A question that comes up frequently involving federated customers is how does an organization need to configure its firewalls to allow users in a trusted, but not fully trusted, domain to access their resources. Consider the following scenario: [WEB RESOURCE]---|---FIREWALL---WAN---FIREWALL---|---[USER