Guidelines for SAML SSO authentication
Follow these guidelines for authenticating users using SAML SSO and Firewall Threat Defense devices.
General guidelines
-
A Firewall Threat Defense device can function only as a SAML SP. You cannot configure the device as an IdP in a gateway or peer mode.
-
Ensure that you do not use multiple SAML objects with the same IdP entity ID on a single device.
The device sets the IdP entity ID to the SAML object name from the SSO server object ().
-
Apply an access policy to a SAML-authenticated user by assigning an identity policy that uses an Active Directory (AD) realm matching the SAML domain. For Azure AD SAML, you must map the Azure AD tenant ID to a realm ID on the device.
-
Synchronize the Network Time Protocol (NTP) servers of the Firewall Threat Defense device and the SAML IdP.
-
Maintain valid signing certificates on the Firewall Threat Defense device and the IdP.
The device does not perform a revocation check on the IdP's signing certificate.
-
The
NameIDattribute of the SAML IdP determines the username for authorization, accounting, and VPN session database entries.
Secure Client guidelines
-
Secure Client performs SAML 2.0 authentication through its embedded browser, and the authentication context is not shared with external web browsers.
-
Secure Client can use various methods when connecting to a headend with the embedded browser.
The client might connect using IPv4 address while the embedded browser uses IPv6 address, or vice versa. If a proxy failure occurs, the client switches to no proxy, and the embedded browser stops navigation.
-
Ensure that you do not use untrusted server certificates in the embedded browser.
SAML assertion timing guidelines
The Firewall Threat
Defense device's SAML timeout interacts with NotBefore and NotOnOrAfter conditions in SAML assertions for login requests.
-
Timeout takes effect if the sum of
NotBeforeand timeout is less thanNotOnOrAfter, then. -
NotOnOrAftertakes effect if the sum ofNotBeforeand timeout is more thanNotOnOrAfter. -
The device denies the login request if
NotBeforeis not configured. -
The device denies the login request if
NotOnOrAfterand SAML timeout are not configured.