Dell SonicWALL Secure Mobile Access 8.5
Administration Guide
177
• External Administrator
– Users logging into this domain are treated as administrators, with local
Secure Mobile Access admin credentials. These users are presented with the admin login page.
This option allows the Secure Mobile Access administrator to configure a domain that allows
Secure Mobile Access admin privileges to all users logging into that domain.
Dell SonicWALL recommends adding filters that allow administrative access only to those users
who are in the correct group. You can do so by editing the domain on the
Users > Local Groups
page.
• Read-only Administrator
– Users logging into this domain are treated as read-only
administrators and can view all information and settings, but cannot apply any changes to the
configuration. These users are presented with the admin login page.
20 Click
Accept
to update the configuration. After the domain has been added, the domain is added to the
table on the
Portals > Domains
page.
Active Directory Troubleshooting
If your users are unable to connect using Active Directory, verify the following configurations:
•
The time settings on the Active Directory server and the SMA/SRA appliance must be synchronized.
Kerberos authentication, used by Active Directory to authenticate clients, permits a maximum 15-minute
time difference between the Windows server and the client (the SMA/SRA appliance). The easiest way to
solve this issue is to configure Network Time Protocol on the
System > Time
page of the Secure Mobile
Access web-based management interface and check that the Active Directory server has the correct time
settings.
•
Confirm that your Windows server is configured for Active Directory authentication.
Adding or Editing a Domain with LDAP
Authentication
To configure a domain with LDAP authentication:
1 Click
Add Domain
or the Configure icon for the domain to edit. The
Add Domain
or
Edit Domain
window is displayed.