04-07-2020 10:19 AM
Hi,
Does someone know if ASA supports client certificate authentication + SAML with anyconnect ?
As I understand the certificate is verified on the ASA, then I need a second factor auth with a SAML connection to a 2FA provider.
note : I also have ISE for authorization only and posture (I use authorize-only mode). But maybe the SAML can be integrated here ? But not sure, because ASA talks with ISE in radius and not https.
Best regards
Solved! Go to Solution.
04-07-2020 09:10 PM - edited 04-07-2020 09:15 PM
Hi xbill42,
That is correct.
While using SAML for the authentication, there is no other method like Certificarte authentication or AAA(Radius,LDAP) that can be used in conjunction with it.
There is one Certificate authentication that can take place but it will be between the SAML IdP and the Client PC, the ASA will not be part of this.
AnyConnect 4.7.04056 New Features
This is a maintenance release that includes the following features and enhancements, and that resolves the defects described in AnyConnect 4.7.04056:
Rate if it helps.
Regards,
Josue Brenes
TAC - VPN Engineer.
04-07-2020 11:19 AM
Hi,
regarding the ASA I think I have the response in the docs :
This SAML SSO SP feature is a mutual exclusion authentication method. It cannot be used with AAA and certificate together
Best regards
04-07-2020 09:10 PM - edited 04-07-2020 09:15 PM
Hi xbill42,
That is correct.
While using SAML for the authentication, there is no other method like Certificarte authentication or AAA(Radius,LDAP) that can be used in conjunction with it.
There is one Certificate authentication that can take place but it will be between the SAML IdP and the Client PC, the ASA will not be part of this.
AnyConnect 4.7.04056 New Features
This is a maintenance release that includes the following features and enhancements, and that resolves the defects described in AnyConnect 4.7.04056:
Rate if it helps.
Regards,
Josue Brenes
TAC - VPN Engineer.
09-16-2022 04:47 AM
So to set up SAML + Client Certificate authentication you need to set authentication method to SAML on the ASA/Firepower? I guess you can use Azure to validate the Client Certificate? Is there any guide available for this?
02-01-2023 04:47 PM
Starting with ASA 9.18 and Firepower 7.2, SAML + certificate authentication is supported.
11-15-2024 12:59 PM
Are there any guides to configure the ASA for this type of authentication without FMC
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide