When the need arises to protect selected user workstations from intrusion and virus epidemics, the administrator usually has to visit each computer to manually install and configure its firewall to comply with corporate security policies. Practically always, the same settings and tools are used with each workstation. In complex distributed networks this requires an administrator to spend a lot of time duplicating the same sets of operations multiple times. Moreover, the administrator must manually reapply all modifications made by each individual user. Additionally, each client itself has to download firewall updates that in large networks may result in excessive Internet.