Welcome to TechNet Blogs Sign in | Join | Help

Questionable users

You may have noticed that in certain cases, the Client Username field in the ISA firewall log has user names with question marks - (?) - after them:
 

Who are these questionable users?

These user names appear when you have a policy rule which allows All Users, and a Firewall Client (FWC) computer passes through that rule. Since the ISA policy doesn't require authentication, ISA doesn't perform authentication with the client. But During FWC channel establishment, the client computer sends the user name to the ISA computer. ISA knows what name the user claims to have, but ISA never verified it. To convey this situation, the user is displayed with a question mark.

So should you rely on these user names?

  • If you're suspecting malicious action, then you shouldn't. An attacker can easily forge any user name he wants - he can simply create a local user with the desired name on his own computer, and connect while logged-on as that user.
  • If not, then these user names may help. For example, if user X complains about connection problems, then you could look at the ISA log with a "Client username contains X" filter.

 P.S. Real, authenticated user names appear with a domain prefix: DOMAIN\username.

 

-Jonathan Barner
ISA Server Sustained Engineering Team

Published Wednesday, October 03, 2007 3:42 PM by isablog
Filed under: ,

Comments

# re: Questionable users

10x Jonathan for description :)

Friday, October 05, 2007 5:09 AM by BlackPH

# Software a dokumenty ke stažení - listopad 2007

Security Microsoft and Novell Open Interoperability Lab http://www.microsoft.com/presspass/press/2007/sep07/09-11MSNovellLabsPR.mspx

Saturday, December 01, 2007 7:27 AM by TechNet Blog CZ/SK

# re: Questionable users

News BizTalk Server BizTalk Server Roadmap (updated) http://www.microsoft.com/biztalk/evaluation/roadmap/default.mspx

Tuesday, May 26, 2009 4:01 AM by HD Video Converter
Anonymous comments are disabled
 
Page view tracker