IPSec VPN with SAML and Certificates - Implicit deny on FW groups
Hey all, I recently setup an IPSec VPN to replkace our SSL VPN using Entra and SAML. I had an issue with setting an authusrgrp in the phase1-interface and getting it to work with the user groups that are SAML based. Unset authusrgrp in Phase-1 fixed the issue, and the FW groups starting mathcing on the traffic, but since I moved away from PSK and onto Certificates for IPSec VPN the same behaviour came back, but the authusrgrp knob is gone now due to the certificates.
Can I use SAML based FW groups to segregate traffic while using certs?
More specifics;
We have departmental groups setup in the Entra application, and we need to make sure their access is restricted as such. I'd prefer to only have a single Phase-1 interface that's a 'catch all' for all SAML users (single IP range for all) and let the FW determine who can access what by the SAML groups, if possible.
Any thoughts on what might be causing the FW groups to not match on traffic?
