<div dir="ltr">UWash uses F5 VPN configured to use SAML to integrate with our Shibboleth IdP.<div><br></div><div>The F5 BIG-IP Edge client applications use embedded browsers, and work well enough with our IdP's sign-in page (below), including Duo prompt (not pictured below).</div><div><br></div><div>Our end user information is here:</div><div><a href="https://itconnect.uw.edu/connect/uw-networks/about-husky-onnet/">https://itconnect.uw.edu/connect/uw-networks/about-husky-onnet/</a><br></div><div><br></div><div>-Nathan</div><div><br></div><div><img src="cid:ii_kk7a7fs40" alt="Screen Shot 2021-01-21 at 11.58.42 AM.png" width="562" height="540"><br></div><div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Jan 21, 2021 at 11:43 AM IAM David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div>UAlaska has deployed VPN access using Global Protect. If I understand correctly, VPNs are (or can be) initiated in a web portal. If so, seems one could protect that web page with Shibb and thus have a valid SSO session immediately upon establishment of VPN connection (at least if IP address consistency is not enforced). I’ve been asked about that scenario by alert users. Has anyone tried that and willing to share experience? Or perhaps disabuse me of its feasibility?<div><br></div><div>David St. Pierre Bant</div><div>UAlaska IAM</div></div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>