cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
991
Views
0
Helpful
1
Replies

SAML asa and Keycloak

lopezportilla
Beginner
Beginner

HI,

We have been trying to make this work and so far not successful.

We can get the metadata from the SAML group , but when SAML idp authenticates, the vpn anyconnect client comes back to the login window with a login failed.

 

on the Debug we see no proper stabilshment

If I am correct on the Connection Profile (ASA 9.14.3) we select as AAA SAML and then AAA Server our LDAP or LOCAL and then use authorization for LDAP?

 

I guess SAML is not working properly since on the debug we dont get acknowledged .

 

Thanks

Carmelo

1 Reply 1

Mathias Peter IT
Beginner
Beginner

I've done the same, but with a newer ASA release. AAA is not involved. See configuration documentation.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: