<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Based on the nature of SAML (Security Assertion Markup La... in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-we-do-saml-before-nat/m-p/4936486#M1104888</link>
    <description>Based on the nature of SAML (Security Assertion Markup Language) authentication process, it might not be feasible to perform SAML authentication on the Cisco Firepower Threat Defense (FTD) firewall. The SAML authentication process requires an exchange of XML-based messages between the Service Provider (SP - your internal application in this case) and the Identity Provider (IdP). Cisco FTD firewalls are principally designed to handle traffic control and network security, but not advanced application-level protocols such as SAML.&lt;BR /&gt;&lt;BR /&gt;However, an alternative approach can be considered. You might want to set up a reverse proxy server (like Nginx or Apache) in front of your application. This reverse proxy can handle the SAML authentication before forwarding the traffic to your internal application. The flow would then look like this:&lt;BR /&gt;&lt;BR /&gt;Flow ---) .com URL---)1.1.1.1--) Hits Reverse Proxy --) SAML(OK) --) Forward to Firewall --) Destination NAT happens to APPLICATION&lt;BR /&gt;&lt;BR /&gt;Please note, this is a broad solution and actual implementation might vary depending on your specific network layout and requirements. Always consider engaging with a network security professional for detailed advice and implementation.</description>
    <pubDate>Mon, 09 Oct 2023 09:50:39 GMT</pubDate>
    <dc:creator>Cisco_Virtual_Engineer</dc:creator>
    <dc:date>2023-10-09T09:50:39Z</dc:date>
    <item>
      <title>Can we do SAML before NAT</title>
      <link>https://community.cisco.com/t5/network-security/can-we-do-saml-before-nat/m-p/4935628#M1104860</link>
      <description>&lt;DIV class="lia-message-template-question-zone"&gt;&lt;P&gt;We have an internal application which is accessible on VPN,&amp;nbsp;Currently SAML authentication is configured at application level.&lt;/P&gt;&lt;P&gt;I'm planning to move it off VPN and have it accessible internally as well.&lt;/P&gt;&lt;P&gt;What i have proposed is create an external DNS record have it hit an ip on FTD and then it does destination NAT to FQDN and hits the application where SAML authentication happens&lt;/P&gt;&lt;P&gt;Is it possible to have SAML authenticaton on external IP configured on FTD ? before it enters our network&amp;nbsp;&lt;/P&gt;&lt;P&gt;Flow ---&amp;gt; .com URL---&amp;gt;1.1.1.1--&amp;gt; Hits FW--&amp;gt; Destination NAT happens to APPLICATION -- SAML--&amp;gt; OK&lt;/P&gt;&lt;P&gt;Possible Solution ?&lt;/P&gt;&lt;P&gt;Flow ---&amp;gt; .com URL---&amp;gt;1.1.1.1--&amp;gt; Hits FW--&amp;gt;SAML(OK)--&amp;gt; Destination NAT happens to APPLICATION&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-template-answer-zone"&gt;&lt;H2&gt;&amp;nbsp;&lt;/H2&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 06 Oct 2023 17:39:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-we-do-saml-before-nat/m-p/4935628#M1104860</guid>
      <dc:creator>amitpalsingh</dc:creator>
      <dc:date>2023-10-06T17:39:45Z</dc:date>
    </item>
    <item>
      <title>Based on the nature of SAML (Security Assertion Markup La...</title>
      <link>https://community.cisco.com/t5/network-security/can-we-do-saml-before-nat/m-p/4936486#M1104888</link>
      <description>Based on the nature of SAML (Security Assertion Markup Language) authentication process, it might not be feasible to perform SAML authentication on the Cisco Firepower Threat Defense (FTD) firewall. The SAML authentication process requires an exchange of XML-based messages between the Service Provider (SP - your internal application in this case) and the Identity Provider (IdP). Cisco FTD firewalls are principally designed to handle traffic control and network security, but not advanced application-level protocols such as SAML.&lt;BR /&gt;&lt;BR /&gt;However, an alternative approach can be considered. You might want to set up a reverse proxy server (like Nginx or Apache) in front of your application. This reverse proxy can handle the SAML authentication before forwarding the traffic to your internal application. The flow would then look like this:&lt;BR /&gt;&lt;BR /&gt;Flow ---) .com URL---)1.1.1.1--) Hits Reverse Proxy --) SAML(OK) --) Forward to Firewall --) Destination NAT happens to APPLICATION&lt;BR /&gt;&lt;BR /&gt;Please note, this is a broad solution and actual implementation might vary depending on your specific network layout and requirements. Always consider engaging with a network security professional for detailed advice and implementation.</description>
      <pubDate>Mon, 09 Oct 2023 09:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-we-do-saml-before-nat/m-p/4936486#M1104888</guid>
      <dc:creator>Cisco_Virtual_Engineer</dc:creator>
      <dc:date>2023-10-09T09:50:39Z</dc:date>
    </item>
  </channel>
</rss>

