cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1117
Views
0
Helpful
4
Replies

Cisco ASA/Azure Active Directory/SAML - Limitations/Issues

Working with our VPN team to integrate Cisco ASA with Azure Active Directory/MFA.  There is a Azure AD gallery app.  That has been installed and enabled for SSO.  However, we are experiencing SAML Authentication Request failures.  Our VPN team believes this is because we are utilizing VPN/DNS load balancing and SAML authentication is unsupported.
Is this a true limitation? 

 

Thanks

 

4 Replies 4

Milos_Jovanovic
VIP Alumni
VIP Alumni

Hi @stevensharamatew,

It really depends on how you implemented this setup, so please share more details.

If it is plain round-robin DNS, then most likely it is - you could be sending queries from one device, while AAD could resolve it to another one. If you created it via VPN load-balancing, then it will not cause issues, as I already implemented this solution and it works great. You will have to create multiple applications on AAD side, as each VPN GW will have its on FQDN.

BR,

Milos

Marvin Rhoads
Hall of Fame
Hall of Fame

With VPN load balancing, the members share a common FQDN. I am pretty sure that's not currently supported when using SAML authentication.

@Marvin Rhoads 

Members are sharing common FQDN, but at the same time they must have their own unique FQDNs (which are then used for SAML). I never check if it is officially supported, but I can tell you that it works. I implemented it and we are using it heavilly with one of my customers.

BR,

Milos

Thank you for the responses.  Will dig deeper and work with our VPN team.  Will provide update.

 

Review Cisco Networking for a $25 gift card