Sunday, June 28, 2020

Windows update out locally on a full tunnel?

Hey everyone,

I've got requirements that conflict against our capacities.

Oh the one hand, I've got regulatory requirements for full tunnels, always-on VPN, consistent patch remediation, and FIPS-validated crypto.

On the other, I've got 1500 WFH users who are actually in the habit of shutting down at night.

Which means their windows updates like to saturate my internets during business hours.

How can I make this work and still comply? FIPS-validated means I'm cornered into FortiOS 5.6. Can I poke MS servers out locally and still be in compliance and save some of my bandwidth? Could that even be done in 5.6?



No comments:

Post a Comment