Jump to content

Recommended Posts

Posted

Hi,

 

Does anyone here use, or have experience of SonicWALL? and it's SSO Agents? It's causing massive issues here!

 

We are experiencing issues with workstations that once a user logs in, the SonicWALL appliance states "Agent returned no user name", therefore it should default to the default CFS policy (e.g. no internet)... except it doesn't and is not filtered (or indeed showing in the real-time log monitor either).

 

Additionally, when checking the (two) SSO Agent servers and querying the same problematic workstations, the WMI and NETAPI queries reply, successfully, returning with the correct username and computer name. Also, the test function within SSO Agent section on the SonicWALL appliance itself completes (and retrieves user and computer name ) successfully too. Therefore, is this some form of SSO Agent to SonicWALL appliance communication issue (despite all tests claiming to be fine???)/

 

Client firewalls disabled etc, as per KB articles.

 

Any assistance would be appreciated.

Posted
We ran sonicwalls for a few years using SSO, and found as long as the SSO agent talked to the unit, and it passed the tests back to AD on the controller, it all worked fine. I believe we used DC and Exchange agents. I would log a support call with SW with a high priority, I found they actually weren't bad at finding and sorting little problems.
Posted
You aren't running anything like proxies or any other filters? Your given DHCP gateway on the machines is the sonicwall box? It sounds like something else is providing them with internet and not the SW
Posted

Thanks @CAWJames for the updates and suggestions...

 

The good news is that during the interim period we have since identified and resolved the problem(s).

 

The SSO Agent was, indeed, the main culprit with issues relating to the Domain Controller log files not being correctly set (even though SonicWALL was correctly configured to use NTLM, NETApi as alternative authentication methods).

 

Despite having configured the various log settings on the Domain Controllers (via Group Policy) and within SonicWALL as per instructions (I had) and for use with FastVue, there were a couple of additional DC log auditing (kerberos) settings that were needed (and only identified) after engineer had to check with another engineer.

 

Appreciated your help and assistance James :smile:

 

Thanks.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...