SAML SSO authentication allows users to authenticate once with their identity provider and access the VPN without requiring separate credentials. This method improves user experience while maintaining security standards.
Procedure
Step 1 | Choose
|
Step 2 | To configure SAML SSO authentication for a new remote access VPN policy:
-
Click Add to create a remote access VPN policy.
-
Configure the protocols, devices, and connection profile for the policy.
-
From the Authentication Method drop-down list, choose SAML.
-
From the Authentication Server drop-down list, choose a SAML single sign-on server.
-
Configure the required settings for the remote access VPN policy.
-
Click Finish to save the remote access VPN policy.
|
Step 3 | To configure SAML SSO authentication for an existing remote access VPN policy:
-
Click the edit icon next to the remote access VPN policy.
-
Click the edit icon next to the connection profile that you want to modify.
-
Click the AAA tab.
-
From the Authentication Method drop-down list, choose SAML.
-
From the Authentication Server drop-down list, choose a SAML single sign-on server.
-
Check the Override Identity Provider Certificate check box to override the primary SAML IdP certificate with a profile-specific certificate to support multiple SAML applications for an IdP.
The primary identity certificate is configured in the single sign-on server object.
-
From the drop-down list, choose the IdP certificate.
-
In SAML Login Experience, configure a browser for SAML web authentication:
-
VPN client embedded browser—Select this option to use the embedded VPN client browser for VPN-only web authentication.
-
Default OS Browser—Select this option to use the system's default browser for web authentication. You can use SSO and methods like biometric authentication that are not supported in the embedded browser. This option requires an external browser package which is by default Default-External-Browser-Package. To change this browser package, edit the remote access VPN policy, click the Advanced tab and choose a browser package from the Package File drop-down list.
-
Click Save to save the remote access VPN policy.
|