User not Identified by TSA or only Default CFS Policy Applied to User
07/21/2022 26 People found this article helpful 455,877 Views
Description
No users are identified by the TSA (Terminal Service Agent) on a particular terminal server or the users are identified correctly but only the default CFS policy is applied.
Cause
The web request of the user is proxied by a web filter service on the terminal server.
One example for this is the Sophos web filter included in the Sophos endpoint protection.
Because of the proxy the connection will be incorrectly identified as originating from the user that the proxy runs under (usually local system account) instead of the actual user that tries to view a web page.
To identify this issue do the following:
- Enable verbose logging on the SonicWall Terminal Service Agent for the particular terminal server
- Login a user on the terminal server
- Try to browse to a website that no other user will currently use (ideally one with only a single IP, for example www.cork.ie which resolves to 89.185.146.136 at this time)
- Open the Terminal Service Agent and view the logs
- In the logs, search for the IP of the website that you tried to access
- You should see which user was identified for this particular connection
- If this user is not the user actually trying to access the website, chances are that the connection was proxied
- You will be seeing the user session ID would be identified as "0"
Resolution
- Disable the proxy functionality of your endpoint protection suite.
- Once you disable the proxy functionality or remove the endpoint protection for testing, the logging will be indicating correct user session ID relating to the user instead of "0"
- Kindly refer the below before disabling the proxy functionality
07/13/22:15:31:12 Debug Id:20688 handleOpenAddress: Remote IP Address: '46.x.x.x:80' SessionId: '0'
- After disabling the proxy functionality;
07/13/22:15:58:47 Debug Id:3752 handleOpenAddress: Remote IP Address: '46.x.x.x:80' SessionId: '2'
Related Articles
Categories
Was This Article Helpful?
YESNO