Insights /Network, VPN and firewall

How to allow antivirus updates on an isolated corporate network without enabling general internet access

Use defined sources, vendor update destinations, required ports, controlled DNS recursion, time synchronisation, logging, and default deny to create auditable least-privilege egress.

Quick answer

Use defined sources, vendor update destinations, required ports, controlled DNS recursion, time synchronisation, logging, and default deny to create auditable least-privilege egress. For this case, first verify update-server and endpoint source addresses and vendor update FQDNs and CDN changes, then use DNS resolution path to decide whether remediation is needed.

Define the failure boundary first

For this operations and change-management case, establish the failure boundary with update-server and endpoint source addresses and FQDN CDN, then continue to DNS. Capture the current state, incident time and one known-good comparison before changing production configuration.

Work through the dependency chain

CheckWhy it mattersRecommended action
01 · update-server and endpoint source addressesVerify update-server and endpoint source addresses on the affected path using logs, counters or state information rather than relying only on the configured rule.Record the current value, evidence source and timestamp for update-server and endpoint source addresses. If adjustment is required, change one condition only and retain the original setting for rollback.
02 · vendor update FQDNs and CDN changesVerify vendor update FQDNs and CDN changes on the affected path using logs, counters or state information rather than relying only on the configured rule.Check vendor update FQDNs and CDN changes read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation.
03 · DNS resolution pathVerify DNS resolution path on the affected path using logs, counters or state information rather than relying only on the configured rule.Compare DNS resolution path with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production.
04 · required outbound TCP 80/443Review the current state, related logs and recent changes for required outbound TCP 80/443, then align them with the incident timeline before deciding whether a change is required.Record the current value, evidence source and timestamp for required outbound TCP 80/443. If adjustment is required, change one condition only and retain the original setting for rollback.
05 · default deny and hit loggingReview the current state, related logs and recent changes for default deny and hit logging, then align them with the incident timeline before deciding whether a change is required.Check default deny and hit logging read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation.
06 · failure rollback and antivirus-definition version validationReview the current state, related logs and recent changes for failure rollback and antivirus-definition version validation, then align them with the incident timeline before deciding whether a change is required.Compare failure rollback and antivirus-definition version validation with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production.

Change only after the evidence is clear

  1. Start with read-only evidence. Check update-server and endpoint source addresses and vendor update FQDNs and CDN changes before changing configuration.
  2. If the first checks are normal, continue with DNS resolution path and required outbound TCP 80/443, keeping evidence tied to the incident time.
  3. Change configuration only when the evidence explains the symptom. For default deny and hit logging, preserve the original value and define the rollback trigger before adjustment.
  4. Validate failure rollback and antivirus-definition version validation in a controlled scope before expanding to production users or traffic.

Validation and rollback

  • Validate the complete user or application workflow; do not stop at the single status of update-server and endpoint source addresses.
  • Recheck default deny and hit logging and failure rollback and antivirus-definition version validation after the change and confirm that no new bypass, permission expansion or secondary error has appeared.
  • Archive evidence from update-server and endpoint source addresses through failure rollback and antivirus-definition version validation, together with before/after configuration, business validation and the rollback point.

Common wrong turns

  • Changing update-server and endpoint source addresses and FQDN CDN at the same time, which makes the original cause impossible to prove.
  • Treating a normal result for DNS as proof that required outbound TCP 80/443 and the rest of the business path are healthy.
  • Leaving a temporary exception related to default deny and hit logging or failure rollback and antivirus-definition version validation in production without an owner, expiry time and rollback note.

Related questions

Where should I start with “How to allow antivirus updates on an isolated corporate network without enabling general internet access”?

Start with update-server and endpoint source addresses and vendor update FQDNs and CDN changes; they establish the first useful troubleshooting boundary without changing production state.

What should be checked after the first layer looks normal?

Continue with DNS resolution path and required outbound TCP 80/443, then correlate the result with the incident time and the actual user or application path.

What should be retained after the change?

Keep evidence for default deny and hit logging and failure rollback and antivirus-definition version validation, plus the original configuration, validation result, observation notes and rollback point.

PreviousThe same Group Policy applies to some computers but not others: a complete troubleshooting sequenceNextWhy is Office 2016 slow to start or open documents on a fully isolated network?

Need an assessment based on your actual environment?