cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6500
Views
0
Helpful
3
Replies

Clarification on SAML authentication support for VPN in ISE

Chris Evans
Level 1
Level 1

I have a customer currently using ASA VPN authentication -> ISE -> Microsoft AD.

 

They have SAML on OpenAM and are requesting assistance from me in integrating ISE into the authentication with the end goal of SAML authentication of VPN users.  Links and documentation I see for this imply that the tested use cases on ISE are for guest and sponsor portals, not for VPN authentication (although one of the links implies that if the end user first authenticates their SSL VPN to SAML, they can leverage that authentication for subsequent access to these web pages, such as my device).  One such link is:

 

https://community.cisco.com/t5/identity-services-engine-ise/sso-authentication-for-ssl-vpn-using-ise/td-p/3583755


My customer has had some success integrating the ASA directly with the OpenAM (user is parsed for username and authentication which appears to be sent to OpenAM but the ASA is not receiving a reply).  They'd like to have ISE record the accounting information for the users, however - and the username and IP mapping would be useful for their SIEM.

Reading through documentation on SAML I assume we can either:
- Have the ASA authenticate directly to their server but send accounting information to ISE (likely our best option) or
- Have a username/password authentication via Anyconnect at ISE via standard Radius but redirect to a webportal to get the SAML authentication.  This requires double-authentication though and defeats the point of using SAML.

Am I correct on these and/or is there a different, better option?

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

See my response at Solved: Re: SSO auth for Anyconnect using ISE S... - Cisco Community

The screenshot below shows a sample AnyConnect Connection Profile.

Screen Shot 2019-05-02 at 5.59.58 PM.png

View solution in original post

3 Replies 3

Chris Evans
Level 1
Level 1

A further point that I should iterate - I had originally thought that the intention of SAML within this environment was for SSO for end users using SAML for authentication to other assets.  That may still be the case, but they are indeed using the backend for MFA for users.  I have a meeting with the customer today and will get further clarification on the factors to be used for authentication and the drivers for SAML rather than Radius authentication, but initial feedback was that it was for improved end-user experience.

hslai
Cisco Employee
Cisco Employee

See my response at Solved: Re: SSO auth for Anyconnect using ISE S... - Cisco Community

The screenshot below shows a sample AnyConnect Connection Profile.

Screen Shot 2019-05-02 at 5.59.58 PM.png