<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
We recently deployed Cisco's VPN using SAML authentication, and it uses an embedded browser that doesn't share cookies. Still, it is really nice to use our standard campus login page (with Duo) instead of some custom auth solution!</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Andy<br>
</div>
<div>
<div id="appendonsend"></div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt" face="Calibri, sans-serif" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Thursday, January 21, 2021 11:51 AM<br>
<b>To:</b> Shib Users <Users@shibboleth.net><br>
<b>Subject:</b> Re: Shibb for Global Protect VPN?</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="PlainText">[This email originated from outside of OSU. Use caution with links and attachments.]<br>
<br>
On 1/21/21, 2:42 PM, "users on behalf of IAM David Bantz" <users-bounces@shibboleth.net on behalf of dabantz@alaska.edu> wrote:<br>
<br>
> UAlaska has deployed VPN access using Global Protect. If I understand correctly, VPNs are (or can be) initiated in a web<br>
> portal. If so, seems one could protect that web page with Shibb and thus have a valid SSO session immediately upon<br>
> establishment of VPN connection (at least if IP address consistency is not enforced).<br>
<br>
As far as I know, virtually never. Those are usually based on embedded browsers that aren't going to share cookie state with any browser somebody is using.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</div>
</body>
</html>