Error Code: 0
Appreciate your help. Thank you.
06-29-2021 01:34 AM - edited 06-29-2021 01:44 AM
Hi,
Is anyone can help me regarding the error encountered when connecting to Anyconnect? I have an integrated AZURE SAML w/ Cisco ASA for authentication.
Here's my configuration
webvpn
saml idp https://sts.windows.net/x/ - [Azure AD Identifier]
url sign-in https://login.microsoftonline.com/x - [Login URL]
url sign-out https://login.microsoftonline.com/x – Logout URL
trustpoint idp AzureAD-AC-SAML
trustpoint sp ASDM-Trustpoint0
no force re-authentication
no signature
base-url https://0.0.0.0
I just want to confirm if the trustpoint sp ASDM-Trustpoint0 must be a public signed certificate? I'm getting error when redirecting to microsoft via Anyconnect.
Error Code: 0
Appreciate your help. Thank you.
10-10-2022 04:13 AM
Same error here. It seems that need a public certificate. If you install selfsigned certificate the connection is successfully
10-10-2022 05:29 AM
The certificate you download from Azure and you import into FMC will be used to establish a trust relationship between the FTD and Azure (IdP). On that certificate enrolment you would need to select "skip check for CA flag".
10-06-2023 04:50 AM
How did you resolve it. we use no ca-check but still geting same error.
12-21-2023 01:14 PM
Did anyone find a fix for this issue? I am experiencing same behavior.
webvpn
saml idp https://sts.windows.net/x/ - [Azure AD Identifier]
url sign-in https://login.microsoftonline.com/x - [Login URL]
url sign-out https://login.microsoftonline.com/x – [Logout URL ]
trustpoint idp AzureAD-AC-SAML
trustpoint sp External-CA-VPN-CERT
no force re-authentication
no signature
base-url https://0.0.0.0
12-22-2023 02:08 AM
Use your own cert as SP
Not sure if you came across this guide https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215935-configure-asa-anyconnect-vpn-with-micros.html
01-03-2024 10:28 AM
Hi Ruben,
Thankyou for your response. We are using public signed CA cert for SP at the moment. This cert is generated for our VPN.
When you say "use your own cert as SP" which own cert are you referring to? Are you suggesting for self-signed?
12-22-2023 02:27 AM
yes as Ruben answered you we generated a free certificate on web and everything is working...
02-05-2024 08:33 PM - edited 02-05-2024 08:33 PM
Mine is same behavior.Can advise how to generate free certificate on web
02-06-2024 04:08 AM
https://getacert.com/selfsignedcert.html. try with this one.
02-06-2024 11:43 PM
The getacert.com certificates will still be self-signed. You need a certificate that is issued by a CA trusted by the iDP (Azure / Entra ID in this case). Otherwise, when the iDP (Azure) attempts to connect securely to the SP (firewall) the lack of trust will cause the connection to fail.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide