11-01-2021 02:16 PM
Hi fellow users,
I'm running into an issue and I hope someone can help me in right direction.
I have configured Azure AD SSO and MFA together with Cisco AnyConnect VPN on FTD and it's working fine. I got two different internet connections for fallback if the primary line is down. How do I configure this kind of redundancy while integrating Cisco AnyConnect VPN with Azure AD SSO?
In Azure AD portal you add an enterprise application (Cisco AnyConnect in this case) and the an Azure AD Identifier is created and then we should enter base vpn url.
I have created two enterprise applications for Cisco AnyConnect with two different vpn base urls (one each for two different internet connections).
On Cisco FMC I created two SAML SSO servers and want to create two VPN profiles one each for two different internet connections. When I try to deploy I'm getting an error that Azure AD Identifiers are identical!
Can anyone help me how to solve this issue and maybe there is a better way to solve this issue.
Sincerely,
Sal
11-01-2021 07:29 PM
11-02-2021 01:23 AM
Hi Mohammad,
Thanks for your reply. I have tried to leave the base url blank but when I try to connect to one of the two Cisco Anyconnect VPN URLs (https://ftd.lab.local and https://fallbackvpn.lab.local), it's giving a certificate error and it's stops working. The screenshot is just an example. I'm using a wildcard certificate signed by 3rd Party CA.
Regards,
Sal
11-02-2021 03:25 AM
02-28-2023 09:25 PM - edited 02-28-2023 09:48 PM
Hi Sal,
I'm trying to do the same thing at the moment, how'd you end up getting around this?
I'm still in the planning stage for haven't tried any config just yet, but can you have multiple Entity ID and Reply URL's in one AAD Enterprise App?
eg.
https://FTD1.test.com/saml/sp/metadata/<TUNNEL-GROUP>
and
https://FTD2.test.com/saml/sp/metadata/<TUNNEL-GROUP>
Alternatively, I assume using the override feature when you define the Single Sign-on Server on the FMC might also be an option?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide