跳到主内容

Connect AWS Client VPN with SAML

This guide explains how to use Casdoor as the SAML identity provider (IdP) of AWS Client VPN.


Learning outcomes​

  • Configure a Casdoor application for AWS Client VPN.
  • Add Casdoor as a SAML identity provider in AWS IAM.
  • Create a Client VPN endpoint that authenticates users through Casdoor.
  • Connect to the VPN.

What you need​


Configure the Casdoor application​

  1. In the Casdoor admin console, open the edit page of the application.

  2. Add urn:amazon:webservices:clientvpn to Redirect URLs.

    Redirect URLs with the AWS Client VPN identifier

  3. 将设置SAML 响应 URL为http://127.0.0.1:35001。

    SAML reply URL for AWS Client VPN

  4. Save the SAML metadata as an XML file. You upload it to AWS in the next section.

    SAML metadata of the application

Add Casdoor as an identity provider in AWS​

  1. In the IAM console, go to Identity providers and click Create provider.

    Create provider in the IAM console

  2. Select SAML, enter a name for the provider, and upload the metadata file from Casdoor.

    Metadata upload in the IAM console

  3. Click Next step, and then Create.

创建客户端VPN端点​

  1. In the VPC console, go to Client VPN Endpoints and click Create Client VPN Endpoint.

    Client VPN Endpoints in the VPC console

  2. In Client IPv4 CIDR, enter the address range for remote users.

  3. In Server certificate, select your certificate from ACM.

  4. Under Authentication, select User-based authentication, and then Federated authentication.

  5. Select the SAML identity provider that you created.

  6. 点击创建客户端VPN端点。

    Client VPN endpoint settings

Associate the endpoint with a VPC​

  1. Open the endpoint, go to Target network associations, and click Associate target network.

  2. Select the VPC and the subnet.

    Target network association

Add an authorization rule​

This step is optional. It limits access to a network to one group of users.

  1. Open the endpoint, go to Authorization rules, and click Add authorize rule.

  2. In Destination network, enter the network of your EC2 instance, for example 172.31.16.0/20.

  3. Under Grant access to, select Allow access to users in a specific access group and enter the name of the group, for example casdoor.

  4. 添加规则。

    Authorization rule

Verify the result​

  1. In the VPC console, select the endpoint, wait until its state is Available, and click Download Client Configuration.

    Download Client Configuration

  2. In the AWS Client VPN application, go to File > Manage Profiles, click Add Profile, and select the downloaded file.

  3. 选择配置文件并单击连接。 The Casdoor sign-in page opens in your browser. After you sign in, the VPN connects.

See also​