Created on ‎02-03-2011 03:08 AM
They do it for SSL VPN and for admin access so why not for end users.Because in the case of SSL VPN or admin access the ' stateful' device is the FG itself. It has full control over the session it has allowed. So when you click the ' logout' button it kills the corresponding session. For IBPs, the first problem is how to authenticate: it takes an interactive process to enter credentials. So you can use HTTP, HTTPS, ftp or telnet. How would a user notify the FG that he/she wants to log out? After all, traffic from the user is authenticated and the firewall is no longer watching it. I am still trying to think of a decent way how to handle a logout request interactively if all the FG sees is a data stream. And when the user logs out and somehow notifies the FG of this fact, should all of his sessions be killed? Or certain protocols only, or sessions from a certain host only? Ain' t that easy.
Created on ‎02-09-2011 02:14 AM
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.