I believe I've not explained, if one of my terminal servers is, i.e., 172.30.2.121 and in the Traffic Log I use the filter " ( addr.src in 172.30.2.121 ) " I can see a lot of traffic sourced from the server, almost all of it is with EMPTY user and source port=System Port Allocation Range, a little bit is with user and source port=User Port Allocation Range Isn't this enough to say that I don't have user information for the server? I've made test rules with source ip only=terminal servers and user=any, and of course they're hit. I can't explain how many rules are in production, some servers are to be filtered accounting for logged in users, some servers not, now it's not of interest, the matter is that I don't have user information on TS servers. After show session info there is no other option admin@itsg-fw2(active)> show session info | Pipe through a command <Enter> Finish input
... View more