Skip to main content
cpynch
New Member
August 27, 2025
Solved

IPSec VPN with SAML and Certificates - Implicit deny on FW groups

  • August 27, 2025
  • 5 replies
  • 1931 views

Hey all, I recently setup an IPSec VPN to replkace our SSL VPN using Entra and SAML. I had an issue with setting an authusrgrp in the phase1-interface and getting it to work with the user groups that are SAML based. Unset authusrgrp in Phase-1 fixed the issue, and the FW groups starting mathcing on the traffic, but since I moved away from PSK and onto Certificates for IPSec VPN the same behaviour came back, but the authusrgrp knob is gone now due to the certificates. 

Can I use SAML based FW groups to segregate traffic while using certs? 

More specifics;
We have departmental groups setup in the Entra application, and we need to make sure their access is restricted as such. I'd prefer to only have a single Phase-1 interface that's a 'catch all' for all SAML users (single IP range for all) and let the FW determine who can access what by the SAML groups, if possible.

Any thoughts on what might be causing the FW groups to not match on traffic? 

Best answer by cpynch

Ended up creating multiple Phase-1 interfaces for each dept\group with unique DH groups for each. Created PKI groups with unique subjects for each OU\dept, and unique IP pools for each P1 interface - now IPSec with SAML and certificates is working perfectly. FW traffic segregation is done via subnet now with no need to use EAP for FW groups. 

5 replies

Anthony_E
Staff
Staff
September 1, 2025

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Anthony_E
Staff
Staff
September 4, 2025

Hello,

We are still looking for someone to help you.

We will come back to you ASAP.


Thanks,

Best Regards
cpynch
cpynchAuthorAnswer
New Member
September 4, 2025

Ended up creating multiple Phase-1 interfaces for each dept\group with unique DH groups for each. Created PKI groups with unique subjects for each OU\dept, and unique IP pools for each P1 interface - now IPSec with SAML and certificates is working perfectly. FW traffic segregation is done via subnet now with no need to use EAP for FW groups. 

funkylicious
SuperUser
SuperUser
September 4, 2025

can you please share a sanitized config of your setup that works?

it sounds really interesting and would like to have it as a future reference :)

"jack of all trades, master of none"
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!