Hi @sigveo ,
Duo SSO (a SAML IdP) is hosted in the cloud, so it must be able to communicate to your application’s (a SAML Service Provider) ACS URL. Additionally, your application must be able to communicate with Duo SSO’s /metadata and /sso URLs, which are publicly accessible upon creation of the application in the Duo Admin Panel (Single Sign-On for Generic SAML Service Providers | Duo Security).
If you are looking to protect an internal application, please see if it is compatible with RADIUS, LDAPS, WebSDK, or Auth API.
Hope this helps!