官术网_书友最值得收藏!

Authenticating users with User-ID

Frequently neglected but very powerful when set up properly is a standard feature called User-ID. Through several mechanisms, the firewall can learn who is initiating which sessions, regardless of their device, operating system, or source IP. Additionally, security policies can be set so users are granted access or restricted in their capabilities based on their individual ID or group membership.

User-ID expands functionality with granular control of who is accessing certain resources and provides customizable reporting capabilities for forensic or managerial reporting.

Users can be identified through several different methods:

  • Server monitoring:

    --Microsoft Active Directory security log reading for log-on events

    --Microsoft Exchange Server log-on events

    --Novell eDirectory log-on events

  • The interception of X-Forward-For (XFF) headers, forwarded by a downstream proxy server
  • Client probing using Netbios and WMI probes
  • Direct user authentication

    -- The Captive Portal to intercept web requests and serve a user authentication form or transparently authenticate using Kerberos

    -- GlobalProtect VPN client integration

  • Port mapping on a multiuser platform such as Citrix or Microsoft Terminal Server where multiple users will originate from the same source IP
  • The XML API
  • A syslog listener to receive forwarded logs from external authentication systems
主站蜘蛛池模板: 郎溪县| 柘城县| 五河县| 景东| 安国市| 房产| 中西区| 贵阳市| 金门县| 葫芦岛市| 奉贤区| 广河县| 绥阳县| 四子王旗| 房产| 吴堡县| 内黄县| 正镶白旗| 北流市| 林州市| 桑植县| 高邑县| 正宁县| 涡阳县| 乃东县| 松江区| 微山县| 仲巴县| 那曲县| 苏尼特右旗| 清苑县| 东丰县| 闸北区| 西乌珠穆沁旗| 资阳市| 贵阳市| 鄱阳县| 深州市| 双城市| 浦城县| 建德市|