Deb Shinder Blog RSS

All Blogs  »  Deb Shinder Blog  »  News ISA Central  »  Blog article: ISA Firewall Auto Log Off Controls Can Be a Security Issue for OWA Publishing

ISA Firewall Auto Log Off Controls Can Be a Security Issue for OWA Publishing

One of the features that I really liked about previous versions of the ISA Firewall (2000 and 2004) was the auto logoff when the user navigated about from the OWA page. I was very disappointed when this feature was removed from the 2006 ISA Firewall. I asked some of the ISA Firewall Team members why this feature was removed, and I got a variety of responses, mostly saying that auto logoff was problematic and difficult to make work right.

However, even with the previous versions of the ISA Firewall, if a pop-up blocker is enabled on the browser, the auto logoff feature still wouldn’t work.

This is a real problem, because users at kiosks, public computers, and unmanaged computers can leave the OWA site and think that they’re automatically logged off. If another person comes to the same computer later, he can look at the URL history in the Internet Explorer address bar and click on the OWA URL and be automatically logged on. This can be seen as a significant security issue, even when form-based authentication is used.

However, there is a solution. Messageware has a product called NavGuard that solves this problem. With NavGuard, users are automatically logged off when they move away from the OWA site and they’re given prompts about whether they want to log off or not.

For more information on this ISA Firewall security issue in OWA environments, check out Messageware’s White Paper on this issue at http://www.messageware.com/ISAWhitePaper.htm

HTH,

Tom

Thomas W Shinder, M.D.
Site: www.isaserver.org

Blog: http://blogs.isaserver.org/shinder/
Book: http://tinyurl.com/3xqb7

Email: tshinder@isaserver.org

MVP — Microsoft Firewalls (ISA)

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Follow TechGenix on Twitter