SonicOS 8 SAML Feature Guide

Import from File

To configure SAML IdP using import from file

  1. Navigate to Device > Users > Settings > SAML Configuration.

  2. Click the Configure button next to SAML Identity Provider.

  3. In the SAML Identity Provider dialog box, click Import SAML File.

  4. In the Import SAML File dialog box, click Add File.

  5. Select the XML metadata file downloaded from your IdP server and click Open.

    Most IdPs offer the option to download the IdP metadata in XML format.

  6. In the Name field, enter the name for the IdP profile.

  7. Click Next.

    You will be prompted to restart the firewall; you can choose to restart the firewall later.

    Most IdP XML metadata files contain a certificate from the IdP provider. If the certificate has already been imported to the firewall, the message ‘CA Certificate has been loaded before’ is displayed. Click OK.

  8. Importing IdP XML metadata file auto populate some fields (SAML IdP Server ID, ACS URL, Certificate). If any URLs, such as the logout service URL, are missing, please fill them in manually. You can obtain this information from your IdP.

    User Name Attribute and Group Name Attribute need to be entered manually. User Name attribute is mandatory, and group name is optional.

  9. In the User Name Attribute field, enter the attribute name from IdP that maps to the user name.

  10. In the Group Name Attribute field, enter the attribute name from IdP that maps to the group name.


    The User Name Attribute identifies the user's login name in the SAML assertion, while the Group Name Attribute specifies their group, both pulled from the Identity Provider (IdP) during authentication. You must specify which attributes from the IdP correspond to the User Name and Group Name.
    You must configure the matching group names on the Firewall and the IdP to ensure that the authenticated user is part of the necessary groups. These groups can later be used in various security policies on the Firewall.
    For Example: when managing the firewall via SAML Single Sign-On (SSO), a user must have administrative privileges for authentication. To achieve this, the Identity Provider (IdP) should return a group name attribute that exactly matches the default group on the firewall, which is "SonicWall Administrators." Once the user is logged in and mapped to this group, they will gain admin privileges on the firewall. You can apply the same approach for other privileges on the firewall, such as the SSLVPN services group or any custom groups you wish to use in security policies after a user is identified via User Level Authentication (ULA).

  11. Click Save.

  12. Click Continue.


    To ensure users can access the IdP URLs and login screen, SonicOS will automatically create address objects and access rules for these URLs.
    For non LAN cases, or if wish to create the access rules manually, clear the checkbox Create Address Group and Access Rules for me.

  13. Click Next.

    On the SAML Identification Provider dialog box, the last entry displays the newly created IDP provider.

  14. Click Close.