SonicWALL 5.8.1 Microscope & Magnifier User Manual


  Open as PDF
of 1490
 
User Management
1003
SonicOS 5.8.1 Administrator Guide
Benefits of SonicWALL SSO
SonicWALL SSO is a reliable and time-saving feature that utilizes a single login to provide
access to multiple network resources based on administrator-configured group memberships
and policy matching. SonicWALL SSO is transparent to end users and requires minimal
administrator configuration.
By automatically determining when users have logged in or out based on workstation IP
address traffic, or, for Terminal Services or Citrix, traffic from a particular user at the server IP
address, SonicWALL SSO is secure and hands-free. SSO authentication is designed to operate
with any external agent that can return the identity of a user at a workstation or Terminal
Services/Citrix server IP address using a SonicWALL ADConnector-compatible protocol.
SonicWALL SSO works for any service on the SonicWALL security appliances that uses user-
level authentication, including Content Filtering Service (CFS), Firewall Access Rules, group
membership and inheritance, and security services (Application Control, IPS, GAV, and SPY)
inclusion/exclusion lists.
Other benefits of SonicWALL SSO include:
Ease of use — Users only need to sign in once to gain automatic access to multiple
resources.
Improved user experience — Windows domain credentials can be used to authenticate a
user for any traffic type without logging into the appliance using a Web browser.
Transparency to users — Users are not required to re-enter user name and password for
authentication.
Secure communication — Shared key encryption for data transmission protection.
SonicWALL SSO Agent can be installed on any Windows server on the LAN, and TSA can
be installed on any terminal server.
Multiple SSO Agents — Up to 8 agents are supported to provide capacity for large
installations
Multiple TSAs — Multiple terminal services agents (one per terminal server) are supported.
The number depends on the SonicWALL appliance model and ranges from 4 to 256.
Login mechanism works with any protocol, not just HTTP.
Browser NTLM authentication — SonicWALL SSO can authenticate users sending HTTP
traffic without using the SSO Agent.
Mac and Linux support — With Samba 3.5 and higher, SonicWALL SSO is supported for
Mac and Linux users.
Per-zone enforcement — SonicWALL SSO can be triggered for traffic from any zone even
when not automatically initiated by firewall access rules or security services policies,
providing user identification in event logging or App Flow Monitoring.
Platforms and Supported Standards
SonicWALL SSO is available on SonicWALL NSA Series appliances running SonicOS
Enhanced 5.0 or higher, and SonicWALL PRO security appliances running SonicOS Enhanced
4.0 or higher. The SonicWALL SSO Agent is compatible with all versions of SonicOS Enhanced
that support SonicWALL SSO. The SonicWALL TSA is supported on SonicOS Enhanced 5.6
and higher, running on SonicWALL NSA Series and TZ 210 Series appliances.