Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

enterprise questions

Status
Not open for further replies.

david902

MIS
Jan 6, 2000
160
0
0
US
I work for a fairly large company with alot of remote access user/clients/vendors. right now we have no policy or ways to enforce that these computers are a. running an updated version of windows and b. running updated antivirus definitions.

we've got remote access users with Welchia worm, everytime one of these users dials-up to the network, the network slows down considerably. Some of these user ain't smart enough to update their own systems.

what do large enterprises do in these situatuations with a large number of remote access users to verify their systems are patched or running the latest virus defs ?

I may be dreaming but there should be a solution to check software versions and require a certain level of software to allow the user to connect to the network, otherwise updates are pushed and installation required before a remote access connection can be made.

I want to require a minimum of Windows 2000 Service Pack 3 and antivirus defs no older than 30 days before a connection is made.

This would not only be for dial-up but for VPN access also.

I've got to take this issue up with management today.

thanks for your input.

 
Well, your meeting is probably already over, but what you describe entails a LOT of work. Solutions range from:

- Microsoft SUS and Symantec corporate anti-virus, to

- Multi-million dollar asset management systems that are integrated with your VPN, domain controllers, or whatever.

From a philosophical point of view, I would never allow "clients" or "vendors" access to the heart of my network, because I cannot control what they do on their machines. That's what extranets are for. For "roaming" employees, I can control them, and force them to follow our policies.

On a side note, none of the recent MS vulnerabilities were covered by 2K SP3 or even SP4. You really need a qualified process to download, test, and deploy those patches to your users. Your customers' IT managers probably wouldn't appreciate you patching THEIR machines, however!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top