<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00009hMUKDSA4Okta Classic EngineSingle Sign-OnAnswered2024-03-25T17:14:07.000Z2020-10-16T04:00:02.000Z2020-10-29T19:31:41.000Z

znjnq (znjnq) asked a question.

ASA Anyconnect Integration with Okta

Image is not available
Hello, I configured my ASA for SAML authentication. I followed the instruction exactly and copied the URLs as is. When I go to connect through the VPN client I get a popup window and it says wrong URL! Can you help me find out what I did wrong in my config?


  • sandeepk.84743 (Wipro Technologies)

    Hello Sleiman,

     

    Have you defined the Assertion Consumer Service (ACS) URL & SP Entity ID correctly? Please install the SAML tracer plugIn & see the SAML request flow. It shouldn't be difficult to trace the errors.

  • znjnq (znjnq)

    The problem was with the tunnel-group URL. Okta didn't like using a / after the domain. We currently use ACS for authorization based on AD groups. Can OKTA do authorization or can it send the request back to the ASA for authorization?

  • Hi Sleiman,

     

    If I understood your question correctly. Okta does not send authorization request after authentication for ASA. Okta can reply back with groups via SAML or RADIUS and then ASA can handle authorization. Please let me know if you have any follow-up questions or concerns. Also please feel free to open support case if you would like to discuss your use-case in detail.

     

    Regards,

     

    Jonil Soni

    Tier 2 Technical Support Engineer

    Okta Global Customer Care

    Expand Post
This question is closed.
Loading
ASA Anyconnect Integration with Okta