SSLVPN authentication with SAML and Google Workspace

Description

This article explains how to configure SSLVPN authentication using SAML and Google Workspace. When a user tries to connect to the SSLVPN, the firewall generates a SAML request, which redirects the user to Google Workspace (acting as the Identity Provider). The Identity Provider authenticates the user and generates a SAML response. The firewall then verifies the SAML response and logs the user in.

Resolution

Resolution for SonicOS 7.X

This release includes SLVPN authentication using SAML and Google Workspace. The below resolution is for customers using SonicOS 7.X firmware.

Step 1:

To configure SAML service provider, navigate to device > user> settings> SAML Service Provider> Configure.
Add SAML service Provider, select type as domain and service and SSLVPN then save

Image

Image

Image


Export Service Provider Metadata 

Image


Save the exported metadata in PC downloads.


Step 2 : 


Open your Google Workspace, navigate to Directory > Groups, and then click on Create Group.



Image

 

 

Image

 

To configure Access type please select the options as below,

Image


Image


Image


After creating group, add memen=bers as below :

Image

Image


After adding the member to the group, navigate to APPS>  Web and Mobile apps> Add App> Add custom SAML App.

Image

Image

Image

Save the Metadata and click continue.

Image

Image

Image


Image

Image

Image



Step 3 : 

After configuring the groups and adding users in Google Workspace, log in to the SonicWall UI and navigate to:
Device > User Settings > SAML Configuration > SAML Identity Provider, then click Configure.

Image

Image


Image

Add the Metadata which is downloaded from google workspace,

Image


Image

Configure SAML Profile :

Image

Image


Image

Navigate to Network> SSLVPN > Server settings, select the autehntication type as SAML

Image

After adding Autheication type, Configure SAML profile as below :

Image
Image



Related Articles

  • How to use www.pkitools.net for Resigning the DPI SSL Client Certificate.
    Read More
  • Certificate error when accessing certain websites when Client DPI-SSL is Enabled
    Read More
  • Custom DPI-SSL certificate generation and re-signing for expired DPI-SSL certificates on SonicOS 7.0.1
    Read More
not finding your answers?