官术网_书友最值得收藏!

Authenticating users with User-ID

Frequently neglected but very powerful when set up properly is a standard feature called User-ID. Through several mechanisms, the firewall can learn who is initiating which sessions, regardless of their device, operating system, or source IP. Additionally, security policies can be set so users are granted access or restricted in their capabilities based on their individual ID or group membership.

User-ID expands functionality with granular control of who is accessing certain resources and provides customizable reporting capabilities for forensic or managerial reporting.

Users can be identified through several different methods:

  • Server monitoring:

    --Microsoft Active Directory security log reading for log-on events

    --Microsoft Exchange Server log-on events

    --Novell eDirectory log-on events

  • The interception of X-Forward-For (XFF) headers, forwarded by a downstream proxy server
  • Client probing using Netbios and WMI probes
  • Direct user authentication

    -- The Captive Portal to intercept web requests and serve a user authentication form or transparently authenticate using Kerberos

    -- GlobalProtect VPN client integration

  • Port mapping on a multiuser platform such as Citrix or Microsoft Terminal Server where multiple users will originate from the same source IP
  • The XML API
  • A syslog listener to receive forwarded logs from external authentication systems
主站蜘蛛池模板: 黑山县| 洪洞县| 江孜县| 嘉鱼县| 兰西县| 陆良县| 牙克石市| 英德市| 额尔古纳市| 永川市| 双鸭山市| 云浮市| 华安县| 浏阳市| 皋兰县| 武山县| 昌黎县| 栾城县| 襄城县| 大冶市| 社旗县| 长岛县| 平阴县| 寻乌县| 广州市| 信阳市| 建瓯市| 神农架林区| 岳阳市| 农安县| 扶余县| 哈巴河县| 桂东县| 石河子市| 昌宁县| 陈巴尔虎旗| 广河县| 湖北省| 水富县| 衢州市| 昌江|