Windows Server security/ Virus Definition update methods.

Posted on 2003-12-09
Medium Priority
Last Modified: 2010-04-11
Hello Everybody.

I have a question that is more methodical rather than purely technical, I hope tha is OK. My servers have been hit with a virus two months after we purchased many licenses for Norton AV.

(never installed it)

The previous version was running with outdated definitions prior to this. Since being hit by the new virus, we have applied the new AV software and definitions. NAV uses 'Live Update' to go out over the net and download newer virus definitions on a regular basis.

Now, coming from an IP network/ router background, my first inclination is cut these servers off from the internet, and allow only DNS & some higher level custom TCP ports through. I could possibly open a hole in my FW for LiveUpdate, or I could delegate the download function to a DMZish server from which the updates can be periodically pulled. (Or can't I?- does NAV support this?)

I know the dangers of treating every problem like it was a nail when the only tool you own is a hammer. Is this an appropriate network transport issue? What is the industry prevalent method of insulating servers from the internet and updating/verifying virus definitions?

Question by:johndarpino

Accepted Solution

NeilDavis earned 750 total points
ID: 9905695
We dont use live update for our AV servers.  Instead we use a batch file avaliable from symantec follow this link:


I find the batch file works better and you can modify and run from a machine in you DMZ.

Expert Comment

ID: 9909659
We are going the same way, I think. FTP pattern to our server. Then, the clients are scheduled to check the server at regular intervals (use SAVROAM to locate server).  In case of trouble on network, other options including liveupdate from our client to our server is option, and we also stick it on our webserver, to cover anyone else, such as for a few laptops.

Do also a better job of getting updates from Microsoft.  They have weekly vulnerabilities and now should be only once a month downloads.  I'd guess that your servers got hit because they were short on an upgrade from Microsoft as well, and exploited. That is all too common these days.

Featured Post

We Need Your Input!

WatchGuard is currently running a beta program for our new macOS Host Sensor for our Threat Detection and Response service. We're looking for more macOS users to help provide insight and feedback to help us make the product even better. Please sign up for our beta program today!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Spectre and Meltdown, how it affects me and my clients?
Are you looking to start a business? Do you own and operate a small company? If so, here are some courses you need to take before you hire a full-time IT staff.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…

624 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question