Logging

The SonicWall SSO Agent sends log event messages to the Windows Event Log based on administrator-selected logging levels.

The SonicWall security appliance also logs SSO Agent-specific events in its event log. The following is a list of SSO Agent-specific log event messages from the SonicWall security appliance:

User login denied - not allowed by policy rule – The user has been identified and does not belong to any user groups allowed by the policy blocking the user’s traffic.
User login denied - not found locally – The user has not been found locally, and Allow only users listed locally is selected in the SonicWall security appliance.
User login denied - SSO Agent agent timeout – Attempts to contact the SonicWall SSO Agent have timed out.
User login denied - SSO Agent configuration error – The SSO Agent is not properly configured to allow access for this user.
User login denied - SSO Agent communication problem – There is a problem communicating with the workstation running the SonicWall SSO Agent.
User login denied - SSO Agent agent name resolution failed – The SonicWall SSO Agent is unable to resolve the user name.
SSO Agent returned user name too long – The user name is too long.
SSO Agent returned domain name too long – The domain name is too long.
NOTE: The notes field of log messages specific to the SSO Agent will contain the text
<domain/user-name>, authentication by SSO Agent.