Join the Conversation

To sign in, use your existing MySonicWall account. To create a free MySonicWall account click "Register".

Is this a known bug? Gen 7, unable to add users to the Trusted Users group

I am unable to add users to the Trusted Users Group in 7.0.0-906

Making changes to the group appear to go through, but then if you view group membership, it remains empty.

Trusted Users is the default XAUTH Group for GVC, so it breaks GVC until you change that group.


Is this a known issue? Is this slated to be fixed in the next version of firmware?

Category: Entry Level Firewalls
Reply

Answers

  • @WNRG_NathanOrlina ,

    Any local user added is by default added to the user groups Everyone and Trusted Users. Could you please share the screenshots of the problem to understand this better?

    I tried this on a TZ 470W and that seems to look okay.

    Thanks!

    Shipra Sahu

    Technical Support Advisor, Premier Services

  • It's not local users, it's LDAP users that can't be added to Trusted Users.

  • MitatOngeMitatOnge Newbie ✭

    Hi @WNRG_NathanOrlina;


    I think If you have a LDAP integration on the sonicwall. Please dont use standart trusted user in the vpn profile.

    Below rules are mine and standart for me.

    1. Create an OU for Sonicwall.
    2. Create User Groups for eache sonicwall service. (For CFS, APP, IPS, ACCESS RULE service and others you should create sub groups.)
      1. CFS_Blocked
      2. CFS_Manager
      3. CFS_Personel
      4. CFS_Guest
      5. APP_IM_Allowed
      6. APP_IM_Blocked
      7. etc...
    3. Create VPN groups and add to GVC profile section.

    after that you won't need to login sonicwall GUI. only add to group and that's it...

    😉

  • TKWITSTKWITS Cybersecurity Overlord ✭✭✭

    Are you importing the users onto the firewall? Then adding them to the group?

  • I've already solved the problem, I don't need workarounds. I'm just here to report that All LDAP Users is not a member of Trusted Users by default and you can't add them to Trusted Users.

    This is different from the default behavior in Gen 6 and it doesn't throw an error, it just doesn't work, which is why I think it's a bug.

Sign In or Register to comment.