Welcome to OUR GLOBAL IT COMMUNITY.

Bringing together top IT experts, IT professionals and you to find solutions to today's biggest IT challenges. Ask for expert advice, post a solution and surround yourself with IT knowledge.

MEET THE EXPERTS

Brian Milne
Brian Milne
Daniel Petri
Daniel Petri
Debra Shinder
Debra Shinder
Lawrence Abrams
Lawrence Abrams
Lowell Heddings
Lowell Heddings
Jenny Stout
Jenny Stout

Expert Profile

Blair Briggs

Blair Briggs

I’M BLAIR BRIGGS, THE EDITOR AND FOUNDER of GEEKSTOGO.COM
I’m the editor and founder of geekstogo.com, which offers free, high-quality tech support in a non-technical way. Geeks to Go was started in 2003 to bring tech experts together with people who need tech help, and offering it in a free, friendly environment. Our forums have attracted almost 300,000 members. We have a worldwide audience of 1.2M unique visitors.

Contributions

2

My Answers

Question:
December 7, 2009 at 11:12 AM
Answer:
You don't say what software you're running on the server and clients. If running Server 2008, and Windows 7, or have plans to upgrade soon, then the Direct Access feature looks tailor made for you.

If not, I would recommend the VPN.
Question:
December 7, 2009 at 10:12 AM
Answer:
Some good advice offered already. Drive-by downloads are rarely successful on fully patched systems. Group policies, and features like Network Access Protection available in Server 2008 will help keep users systems updated and secure.

Since you mention Windows 7 and sandboxing, it got me thinking about Windows XP mode. I'm guessing we'll see some creative uses of this integrated virtual machine to prevent browsers from infecting the host OS.

Antivirus vendors are promoting the cloud as a means to offer "real-time" definition updates. While it may increase their detection rates slightly, I don't see this as a game changer. I have seen DNS filtering, such as offered by OpenDNS be surprisingly simple and effective.