This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

STAS Logoff Detection & RDP

Since the implementation of STAS SSO, we’ve had a problem with users being logged out of the firewall (logged out of STAS) when the user is connected to their workstation via RDP.  Note, when the user is connected directly to the console of their workstation machine, STAS works beautifully.

The cause is easy to figure out, but the answer is not.  I’m wondering what the short-term solution is, and if the knuckleheads at Sophos have ever thought about a better way to do logoff detection?  Like the Sophos recommendations suggest, we have enabled STAS Logoff Detection with workstation polling using WMI.  It is widely known that WMI will not report the current user who is logged on to a workstation via RDP.  WMI will only report the current user logged in via the machine console.  Hence, while RDP users initially authenticate with the firewall via STAS, after the detection polling interval, they are “logged out.”

Our environment is comprised of workstations which can be accessed locally or remotely via RD Gateway and RDP.  Note, these are single-interactive-session Windows workstations, not multi-user RDP terminal servers.  This setup is not unusual, which leads me to believe someone, somewhere has come across this.  So, what should we do, and what are the ramifications of each?

  1. Turn off Logoff Detection. Do I really care whether STAS detects logoffs?  We do have several “community use” workstations, where many different users log on and off throughout the day.  It is imperative that AD User & Group based firewall policies be applied correctly to the currently logged on user.  At present, this is working correctly, but I fear turning off Logoff Detection might make this less reliable.
  2. Change the Workstation Polling method to Registry Read Access. I understand that this method requires turning on the remote registry service on the workstations (which is a pain in the ass).  And, assuming running the Remote Registry service doesn’t present some unforeseen security risk, I’m not even sure it will solve the problem.  Will the Registry Read Access polling method identify a user logged on via RDP?
  3. Wait for Sophos to find a better way to do logoff detection.
  4. Find a better firewall vendor.


This thread was automatically locked due to age.
Parents Reply Children
No Data