Cisco Meraki Integration with SecureAuth Connect (SAML)

Follow
    Applies to:
  • Cloudentity
Deployment model:
  • Cloud
  • Prerequisites

    • SecureAuth Connect Workforce workspace with administrative privileges, configured with the same user store defined in your Meraki configuration.
    • User account with administrative privileges for Cisco Meraki.
    • SAML authentication requires Cisco Meraki with MX firmware version 16.13+ or 17.5+.
    • Users need AnyConnect VPN client version 4.8 or higher on either Windows, macOS, Linux, or mobile devices to terminate remote access connections successfully.

    SecureAuth Connect Configuration

    1. Log in to your SecureAuth Connect Workforce workspace with an admin account.
    2. In your workspace, select Applications > Clients > Create client.
    1. Enter a name, select SAML Service Provider, and click Create.
    1.  Download the SAML Metadata.

    1. Scroll down and enable Override SAML Attributes.
    1. Go to the Attributes tab, choose mail from the predefined attribute list, and click Save to apply the changes.
    1. On the SAML tab, select the Manual and set the following configurations:

    Entity ID : Enter your Cisco Meraki SAML entity URL.

    For example, https://merakivpn.example.com/saml/sp/metadata/SAML

    Assertion Consumer Service (ACS) URL : Enter your Cisco Meraki SAML consumer URL.

    For example, https://merakivpn.example.com/saml/sp/acs

    Enable Override Subject NameID, set Name ID Format to urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress and Name ID Value to mail. 

    1. Click Save.

    Cisco Meraki Configuration

    1. Log in to Cisco Meraki as an administrator.
    2. Navigate to Security & SD-WAN > CONFIGURE and click Client VPN.

      arculix_cisco_meraki_vpn_001.png
    3. On the AnyConnect Settings page, for AnyConnect Client VPN, select the Enabled option.

      arculix_cisco_meraki_vpn_002.png
    4. Scroll down and change the Authentication Type to SAML.

      arculix_cisco_meraki_vpn_003.png
    5. Enter the AnyConnect Server URL.

      For example: https://Merakivpn.example.com.

      Add :port to the end of the URL if using a port other than the default port 443.

      Make sure the AnyConnect URL starts with https://.

      arculix_cisco_meraki_vpn_004.png
    6. Click Choose File to upload the SecureAuth Connect metadata that was downloaded earlier.

      arculix_cisco_meraki_vpn_005.png
    7. Save your configuration.
    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.