Hello,
I am running into an issue where a user is able to login to sports.yahoo.com, and from there, they are able to launch their webmail from an icon/link located on sports.yahoo.com.
I found that mg.mail.yahoo.com could still be accessed, so I added it to "Web Protection > Filtering Options > Websites" and assigned it the category of "Web Mail". It will still sometimes let a user view and navigate their email, but only sometimes.
It's like there is an identity transfer or cross-site authentication occurring that sometimes gets flagged by the web filter.
It is important to continue to allow users to login to sports.yahoo.com, but I was hoping anyone could offer some advice on ensuring that the web mail loophole is closed in this scenario.
We are running:
SG210
UTM9
Firmware 9.503-4
This thread was automatically locked due to age.