Microsoft Direct Access - is user Identification possible?


We have user identification working nicely using user ID agents on a few of our active directory domain members.

I've been looking at MS Direct Access (and formerly UAG) and it seems that a DA implementation would show all connected users as having the same source IP address and therefore user ID. (The private IP address of the DA server.)

Do PA firewalls have a way of identifying which user the traffic inside the DA 'tunnel' is from?

I guess what I'm probably asking for is a 'DA Server User Agent' in the same way that there is a MS Terminal Server Agent which does a similar job.



