Why? if the machine that connects to the Internet is fully patched, AV'd and
firewalled, why should all the others have to be (apart from AV if they will
be using email)? If something gets through the connected machine then it's
gonna get through, no matter what the other machines are like.
Firewalls do most of their work at the network level, blocking bad
packets and hacking attempts.
AntiVirus protection applies to the computer that the AV protection is
installed on. It doesn't apply to the network traffic passing thru a
firewall (proxy server) to another computer.
Patches protect the computer that they're installed on.
Browser exploits, and similar attacks, occur at the application layer,
on the computer that runs the browser. A browser exploit is not
detected by a firewall; to the firewall, it is simply data in packets.
If a hostile website, accessed by the target computer, contains a
browser exploit, or a virus, that code will pass thru the firewall
(and proxy server), and attempt to run under the browser on the target
computer.
If the target computer is not up to date with its patches, and does
not have a good, up to date virus and spyware protector, the hostile
code may successfully run and deposit its payload on the target
computer.
Chuck
I hate spam - PLEASE get rid of the spam before emailing me!
Paranoia comes from experience - and is not necessarily a bad thing.