SonicOS 8 Device Settings

Table of Contents

Configuring Login Constraints

To configure login constraints

  1. Navigate to Device | Settings > Administration.
  2. Click Login/Multiple Administrators.

In the LOGIN SECURITY section, configure the following:

  1. To specify the length of inactivity time that elapses before you are automatically logged out of the Management Interface, enter the time, in minutes, in the Log out the Admin after inactivity of (mins) field. By default, the SonicWall Security Appliance logs out the administrator after 5 minutes of inactivity. The inactivity timeout can range from 1 to 9999 minutes.
  2. If the Administrator Inactivity Timeout is extended beyond five minutes, you should end every management session by clicking Logout in the upper right corner of the view to prevent unauthorized access to the firewall’s Management Interface.

  3. To configure the SonicWall Security Appliance to lockout an administrator or a user if the login credentials are incorrect, enable Admin/user lockout. This option locks out the source IP address accessing the firewall after the specified number of incorrect login attempts. This option is enabled by default. When this option is enabled, the following fields become active.

    If the administrator and a user are logging into the firewall using the same source IP address, the administrator is also locked out of the firewall. The lockout is based on the source IP address of the user or administrator.

    1. Select Enable local admin/user account lockout. This option will only lock out the user account when they have surpassed a specified number of incorrect login attempts and other users will still be able to login from the same source IP address. This option is only available when admin/user lockout is enabled.
    2. Select Log event only without lockout for SonicOS to log failed user login attempts that have reached the established threshold, but does not lock out the user or IP address. This option is only available when Admin/user lockout is enabled.

      After a user or IP address is locked out, a “User login denied - User is locked out” message displays on the login screen and the login is rejected.

      You can review and edit all locked out user accounts on the Active Users page when local admin/user account lockout is enabled.

    3. Enter the number of failed attempts within a specified time frame before the user is locked out in the Failed login attempts per minute before lockout field. The default number is 3, the minimum is 1, and the maximum is 99. Enter the maximum time in which failed attempts can be made. The default is 1 minute, the minimum is 1 minute, and the maximum is 240 minutes (4 hours).
    4. Enter the length of time that must elapse before the user is allowed to attempt to log into the firewall again in the Lockout Period (mins) field. The default is 5 minutes, the minimum is 0 (permanent lockout), and the maximum is 60 minutes.

    If the Lockout Period (mins) is set to zero it will lock out IP address or user account permanently based on lock out settings.

  4. To configure the SonicWall Security Appliance to lockout an administrator or a user if the login credentials are incorrect, enable Admin/user lockout. This option locks out the source IP address accessing the firewall after the specified number of incorrect login attempts. This option is disabled by default. When this option is enabled, the following fields become active.

    User lockout is applicable only to local users; it doesn't apply to external authentication users like AD/LDAP/RADIUS/TACACs unless they are imported locally on firewall .

    If the administrator and a user are logging into the firewall using the same source IP address, the administrator is also locked out of the firewall. The lockout is based on the source IP address of the user or administrator.

    1. Select Enable local admin/user account lockout. This option will only lock out the user account when they have surpassed a specified number of incorrect login attempts and other users will still be able to login from the same source IP address. This option is only available when admin/user lockout is enabled.
    2. Select Log event only without lockout for SonicOS to log failed user login attempts that have reached the established threshold, but does not lock out the user or IP address. This option is only available when Admin/user lockout is enabled.

      After a user or IP address is locked out, a “User login denied - User is locked out” message displays on the login screen and the login is rejected.

      You can review and edit all locked out user accounts on the Active Users page when local admin/user account lockout is enabled.

    3. Enter the number of failed attempts within a specified time frame before the user is locked out in the Failed login attempts per minute before lockout field. The default number is 5, the minimum is 1, and the maximum is 99. Enter the maximum time in which failed attempts can be made. The default is 5 minutes, the minimum is 1 minute, and the maximum is 240 minutes (4 hours).
    4. Enter the length of time that must elapse before the user is allowed to attempt to log into the firewall again in the Lockout Period (mins) field. The default is 5 minutes, the minimum is 0 (permanent lockout), and the maximum is 60 minutes.

    If the Lockout Period (mins) is set to zero it will lock out IP address or user account permanently based on lock out settings.

  5. Click Accept.