User's Manual Part 4

Page 62 SonicWALL SonicOS Standard Administrator’s Guide
Users>Settings
On this page, you can configure the authentication method required, global user settings, and an
acceptable user policy that is displayed to users when logging onto your network. The SonicWALL
supports user level authentication using the local SonicWALL database, a RADIUS server, or a
combination of the two authentication methods.
Authentication Method
Use RADIUS for user authentication - if you have more than 1,000 users or want to add an extra
layer of security for authenticating the user to the SonicWALL. If you select Use RADIUS for user au-
thentication, users must log into the SonicWALL using HTTPS in order to encrypt the password sent
to the SonicWALL. If a user attempts to log into the SonicWALL using HTTP, the browser is automat-
ically redirected to HTTPS. If you select Use RADIUS for user authentication, the Configure button
becomes available.
Allow only users listed locally - enable this setting if you have a subset of RADIUS users accessing
the SonicWALL. The user names must be added to the internal SonicWALL user database on the Us-
ers>Local Users page before they can be authenticated using RADIUS.
Configure users locally - selecting this setting allows you to configure users in the local SonicWALL
database using the Users>Local Users page.
Global User Settings
The settings listed below apply to all users when authenticated through the SonicWALL.
Inactivity timeout (minutes) - users can be logged out of the SonicWALL after a
preconfigured inactivity time. Enter the number of minutes in this field.
Limit login session time to (minutes) - you can limit the time a user is logged into the SonicWALL
by selecting the check box and typing the amount of time, in minutes, in the Limit login session
time to (minutes) field. The default value is 30 minutes.
Allow only authenticated users to access the Internet - this feature allows Internet access to only
users configured on the SonicWALL. There is a corresponding checkbox when adding a user to the
local SonicWALL database allowing you to grant
access to the Internet. When you select Allow only authenticated users to access the
Internet, but always allow these services, the default Key Exchange (IKE) and Name Service
(DNS) services are activated. You can add or remove services available to users. To add a service,
select the service from the menu, and click Add. To remove a service, select the service in the in the
services list, and click Remove.
And always allow these address ranges - this feature allows the specified IP address or IP address
range to bypass user authentication. To add an IP address, enter the single IP address in the first