Authentication
OIDC Authentication
VNS3 Licensing
Access Management
Clientpack Generation
Installing HTTPS
Firewall 2.0
Firewall
AWS Specific features
Firewall FWSets
VNS3 Variables
VNS3 Router
IPsec Configuration
IPsec Parameters
VNS3 Peering Mesh
Setting Topology Name
VNS3 Overlay Network
Snapshot Management
VNS3 Event Alerting
Network Address Translation
Traffic inspection
SNMP Support
VNS3 BGP Configuration Guide
Remote Support
Resetting VNS3
Upgrading
VNS3 Release Notes
VNS3 EOL Policy and Milestones
IPSec Connection Checklist
VNS3 Known Issues
VNS3 Specifications
VNS3 VPN Client tools
VNS3 Control Center
VNS3 setup
OIDC Authentication
Admin Authentication
OIDC can be configured for administrators to log into the VNS3 controller. To configure a VNS3 controller for OIDC login, click on Identity Managment on the left navigation and click on the VNS3 Admins tab on the top right of the configuration page.
Add the client OIDC application (see your Identify Provider for creating OIDC applications) identifier and the secret, then add the associated URL’s. For convenience, the OpenID Connect Discovery URL can be used to auto populate the OIDC urls by clicking on Use discovery. Note, be sure to click to enable the ODIC authentation at the top left of the configuration page.
The following shows a configured OIDC controller:
Logging into the UI using OIDC
Logging into the UI using the sytem account requires entering the controller username and password and clicking Login.
If OIDC is configured on the controller, you will see an additional option with
a link below the form, such as below (Log in with okta.com), that administrators can click to log in via OIDC and administer
the VNS3 controller.
VPN Client Authenication
Wireguard VPN clients can be configured to authenticate using OIDC to connect to the VPN. To configure a VNS3 for OIDC login, click on Identity Management of the left navigation and click on the VPN Users tab on the right. Add the client OIDC application (see your Identify Provider for creating OIDC applications) identifier and secret, then add the associated URL’s. For convenience, the OpenID Connect Discovery URL can be used to auto populate the OIDC urls by clicking on Use discovery. Note, be sure to click to enable the ODIC authentation at the top left of the configuration page.
The following shows a configured OIDC controller to use:
Once configured, VNS3 VPN clients (Download VNS3 VPN Client) will see a browser window appear when they attempt to make a VPN connection, enter the credentials and then a message will appear that authentication has succeeded and the VPN connection is completed.
Updated on 24 Apr 2020