Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


March 2007

Patch Management Solutions

See how WSUS stacks up against two popular ISV offerings
RSS
Subscribe to Windows IT Pro | See More Products / Software Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

PatchLink Update 6.3
PatchLink Update 6.3 is an agent-based, multiplatform patch management product that provides agents for Novell NetWare, Mac OS X, Windows, and several Linux platforms. You use policies to configure the agents to periodically scan for applicable vulnerabilities. You can then schedule deployments of Packages, which are patches for one or more vulnerabilities. PatchLink Update runs on Windows 2003 and, like the other products reviewed, can store patch deployment data in a SQL Server database. PatchLink Update uses SQL Server Express if SQL Server isn't available.

The evaluation copy of PatchLink Update 6.3 came preinstalled on a VMware virtual machine (VM). This was a nice touch that made evaluating the product easier.

PatchLink Update uses a patching cycle that begins by downloading an XML file from PatchLink. This file lists available software patches for the supported software. You then use the Web-based administrator console to schedule or manually initiate scans for vulnerabilities. Based on the results of the vulnerability scan, PatchLink Update distributes patch deployments to agents. The patches can be prestaged on the server or downloaded from software vendor Web sites immediately prior to their deployment. PatchLink Update also can roll back patches after they're installed.

PatchLink Update can accommodate a variety of network topologies by using distribution points. This lets you locate patch content closer to clients or load-balance clients across multiple distribution points. PatchLink Update recognizes and patches vulnerabilities in the supported OSs, Microsoft server and desktop applications, and other popular applications such as Adobe Acrobat and Flash, Mozilla Firefox, Apple QuickTime, and WinZip.

In addition to collecting vulnerability information, PatchLink Update performs an inventory of hardware, services, and installed software. The Web-based interface displays the inventory organized in several ways and with several summary levels (as Figure 2 shows), and this data can be exported in CSV, XLS, and XML formats. Neither of the other products in this review collected such inventory information.

PatchLink Update is also the only product reviewed that includes an interface for creating system users and assigning role-based permissions. For example, you can give an administrator read-only access to PatchLink Update's inventory data (the Guest role) or full access to a subset of the managed computers.

Even if you've scheduled regular vulnerability scans, PatchLink Update lets you force a vulnerability scan. That way, when a major software vulnerability is discovered, you can use an on-demand scan to more quickly identify and deploy the needed patch.

The PatchLink Update report module is configured with several useful reports. Included are reports (mentioned above) on hardware, software, and service inventory along with the usual reports on missing and deployed patches. One particularly useful report is the Vulnerability Analysis Report, which summarizes several critical metrics relating to specific unpatched vulnerabilities. All report data can be exported in CSV, XLS, and XML formats.

The PatchLink Update agent proved tricky to install on the Linux Fedora Core 4 client that I included in my testing. The agent requires the Sun Microsystems Java Runtime Environment rather than the GNU Java Runtime Environment packaged with Fedora. This could complicate agent deployment in some environments.

To prevent unauthorized connections to the server, the PatchLink Update agent requires you to enter the server license key during installation. Windows installs can use a customized .msi file to automate this step, but it seems unnecessary to require a license key for a software patching agent.

Overall, I found PatchLink Update to be a capable solution worthy of consideration for multiplatform enterprises. In fact, it's my pick as the Editor's Choice product. Its flexible agent software and full set of features will keep a wide variety of enterprise networks patched and secure.

Summary
PatchLink Update 6.3

PROS: Flexible permissions assignment model, support for distribution points, good reporting, cross-platform support
CONS: Complicated agent install, especially
for Linux clients; expensive for UNIX and NetWare clients
RATING: 4 1/2 out of 5
PRICE: $1,495 for a server license, plus $18 per node per year for Windows clients, $75 per node per year for UNIX and NetWare clients, and $33 per node per year for Mac OS X clients
RECOMMENDATION: Recommended for organizations that need multiplatform patch management, flexible administration interface permissions, and complete reporting. Its flexibility makes it my pick for Editor's Choice.
CONTACT: PatchLink • http://www.patchlink.com • 480-970-1025

   Previous  1  [2]  3  Next 


Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Understanding File-Size Limits on NTFS and FAT

A general confusion about files sizes on FAT seems to stem from FAT32's file-size limit of 4GB and partition-size limit of 2TB. ...


Related Articles Enterprise Patch Management Software

5 Tips for Buying Managed Security Services

Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Protecting Mobile Users' Data

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement