<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
How to Configure Cisco SD-WAN VManage Portal
Single Sign-On
Okta Classic Engine
Okta Identity Engine
Overview

This article describes how to configure the Cisco SD-WAN VManage portal.

Applies To
  • Cisco SD-Wan VManage
  • Custom Security Assertion Markup Language (SAML)
Solution

For detailed instructions, please follow Configure OKTA Single Sign-On (SSO) on SD-WAN.

To configure SSO on the vManage UI:

  1. In vManage, click Administration > Settings > Identify Provider Settings > Edit.
  2. Click Enabled.
  3. Navigate to Click here to download the SAML metadata and save the content in a file. This data will be used for configuring Okta.
  4. In Metadata, follow the information to configure Okta with vManage:
    • Entity ID
    • Signing certificate
    • Encryption certificate
    • Logout URL
    • Login URL

To configure SSO on the Okta Admin Console:

  1. Log in to the  Okta console as an Okta Admin.
  2. Navigate to Add applications Add application.
  3. Select SAML 2.0 and click Create.
  4. Use a string for the Application name.
  5. (Optional) Upload a logo and then click Next.
  6. At SAML Settings, add the SSO URL using the samlLoginResponse URL from the downloaded metadata from the vManage UI.
  7. Copy the entityID string and paste it into the Service Provider ID field.
  8. For Name ID format, select EmailAddress and then click Enter.
  9. For the Application username, select Okta username.
  10. For Show Advanced Settings, enter the fields as indicated in Configure OKTA Single Sign-On (SSO) on SD-WAN.
  11. Click Next.
  12. For App type, check This is an internal app that we have created (optional).
  13. Click Finish.
  14. This prompts the Okta application page.
  15. Click on View Setup Instructions.
  16. Copy the IDP metadata.
  17. Navigate back to the vManage UI.
  18. Click on Identity Provider Settings.
  19. Paste the IDP metadata that was copied to Upload Identity Provider Metadata, and then click Save.


To assign users to the application in Okta:

  1. On the Okta application page, navigate to Assignments > People Assign.
  2. Select Assign to people from the drop-down menu.
  3. Click on Assign next to the user(s) that was selected and click Done.
  4. To add a user, click on Directory > Add Person > Save.

 

OKTA SAML Config Example

OKTA SAML Config Example

NOTE: Groups must match the Cisco vManage groups and be in lowercase.

Loading
How to Configure Cisco SD-WAN VManage Portal