Can anyone point me to any articles or discussions on how best to handle
using automatic Windows Updates with a stateful desktop firewall that
controls inbound and outbound traffic? Many Windows patches start install
processes that require network access. Since most desktop firewalls will
reject or prompt users for permission before allowing new and untrusted
processes to access the network, by default these updates will fail if left
unattended. And since the executables for the processes do not exist until
the patch is download, they could not be trusted in advance.
If you have any suggestions or can refer me to articles, it would be
appreciated.
Joe
|