User Management
609
SonicOS Enhanced 4.0 Administrator Guide
Figure 52:6 SonicWALL SSO Agent Process
The SonicWALL security appliance queries the SonicWALL SSO Agent over the default port
2258. The SSO Agent then communicates between the client and the SonicWALL security
appliance to determine the client’s user ID. The SonicWALL SSO Agent is polled, at a rate that
is configurable by the administrator, by the SonicWALL security appliance to continually
confirm a user’s login status.
Logging
The SonicWALL SSO Agent sends log event messages to the Windows Event Log based on
administrator-selected logging levels.
The SonicWALL security appliance also logs SSO Agent-specific events in its event log. The
following is a list of SSO Agent-specific log event messages from the SonicWALL security
appliance:
• User login denied - not allowed by policy rule: The user has been identified and does
not belong to any user groups allowed by the policy blocking the user’s traffic.
• User login denied - not found locally: The user has not been found locally, and Allow only
users listed locally is selected in the SonicWALL security appliance.
• User login denied - SSO Agent agent timeout: Attempts to contact the SonicWALL SSO
Agent have timed out.
• User login denied - SSO Agent configuration error: The SSO Agent is not properly
configured to allow access for this user.
• User login denied - SSO Agent communication problem: There is a problem communicating
with the workstation running the SonicWALL SSO Agent.