In the console tree of ISA Server Management, click
Firewall Policy.
On the Toolbox tab, click Network Objects.
Expand Web Listeners, and then click the applicable Web
listener.
On the toolbar beneath Network Objects, click
Edit.
On the RSA SecurID tab, verify that the Ignore
browser IP address for cookie validation is not selected.
Important
Another way to further protect cookies is by minimizing the
cookie expiration time.
Notes
To open ISA Server Management, click Start, point to
All Programs, point to Microsoft ISA Server, and then
click ISA Server Management.
For ISA Server 2006 Enterprise Edition, expand
Microsoft Internet Security and Acceleration
Server 2006, expand Arrays, expand
Array_Name, and then click Firewall
Policy.
For ISA Server 2006 Standard Edition, expand Microsoft
Internet Security and Acceleration Server 2006, expand
Server_Name, and then click Firewall
Policy.
Important
When you enable this option, the cookie retains and signs the
client's IP address, thereby guaranteeing that a user cannot use
the same cookie from a different IP address.