ADFS SAML Configuration

L1 Bithead

ADFS SAML Configuration

Hi all

 

I need help to configure ADFS SAML with global-protect.

i have successfully imported the metadata.xml from adfs into palo.

But now i can't export the metadata from paloalto. 

 

Screen Shot 2017-02-25 at 03.50.54.png

 

Whats the correct identifiers and endpoints urls for global-contect clientless? I have no idea, what i must configure in adfs. 

Can anyone help?

I use panos 8.0

 

regards

Benjamin

 

 

 

L1 Bithead

Re: ADFS SAML Configuration

I solved the issue with the cli and now i have a connection from adfs to palo. But i can't login with adfs to palo alto. Has anyone experience with adfs -> saml palo alto?
i don't know what username attribute i must use for saml.

 

I created this rule in the adfs:

Screen Shot 2017-02-28 at 15.18.17.pngScreen Shot 2017-02-28 at 15.19.42.png

 

Palo Alto Saml Profile:

Screen Shot 2017-02-28 at 15.20.13.png

 

Could anyone help me?

 

Regards

Benjamin

L7 Applicator

Re: ADFS SAML Configuration

Hello,

While I have not set this up before, I am familiure with ldap. For the User attriobute, have you tried sAMAccountName?

 

Regards,

L1 Bithead

Re: ADFS SAML Configuration

Yes, i tested with sAMAccountName but it doesn't work. Login failed.

 

Screen Shot 2017-03-01 at 09.17.11.png

 

 

L7 Applicator

Re: ADFS SAML Configuration

If you havent already, I would recommend opening a support ticket.

L1 Bithead

Re: ADFS SAML Configuration

Yes, i think i must open a ticket for this case. Thanks for your help.

 

L2 Linker

Re: ADFS SAML Configuration

Looking at the transforms in ADFS that are populating your SAML Response, you probably want to use NameID as the username attribute in your configuration on the PAN-OS side. 

 

 

 

 

L0 Member

Re: ADFS SAML Configuration

Hi Benjamin,

 

Did you ever get this sorted out.   What was the trick?

 

Regards, Malcolm

L1 Bithead

Re: ADFS SAML Configuration

Hi Malcolm

 

No, it doesn't work. 

I will spend more time in this task in 2-3 weeks.

It's not a high prio task for us. 

 

regards, Benjamin

L2 Linker

Re: ADFS SAML Configuration

Hi @benjaminsutter

 

i would please like to know whether you were able to solve this problem

as am now facing the same Issue with SAML and AD FS (Login Retry)

 

I think the piece that is actually missing are Username Attribute and User group Attribute.

 

What parameters did you use for Username Attribute and User group Attribute?

 

I will deeply appreciate any hints on this matter.

 

 

kind regards,

Gilo

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!