User identification (User-ID™)—The User-ID feature
allows administrators to configure and enforce firewall policies
based on users and user groups instead of or in addition to network
zones and addresses. The firewall can communicate with many directory
servers, such as Microsoft Active Directory, eDirectory, SunOne,
OpenLDAP, and most other LDAP-based directory servers to provide
user and group information to the firewall. You can then use this
information for secure application enablement that can be defined
per user or group. For example, the administrator could allow one
organization to use a web-based application but not allow any other
organizations in the company to use that same application. You can
also configure granular control of certain components of an application
based on users and groups (see
User
Identification).