To configure login constraints
In the LOGIN SECURITY section, configure the following:
If the Administrator Inactivity Timeout is extended beyond five minutes, you should end every management session by clicking Logout in the upper right corner of the view to prevent unauthorized access to the firewall’s Management Interface.
To configure the SonicWall Security Appliance to lockout an administrator or a user if the login credentials are incorrect, enable Admin/user lockout. This option locks out the source IP address accessing the firewall after the specified number of incorrect login attempts. This option is enabled by default. When this option is enabled, the following fields become active.
If the administrator and a user are logging into the firewall using the same source IP address, the administrator is also locked out of the firewall. The lockout is based on the source IP address of the user or administrator.
Select Log event only without lockout for SonicOS to log failed user login attempts that have reached the established threshold, but does not lock out the user or IP address. This option is only available when Admin/user lockout is enabled.
After a user or IP address is locked out, a “User login denied - User is locked out” message displays on the login screen and the login is rejected.
You can review and edit all locked out user accounts on the Active Users page when local admin/user account lockout is enabled.
If the Lockout Period (mins) is set to zero it will lock out IP address or user account permanently based on lock out settings.
To configure the SonicWall Security Appliance to lockout an administrator or a user if the login credentials are incorrect, enable Admin/user lockout. This option locks out the source IP address accessing the firewall after the specified number of incorrect login attempts. This option is disabled by default. When this option is enabled, the following fields become active.
User lockout is applicable only to local users; it doesn't apply to external authentication users like AD/LDAP/RADIUS/TACACs unless they are imported locally on firewall .
If the administrator and a user are logging into the firewall using the same source IP address, the administrator is also locked out of the firewall. The lockout is based on the source IP address of the user or administrator.
Select Log event only without lockout for SonicOS to log failed user login attempts that have reached the established threshold, but does not lock out the user or IP address. This option is only available when Admin/user lockout is enabled.
After a user or IP address is locked out, a “User login denied - User is locked out” message displays on the login screen and the login is rejected.
You can review and edit all locked out user accounts on the Active Users page when local admin/user account lockout is enabled.
If the Lockout Period (mins) is set to zero it will lock out IP address or user account permanently based on lock out settings.