hello Everybody.

I have a question that is more methodical rather than purely technical, I hope tha is OK. My servers have been hit with a virus two months after we purchased many licenses for Norton AV.

(never installed it)

The previous version was running with outdated definitions prior to this. Since being hit by the new virus, we have applied the new AV software and definitions. NAV uses 'Live Update' to go out over the net and download newer virus definitions on a regular basis.

Now, coming from an IP network/ router background, my first inclination is cut these servers off from the internet, and allow only DNS & some higher level custom TCP ports through. I could possibly open a hole in my FW for LiveUpdate, or I could delegate the download function to a DMZish server from which the updates can be periodically pulled. (Or can't I?- does NAV support this?)

I know the dangers of treating every problem like it was a nail when the only tool you own is a hammer. Is this an appropriate network transport issue? What is the industry prevalent method of insulating servers from the internet and updating/verifying virus definitions?


/john
0
Comment
Question by:johndarpino
2 Comments
 
LVL 1

Accepted Solution

by:
NeilDavis earned 750 total points
ID: 9905695
We dont use live update for our AV servers.  Instead we use a batch file avaliable from symantec follow this link:

http://service1.symantec.com/SUPPORT/ent-security.nsf/d04e6f2f2dfad5de88256c910079502c/80e201e3738ae3cc88256c55004c28f4?OpenDocument&src=bar_sch_nam

I find the batch file works better and you can modify and run from a machine in you DMZ.
0
 
LVL 4

Expert Comment

by:MobileOakAI
ID: 9909659
We are going the same way, I think. FTP pattern to our server. Then, the clients are scheduled to check the server at regular intervals (use SAVROAM to locate server).  In case of trouble on network, other options including liveupdate from our client to our server is option, and we also stick it on our webserver, to cover anyone else, such as for a few laptops.

Do also a better job of getting updates from Microsoft.  They have weekly vulnerabilities and now should be only once a month downloads.  I'd guess that your servers got hit because they were short on an upgrade from Microsoft as well, and exploited. That is all too common these days.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes Administrators rights are not enough. These cases call for the SYSTEM account. The process in this article outlines the steps required to execute commands using the SYSTEM account.
It’s a season to be thankful, and we’re thankful for users like you who engage on site, solve technology problems, and network with others in the industry. What tech are we most thankful for? Keep reading.
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question