In a federation of BIG-IP® systems, one BIG-IP system acts as a SAML Identity Provider (IdP) and other BIG-IP systems act as SAML service providers.
This configuration supports:
A SAML IdP service is a type of single sign-on (SSO) authentication service in Access Policy Manager® (APM®). When you use a BIG-IP® system as a SAML identity provider (IdP), a SAML IdP service provides SSO authentication for external SAML service providers (SPs). You must bind a SAML IdP service to SAML SP connectors, each of which specifies an external SP. APM responds to authentication requests from the service providers and produces assertions for them.
A SAML service provider connector (an SP connector) specifies how a BIG-IP® system, configured as a SAML Identity Provider (IdP), connects with an external service provider.
You can use one or more of these methods to configure SAML service provider (SP) connectors in Access Policy Manager®.
A SAML SP service is a type of AAA service in Access Policy Manager® (APM® ). It requests authentication from an external SAML Identity Provider (IdP) that is specified on APM in a SAML IdP connector. (You bind a SAML service provider (SP) service to one or more SAML IdP connectors.) APM requests authentication from an IdP and consumes assertions from it to allow access to resources behind APM.
An IdP connector specifies how a BIG-IP® system, configured as a SAML service provider (SP), connects with an external SAML identity provider (IdP).
You can use one or more of these methods to configure SAML identity provider (IdP) connectors in Access Policy Manager® (APM®).
Setting up SAML federation for BIG-IP® systems involves three major activities:
This flowchart illustrates the process for configuring BIG-IP® systems in federation and providing an SSO portal.
You associate the access profile with the virtual server so that Access Policy Manager® can apply the profile to incoming traffic.
You associate the access profile with the virtual server so that Access Policy Manager® can apply the profile to incoming traffic.