Dell SonicWALL Directory Services Connector 3.7
Administration Guide
13
Both the NetBIOS name and the FQDN domain name can be found through an LDAP search. The SSO Agent
connects to the DC using these service credentials and completes the LDAP search.
The SSO Agent remembers these names and sends the correct domain name to the firewall according to the
administrator's configuration of the SSO Agent. By default, it sends the NetBIOS name.
You can enable or disable the NetBIOS feature from the DSC Configuration Tool. By default the NetBIOS feature
is disabled.
About using Samba on Linux/UNIX clients
Samba 3.0 or newer can be installed on Linux/UNIX clients for use with Dell SonicWALL SSO. Samba is a software
package used on Linux/UNIX machines to give them access to resources in a Windows domain (by way of Samba's
smb client utility). A user working on a Linux PC with Samba in a Windows domain can be identified through the
SSO, but it requires proper configuration of the Linux PC, and possibly some reconfiguration of the appliance, as
described in the Using Single Sign-On with Samba technote, available at:
https://support.software.dell.com
.
Without Samba, Linux PCs do not support the Windows networking requests that are used by the Dell SonicWALL
SSO Agent, and therefore, do not work with NetAPI or WMI client probing methods. Linux users can still get
access, but they need to log in to do so. They can be redirected to the login prompt if policy rules are set to
require authentication. Without Samba, the DC security log method works for using Single Sign-On with Linux
clients.
Platform compatibility
To use Dell SonicWALL Single Sign-On, it is required that the SSO Agent is installed on a server that can
communicate with the Active Directory or eDirectory server and with clients and the Dell SonicWALL security
appliance directly using the IP address or using a path, such as VPN.
The following requirements must be met in order to run the SSO Agent:
• Port 2258 must be open; the firewall uses UDP port 2258 by default to communicate with the SSO Agent;
if a custom port is configured instead of 2258, then this requirement applies to the custom port Windows
Server, with latest service pack.
• .NET Framework 2.0 or above
• NetAPI or WMI (unless using DC Windows security log as the Client Probing Method)
• The SSO Agent must run under Domain Admin privileges
Dell SonicWALL Directory Services Connector and the SSO Agent run as a 32-bit application. This improves the
performance of 64-bit agent machines, especially in cases where the agent is set to use NetAPI or WMI as the
Client Probing Method.
See the following sections:
•
SonicWALL appliance/firmware compatibility
on page
14
•
Virtual environment compatibility
on page
14
•
eDirectory server compatibility
on page
14
•
Domain controller server compatibility
on page
15
•
SSO Agent platform compatibility
on page
15
•
Client compatibility
on page
16
•
Citrix or terminal services compatibility
on page
16