Passer au contenu principal

Connect AWS Client VPN with SAML

This guide explains how to use Casdoor as the SAML identity provider (IdP) of AWS Client VPN.


Learning outcomes​

  • Configure a Casdoor application for AWS Client VPN.
  • Add Casdoor as a SAML identity provider in AWS IAM.
  • Create a Client VPN endpoint that authenticates users through Casdoor.
  • Connect to the VPN.

What you need​


Configure the Casdoor application​

  1. In the Casdoor admin console, open the edit page of the application.

  2. Add urn:amazon:webservices:clientvpn to Redirect URLs.

    Redirect URLs with the AWS Client VPN identifier

  3. Set SAML reply URL to http://127.0.0.1:35001.

    SAML reply URL for AWS Client VPN

  4. Save the SAML metadata as an XML file. You upload it to AWS in the next section.

    SAML metadata of the application

Add Casdoor as an identity provider in AWS​

  1. In the IAM console, go to Identity providers and click Create provider.

    Create provider in the IAM console

  2. Select SAML, enter a name for the provider, and upload the metadata file from Casdoor.

    Metadata upload in the IAM console

  3. Click Next step, and then Create.

Create a Client VPN endpoint​

  1. In the VPC console, go to Client VPN Endpoints and click Create Client VPN Endpoint.

    Client VPN Endpoints in the VPC console

  2. In Client IPv4 CIDR, enter the address range for remote users.

  3. In Server certificate, select your certificate from ACM.

  4. Under Authentication, select User-based authentication, and then Federated authentication.

  5. Select the SAML identity provider that you created.

  6. Cliquez sur Créer un point de terminaison VPN client.

    Client VPN endpoint settings

Associate the endpoint with a VPC​

  1. Open the endpoint, go to Target network associations, and click Associate target network.

  2. Select the VPC and the subnet.

    Target network association

Add an authorization rule​

This step is optional. It limits access to a network to one group of users.

  1. Open the endpoint, go to Authorization rules, and click Add authorize rule.

  2. In Destination network, enter the network of your EC2 instance, for example 172.31.16.0/20.

  3. Under Grant access to, select Allow access to users in a specific access group and enter the name of the group, for example casdoor.

  4. Add the rule.

    Authorization rule

Verify the result​

  1. In the VPC console, select the endpoint, wait until its state is Available, and click Download Client Configuration.

    Download Client Configuration

  2. In the AWS Client VPN application, go to File > Manage Profiles, click Add Profile, and select the downloaded file.

  3. Select the profile and click Connect. The Casdoor sign-in page opens in your browser. After you sign in, the VPN connects.

See also​