Hi Bob, Thanks for the reply. Perhaps I'm just overthinking it at the moment. I'm new to Sophos and migrating rules from TMG to Sophos and perhaps I can simply use user at the source as they are required to authenticate anyway I should leave the IP source off and simply filter by active user. Thanks, Karl
↧