Secure Mobile Access 12.5 Administration Guide

Table of Contents

Configuring SMA1000 Appliance

Create a SAML Authentication Server to authenticate users using OneLogin.

  1. In the AMC, navigate to System Configuration > Authentication Servers.

  2. Under Authentication servers, click the + (New) icon. The Add Authentication Server page displays.

  3. Select SAML 2.0 Identity Provider.

  4. Click Continue The Edit Authentication Server page displays.

    The steps that follow explain how to configure the fields in the Configure Authentication Server .

  5. In the Name field, enter OneLogin.

  6. In the Appliance ID field, enter the Audience/SPIdentity from the Configuration tab of the SonicWall VPN page. For example,https://workplace.company.com.
  7. (Optional) Select the Sign AuthnRequest message using this certificate if you want it, then select the appropriate certificate.
  8. Select the Endpoint FQDN value. For example, workplace.company.com.

  9. Under the Identity Enter Configuration section, click the Choose file or Browse button to upload the OneLogin SAML IdP metadata XML file downloaded from the OneLogin admin portal.

  10. Click Import to import the OneLogin configuration.

  11. If the user should not be logged out from the OneLogin portal when logging out of SMA1000 Connect Tunnel or Workplace, clear the Logout service URL field value.

  12. Expand the Advanced section.

  13. For group level management, if you are sending user groups or roles information from OneLogin to SMA1000 (in case of no on-prem AD), set the SAML claim containing the user groups field with the value as the field name you configured when creating the application on the OneLogin admin portal.

    • Example 1: groups

    • Example 2: roles

  14. For group level management, if the user directory (Active Directory, etc) is available on-premises, configure it as an authentication server. Next, use the "Group Authorisation" option on the Realm page to leverage AD for resource authorisation, while using OneLogin for user authentication. Refer to the following sections

  15. Click Save.