Configure SAML authorization

SAML authorization allows you to integrate your VPN solution with existing identity providers for centralized authentication and access control. This configuration involves setting up SAML authentication in connection profiles and creating DAP policies that match SAML criteria.

Before you begin

Ensure that you review Prerequisites for SAML SSO, Guidelines for SAML SSO authentication, and Limitations for SAML SSO.

Follow these steps to configure SAML authorization:

Procedure


Step 1

Configure SAML authentication in the remote access VPN connection profile.

For more information, see Configure SAML SSO authentication.

Step 2

Match a SAML criteria in a DAP policy.

  1. Choose Secure Connections > Dynamic Access Policy.

  2. Create a new DAP policy or edit an existing policy.

  3. Create a DAP record or edit an existing record.

  4. Click the AAA Criteria tab.

  5. In SAML Criteria, click + to create SAML criteria based on the SAML assertions returned by the SSO server.

Step 3

Deploy the remote access VPN configuration.