Active Users refreshed every few seconds, incorrect policies applied

Description

This article shows the SSO Agent configuration to apply when your Active Users monitor shows a Session Time for all users of 0 or 1 minutes. This may happen when SSO is incorrectly configured and it will poll/refresh all users every few seconds causing a very high CPU usage as well as incorrect policies applied.

Cause

It looks like these users are just being replaced by the same user and this is caused by incorrectly configured Polling and/or Scanning options.

  1. The Agent seems to be scanning and notifying the firewall of a change.
  2. The firewall logs messages are relating to polling and detected logouts.
  3. The user is being logged back in by generating traffic and causing SonicOS to request identification.
  4. Polling successfully finds user and the Agent reports logoff/new login despite user being the same
  5. Old user is being logged out while the same user is being logged in via NetAPI
  6. Polling starts again and the cycle goes on.

Resolution

Applying the following changes, you should mitigate or solve the issue:

  • SSO Agent (Directory Services Connector) changes:
    Go to the SSO Agent (SonicWall Directory Connector Configuration Tool), right-click on SonicWall SSO Agent and then Properties:
  1. Disable SCAN Users from the SSO Agent configuration

  2. Enable Preserve Users option to keep the user cache when the SSO Agent service restarts from the SSO Agent config

  3. Disable the authentication methods not used by the SSO Agent --> I.E. If all the users are getting recognized using NetAPI but on the SSO Agent it's enabled NetAPI+WMI, disable WMI.

NOTE: Make sure the SSO Agent is updated to the latest version

  • On the Firewall:
  1. Go to Users | Settings and click on Configure SSO
  2. Go to the Users tab and enable the option "Poll using the same Agent that identified the user"

If the issue persists, please collect all the data to troubleshoot the issue:

Related Articles

  • How to block ICMP (Ping ) using Application control
    Read More
  • SonicWall GEN8 TZ and NSa Firewalls FAQ
    Read More
  • How to configure Link Aggregation
    Read More
not finding your answers?