Cisco Cisco Web Security Appliance S170 사용자 가이드

다운로드
페이지 734
 
16-4
Cisco IronPort AsyncOS 7.5.7 for Web User Guide
Chapter 16      Controlling Access to SaaS Applications
Understanding How SaaS Access Control Works
Note
To achieve single sign-on behavior using explicit forward requests for all authenticated users when the 
appliance is deployed in transparent mode, you must select the “Apply same surrogate settings to explicit 
forward requests” setting when you configure the Identity group.
Authentication Requirements
Some service providers require a particular authentication mechanism to allow users to access the SaaS 
application. If a service provider requires an authentication context that is not supported by an identity 
provider, users cannot access the service provider using single sign-on from the identity provider. 
Therefore, SaaS Access Control only works with SaaS applications that require an authentication 
mechanism supported by the Web Security appliance. Currently, the Web Proxy uses the 
“PasswordProtectedTransport” authentication mechanism. You configure this value when you create a 
SaaS Application Authentication Policy using the Authentication Context setting. However, 
administrators typically choose “Automatic” as the Authentication Context setting.
For more information on creating SaaS Application Authentication Policies, see 
Enabling SaaS Access Control
To enable SaaS Access Control, you must configure settings on both the Web Security appliance and the 
SaaS application. It is very important that the settings you configure on the appliance and SaaS 
application match each other appropriately.
When enabling SaaS Access Control, it is easiest to keep open a connection to the Web Security 
appliance and the SaaS application simultaneously. You will need to go back and forth between both 
components and copy and paste information between both.
Note
For more information on configuring SaaS Access Control for particular SaaS applications, contact your 
technical sales representative or search the cisco.com website for additional information, such as white 
papers, knowledge base articles, or video tutorials.
To use SaaS Access Control, follow these steps:
1.
Configure the Web Security appliance as an identity provider. For more information, see 
.
2.
Configure the SaaS application for single sign-on. When configuring the SaaS application, you 
must also upload the certificate used on the Security Services > Identity Provider for SaaS page. For 
more information, see the SaaS application documentation.
3.
Create one or more SaaS Application Authentication Policies for each SaaS application. For 
more information, see 
Understanding the Single Sign-On URL
After you configure the Web Security appliance as an identity provider and create a SaaS Application 
Authentication Policy for the SaaS application, the appliance creates a single sign-on URL (SSO URL).
How administrators use this URL depends on the flow type: