We are an organization with about 800 network connected
pc's that have access to the internet. We run Norton
Anti-virus on all the workstations and the signatures are
updated daily. We are behind a Cisco PIX firewall that
only allows established connections back in. Do I need
to be worried about applying all the MS "critical"
updates to all the workstations? Is there a MS article
regarding this that anyone knows of?

Paul

Re: MS Security Updates and Firewall by Bill

Bill
Thu Feb 12 00:27:07 CST 2004

YES.

Does anyone ever plug a laptop into the network which comes, unwashed, from
the outside world?

Do your users open email attachments?

You must assume that the outside world will find a way around your firewall,
and that a virus or worm will eventually wend its way towards you ahead of
Norton's excellent efforts to define it to your client machines.

Do your users open HTTP sessions outbound? Are they able to accept code
downloads to those sessions--signed or not?

This certainly isn't exhaustive, but there are many ways that a worm or
virus can be introduced behind a firewall, or penetrate it, perhaps via
clever social engineering.

In fact, current thinking tends towards firewalling all machines, even those
behind a router or firewall. The firewall in XP SP2 will be controllable
via group policy settings.

http://www.microsoft.com/presspass/newsroom/winxp/WindowsXPSPFS.asp

So--if you are behind a firewall, and you have a firewall running, do you
still need to patch? Yes--patching may prevent an infection--you are still
going to open attachments. There may eventually be an exploit that attacks
a port you have opened in the firewall.

And here's my last-ditch thought: What happens to those 800 machines when
they end useful life for you? Do they go out the door in a way that might
involve continued use--maybe donated to a non-profit? Do you owe that new
user (who may well not be behind a firewall) a machine which is safe to use
in their environment?

Slammer and MSBlaster each had high-profile victims who thought that they
didn't need to patch because they were behind firewalls.


<pbd1963@hotmail.com> wrote in message
news:e08201c3f0b0$86fdb4b0$a301280a@phx.gbl...
> We are an organization with about 800 network connected
> pc's that have access to the internet. We run Norton
> Anti-virus on all the workstations and the signatures are
> updated daily. We are behind a Cisco PIX firewall that
> only allows established connections back in. Do I need
> to be worried about applying all the MS "critical"
> updates to all the workstations? Is there a MS article
> regarding this that anyone knows of?
>
> Paul