<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAML configuration for ISE,  can SSO Binding URL/Port be changed? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/saml-configuration-for-ise-can-sso-binding-url-port-be-changed/m-p/5220703#M593024</link>
    <description>&lt;P&gt;The Assertion is bound to the portal and the respective interface. The only way I can think of that&amp;nbsp;&lt;STRONG&gt;might&amp;nbsp;&lt;/STRONG&gt;work would be to enable a second interface on ISE, create a static host entry for that interface, and move the Portal to use that interface.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Nov 2024 03:50:45 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2024-11-06T03:50:45Z</dc:date>
    <item>
      <title>SAML configuration for ISE,  can SSO Binding URL/Port be changed?</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-configuration-for-ise-can-sso-binding-url-port-be-changed/m-p/5220581#M593021</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have and an environment with Microsoft Entra ID, providing SAML/SSO for administration access to ISE.&amp;nbsp; &amp;nbsp; &amp;nbsp;Internally this works, and administrators are able to login using their Entra Creds.&lt;BR /&gt;&lt;BR /&gt;I also have Zscaler, and use the Client Portal to provide web based access to a variety of things for 3rd partys/contractors.&amp;nbsp; The Zscaler Client portal, only listens on port 443, and 80.&amp;nbsp; &amp;nbsp; &amp;nbsp;It can redirect traffic to to other ports internally.&amp;nbsp; &amp;nbsp;However to do so, i'd need to be able to change the URL of the SSO binding.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;my ise server's host name is akl-01.radius.XXX.cloud and it reponds on 443 as expected.&amp;nbsp; The configuration provides this location for the SAML assertion.&amp;nbsp; &amp;nbsp; You can see the base URL is the same.&amp;nbsp; and that is where i get unstuck.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;md:AssertionConsumerService&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Binding&lt;/SPAN&gt;="&lt;SPAN class=""&gt;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Location&lt;/SPAN&gt;="&lt;SPAN class=""&gt;&lt;A href="https://akl-01.radius.XXXXX.cloud:8443/portal/SSOLoginResponse.action" target="_blank" rel="noopener"&gt;https://akl-01.radius.XXXXX.cloud:8443/portal/SSOLoginResponse.action&lt;/A&gt;&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;index&lt;/SPAN&gt;="&lt;SPAN class=""&gt;0&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;/&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Is it possible for me to set up a different Host name for the assertion?&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;something like&amp;nbsp; &amp;nbsp;akl-01.saml4radius.XXXX.cloud ?&lt;BR /&gt;If i coudl do this, it would allow me to do some redirections..&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 18:50:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-configuration-for-ise-can-sso-binding-url-port-be-changed/m-p/5220581#M593021</guid>
      <dc:creator>afrazer</dc:creator>
      <dc:date>2024-11-05T18:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: SAML configuration for ISE,  can SSO Binding URL/Port be changed?</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-configuration-for-ise-can-sso-binding-url-port-be-changed/m-p/5220703#M593024</link>
      <description>&lt;P&gt;The Assertion is bound to the portal and the respective interface. The only way I can think of that&amp;nbsp;&lt;STRONG&gt;might&amp;nbsp;&lt;/STRONG&gt;work would be to enable a second interface on ISE, create a static host entry for that interface, and move the Portal to use that interface.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 03:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-configuration-for-ise-can-sso-binding-url-port-be-changed/m-p/5220703#M593024</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-11-06T03:50:45Z</dc:date>
    </item>
  </channel>
</rss>

