How To: Integrate Cisco Meraki Client VPN with SecureAuth Connect (SAML)

Follow
    Applies to:
  • Connect
Deployment model:
  • Cloud
  • Version Affected: All Versions

     

    Overview

    This article explains how to integrate Cisco Meraki Client VPN with SecureAuth Connect using SAML.

     

    Prerequisites

    • A SecureAuth Connect Workforce workspace with administrative privileges, configured with the same user store defined in your Meraki configuration.
    • A user account with administrative privileges for Cisco Meraki.
    • SAML authentication requires Cisco Meraki with MX firmware version 16.13+ or 17.5+.
    • Users need AnyConnect VPN client version 4.8 or higher on Windows, macOS, Linux, or a mobile device to terminate remote access connections successfully.

     

    SecureAuth Connect Configuration

    1. Log in to your SecureAuth Connect Workforce workspace with an admin account.
    2. In your workspace, select Applications > Clients > Create client.

      The Client Applications page in SecureAuth Connect with the Create Client button highlighted.

    3. Enter a name, select SAML Service Provider, and click Create.

      The Create Client form with a name entered and SAML Service Provider selected as the application type.

    4. Download the SAML Metadata.

      The newly created SAML client application page with the option to download SAML Metadata.

    5. Scroll down and enable Override SAML Attributes.

      The Override SAML Attributes toggle enabled on the client application.

    6. Go to the Attributes tab, choose mail from the predefined attribute list, and click Save to apply the changes.

      The Attributes tab with mail selected from the predefined attribute list.

    7. On the SAML tab, select Manual and set the following configuration:
      • Entity ID: enter your Cisco Meraki SAML entity URL -- for example, https://merakivpn.example.com/saml/sp/metadata/SAML.
      • Assertion Consumer Service (ACS) URL: enter your Cisco Meraki SAML consumer URL -- for example, https://merakivpn.example.com/saml/sp/acs.
      • Enable Override Subject NameID, set Name ID Format to urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress, and set Name ID Value to mail.

        The SAML tab Subject NameID section with Override Subject NameID enabled, Name ID Format set to the emailAddress URN, and Name ID Value set to mail.

    8. Click Save.

     

    Cisco Meraki Configuration

    1. Log in to Cisco Meraki as an administrator.
    2. Navigate to Security & SD-WAN > Configure > Client VPN.

      The Cisco Meraki dashboard navigation menu with Security and SD-WAN expanded and Client VPN highlighted.

    3. On the AnyConnect Settings page, for AnyConnect Client VPN, select Enabled.

      The AnyConnect Client VPN setting switched to Enabled.

    4. Scroll down and change the Authentication Type to SAML.

      The Authentication Type setting changed to SAML.

    5. Enter the AnyConnect Server URL -- for example, https://merakivpn.example.com. Add :port to the end of the URL if using a port other than the default port 443, and make sure the URL starts with https://.

      The AnyConnect Server URL field with an example HTTPS URL entered.

    6. Click Choose File to upload the SecureAuth Connect metadata that was downloaded earlier.

      The Choose File control for uploading the SAML metadata file.

    7. Click Save to save your configuration.




     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.