288 | SRA 6.0 Administrator’s Guideuser logged in, the duration of the session, and the cumulative idle time during the session. Anadministrator may terminate a user session and log the user out by clicking the Logout icon atthe right of the user row. The Active User Session table includes the following information:Table 20 Active User InformationAccess Policies ConceptsThe Dell SonicWALL SRA Web-based management interface provides granular control ofaccess to the SRA appliance. Access policies provide different levels of access to the variousnetwork resources that are accessible using the SRA appliance. There are three levels ofaccess policies: global, groups, and users. You can block and permit access by creating accesspolicies for an IP address, an IP address range, all addresses, or a network object.Access Policy HierarchyAn administrator can define user, group and global policies to predefined network objects, IPaddresses, address ranges, or all IP addresses and to different SRA services. Certain policiestake precedence.The Dell SonicWALL SRA policy hierarchy is:• User policies take precedence over group policies• Group policies take precedence over global policies• If two or more user, group or global policies are configured, the most specific policy takesprecedenceFor example, a policy configured for a single IP address takes precedence over a policyconfigured for a range of addresses. A policy that applies to a range of IP addresses takesprecedence over a policy applied to all IP addresses. If two or more IP address ranges areconfigured, then the smallest address range takes precedence. Host names are treated thesame as individual IP addresses.Network objects are prioritized just like other address ranges. However, the prioritization isbased on the individual address or address range, not the entire network object.For example:• Policy 1: A Deny rule has been configured to block all services to the IP address range10.0.0.0 - 10.0.0.255• Policy 2: A Deny rule has been configured to block FTP access to 10.0.1.2 - 10.0.1.10Column DescriptionName A text string that indicates the ID of the user.Group The group to which the user belongs.Portal The name of the portal that the user is logged into.IP Address The IP address of the workstation which the user is logged into.Login Time The time when the user first established connection with the SRA applianceexpressed as day, date, and time (HH:MM:SS).Logged In The amount of time since the user first established a connection with the SRA appli-ance expressed as number of days and time (HH:MM:SS).Idle Time The amount of time the user has been in an inactive or idle state with the SRA appli-ance.Logout Displays an icon that enables the administrator to log the user out of the appliance.