cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
552
Views
0
Helpful
3
Replies

Anyconnect Azure SAML Configuration

Karol Kot
Level 1
Level 1

Hi,


I'm having problem with correct configuration of Remote Access VPN with Azure SAML on Firepower Appliance. How do I manage to create access control rule based on that specific user that I'm connecting through Microsoft?. I've tried to set up realms with AD but it doesn't work. When I reconfigure remote access to authenticate through AD, rules based on user works without problem. I've notice that, when I connect throught Microsoft portal, user that I'm connecting from isn't listed in "Active sessions" and in logs it shows that traffic is blocked and the "initiator user" is "not found" (without decryption) or "Pending user" (with decryption enabled).


My question is, is it even possible to create access control rules based on users that i'm connecting through Microsoft portal?

 

3 Replies 3

Karol Kot
Level 1
Level 1

No one?

Marvin Rhoads
Hall of Fame
Hall of Fame

Realm integration with on premises AD and an identity policy (whether the source is ISE or User Agent) won't help when you are using Azure AD for authentication.

You should be picking up the user identity though from the VPN authentication. Do the usernames show up in the cli show command "show vpn-sessiondb anyconnect"?

Yes, they do, but not in 'active sessions' in FMC.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: