How to Configure SAML Authentication for FSG (Flexible Secure Gateway)

Item

Description

Pre-check

  • Prior configuration is required in the FSG (Flexible Secure Gateway) (hereinafter "FSG") settings.

  • For the latest setup procedure, please refer to the manual provided by FSG.

Name ID

Email address

 

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

 

Request the SP to configure

Provisioning

 

Supports API-based provisioning (account management possible in TrustLogin)

 

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other

Notes

  • If the number of cells included in the linked cell group exceeds five, authentication integration cannot be performed using the procedure described in this article. If this applies to you, please contact our support desk.

 

Table of Contents:

TrustLogin Admin Page Configuration

FSG Configuration

TrustLogin Admin Page Configuration (Continued)

TrustLogin User Configuration

Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ① [Register Custom URL Category]

Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ② [Add Security Policy Rule]

Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ③ [Add Captive Portal Authentication Exclusion Setting]

 

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Company App Registration" screen, search and select "FSG(Flexible Secure Gateway)".
    02.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
    03.png

Now, switch to the FSG-side configuration.
Do not click the "Register" button yet; open the FSG console in a separate window.

 

FSG Configuration

  1. Log in to the FSG console, select the target cell group from the drop-down list, and open "Active Directory".
    fsg01.png

  2. Click the "v" to the left of Microsoft Entra ID to expand the Microsoft Entra ID configuration accordion.
    fsg02.png

  3. Click "Add New" under "SAML Identity Provider Config".
    fsg03.png

  4. Set an arbitrary name for the SAML Identity Provider Config in "Name", and upload the metadata obtained from TrustLogin in "Federation Metadata XML Upload". When you have finished editing, click "Confirm".
    fsg04.png

  5. Check the details and click "Execute".
    fsg05.png

  6. Confirm the application completion message and click "OK".
    fsg06.png

  7. To display the latest information, click the "Refresh" button.
    fsg07.png

  8. Click the "Apply Config" button in the left menu to apply the settings to the cell.
    Config Application Procedure

  9. Click the "View Identifier/Reply URL" button to the right of "SAML Identity Provider Config".
    fsg08.png

  10. Make a note of the IP address of each cell.
    fsg09.png

 

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure each item under "Service Provider Configuration" as follows.
    Login URL The IP address of any cell from the identifier/reply URL confirmed in the FSG console
    Entity ID The IP address of any cell from the identifier/reply URL confirmed in the FSG console

    Note: enter the same value (the IP address of the same cell) for both the Login URL and Entity ID
    ACS URL to the Service
    The IP addresses of all cells from the reply URL confirmed in the FSG console

    Note: If cells are redundant, enter the IP address of each cell in the cell group one by one in each field

    04.png

  2. Click the "Register" button to save.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "FSG(Flexible Secure Gateway)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "FSG(Flexible Secure Gateway)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

 

Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ①
[Register Custom URL Category]

When integrating with TrustLogin, you need to configure authentication exclusion settings on the Captive Portal and communication permission settings on the UTM for the traffic used for authentication.

This section registers the TrustLogin URLs, which are specified as the communication destinations in each setting, as a custom URL category.

From the FSG console, register the URLs that are the destinations of TrustLogin authentication traffic as a category.
For the setup procedure, see Configuring a Custom URL Category.
Depending on your usage, you may also need to register the URL lists in ② and ③.

Name
Any identifiable name
URL List ①
Required
・portal.trustlogin.com
・tl-prod-cluster-images.s3.*.amazonaws.com
URL List ②
Required if using AD integration (optional)
・a-mq-ad.services.sku.id:5671
・b-mq-ad.services.sku.id:5671
URL List ③
Required if using client authentication (optional)
・cert.sku.id
・cert.trustlogin.com
・ocsp.globalsign.com
・crl.globalsign.com
・secure.globalsign.com


fsg10.png

 

Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ②
[Add Security Policy Rule]

This section adds a security policy that explicitly allows the traffic used during TrustLogin authentication integration on the UTM.

For any parameters not listed below, specify values of your choosing.

From the FSG console, follow the procedure in Configuring the UTM Feature (Security Policy Rules) to add a security policy that allows the following TrustLogin authentication traffic.

Name Any identifiable name
Log Log enabled
Source IP Address any
Destination IP Address any
Destination TCP Port any
Custom URL Category/Custom URL Category List the previous section's URL category
Application List any
Action Allow

 

  • Due to UTM specifications, security policy rules deny all traffic that is not explicitly allowed by a rule, in principle.
  • For any outbound traffic that needs to be allowed after successful TrustLogin authentication, add an allow rule below the rule you configured in this section.

fsg11.png


After adding the security policy, click "Change Priority" in the FSG console to move the created policy to the top.fsg12.png


Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ③
[Add Captive Portal Authentication Exclusion Setting]

This section adds a setting to explicitly exclude the traffic used during TrustLogin authentication integration from Captive Portal authentication determination.

From the FSG console, follow the procedure for configuring Captive Portal authentication exclusion to add the following TrustLogin authentication traffic to the Captive Portal authentication settings.

 

Name Any identifiable name
Source IP Address any
Destination IP Address any
Destination TCP Port any
Custom URL Category/Custom URL Category List the section before last's URL category


fsg13.png

How to Configure SAML Authentication for FSG (Flexible Secure Gateway)

Item

Description

Pre-check

  • Prior configuration is required in the FSG (Flexible Secure Gateway) (hereinafter "FSG") settings.

  • For the latest setup procedure, please refer to the manual provided by FSG.

Name ID

Email address

 

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

 

Request the SP to configure

Provisioning

 

Supports API-based provisioning (account management possible in TrustLogin)

 

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other

Notes

  • If the number of cells included in the linked cell group exceeds five, authentication integration cannot be performed using the procedure described in this article. If this applies to you, please contact our support desk.

 

Table of Contents:

TrustLogin Admin Page Configuration

FSG Configuration

TrustLogin Admin Page Configuration (Continued)

TrustLogin User Configuration

Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ① [Register Custom URL Category]

Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ② [Add Security Policy Rule]

Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ③ [Add Captive Portal Authentication Exclusion Setting]

 

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Company App Registration" screen, search and select "FSG(Flexible Secure Gateway)".
    02.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
    03.png

Now, switch to the FSG-side configuration.
Do not click the "Register" button yet; open the FSG console in a separate window.

 

FSG Configuration

  1. Log in to the FSG console, select the target cell group from the drop-down list, and open "Active Directory".
    fsg01.png

  2. Click the "v" to the left of Microsoft Entra ID to expand the Microsoft Entra ID configuration accordion.
    fsg02.png

  3. Click "Add New" under "SAML Identity Provider Config".
    fsg03.png

  4. Set an arbitrary name for the SAML Identity Provider Config in "Name", and upload the metadata obtained from TrustLogin in "Federation Metadata XML Upload". When you have finished editing, click "Confirm".
    fsg04.png

  5. Check the details and click "Execute".
    fsg05.png

  6. Confirm the application completion message and click "OK".
    fsg06.png

  7. To display the latest information, click the "Refresh" button.
    fsg07.png

  8. Click the "Apply Config" button in the left menu to apply the settings to the cell.
    Config Application Procedure

  9. Click the "View Identifier/Reply URL" button to the right of "SAML Identity Provider Config".
    fsg08.png

  10. Make a note of the IP address of each cell.
    fsg09.png

 

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure each item under "Service Provider Configuration" as follows.
    Login URL The IP address of any cell from the identifier/reply URL confirmed in the FSG console
    Entity ID The IP address of any cell from the identifier/reply URL confirmed in the FSG console

    Note: enter the same value (the IP address of the same cell) for both the Login URL and Entity ID
    ACS URL to the Service
    The IP addresses of all cells from the reply URL confirmed in the FSG console

    Note: If cells are redundant, enter the IP address of each cell in the cell group one by one in each field

    04.png

  2. Click the "Register" button to save.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "FSG(Flexible Secure Gateway)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "FSG(Flexible Secure Gateway)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

 

Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ①
[Register Custom URL Category]

When integrating with TrustLogin, you need to configure authentication exclusion settings on the Captive Portal and communication permission settings on the UTM for the traffic used for authentication.

This section registers the TrustLogin URLs, which are specified as the communication destinations in each setting, as a custom URL category.

From the FSG console, register the URLs that are the destinations of TrustLogin authentication traffic as a category.
For the setup procedure, see Configuring a Custom URL Category.
Depending on your usage, you may also need to register the URL lists in ② and ③.

Name
Any identifiable name
URL List ①
Required
・portal.trustlogin.com
・tl-prod-cluster-images.s3.*.amazonaws.com
URL List ②
Required if using AD integration (optional)
・a-mq-ad.services.sku.id:5671
・b-mq-ad.services.sku.id:5671
URL List ③
Required if using client authentication (optional)
・cert.sku.id
・cert.trustlogin.com
・ocsp.globalsign.com
・crl.globalsign.com
・secure.globalsign.com


fsg10.png

 

Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ②
[Add Security Policy Rule]

This section adds a security policy that explicitly allows the traffic used during TrustLogin authentication integration on the UTM.

For any parameters not listed below, specify values of your choosing.

From the FSG console, follow the procedure in Configuring the UTM Feature (Security Policy Rules) to add a security policy that allows the following TrustLogin authentication traffic.

Name Any identifiable name
Log Log enabled
Source IP Address any
Destination IP Address any
Destination TCP Port any
Custom URL Category/Custom URL Category List the previous section's URL category
Application List any
Action Allow

 

  • Due to UTM specifications, security policy rules deny all traffic that is not explicitly allowed by a rule, in principle.
  • For any outbound traffic that needs to be allowed after successful TrustLogin authentication, add an allow rule below the rule you configured in this section.

fsg11.png


After adding the security policy, click "Change Priority" in the FSG console to move the created policy to the top.fsg12.png


Authentication Exclusion/Communication Permission Settings for TrustLogin Authentication Traffic ③
[Add Captive Portal Authentication Exclusion Setting]

This section adds a setting to explicitly exclude the traffic used during TrustLogin authentication integration from Captive Portal authentication determination.

From the FSG console, follow the procedure for configuring Captive Portal authentication exclusion to add the following TrustLogin authentication traffic to the Captive Portal authentication settings.

 

Name Any identifiable name
Source IP Address any
Destination IP Address any
Destination TCP Port any
Custom URL Category/Custom URL Category List the section before last's URL category


fsg13.png