SAML 2.0 Authentication Issue

Ian Gultom Lv1Posted May-28-2025 17:43

My IAG device starts showing error like this everytime i tried to authenticate via SAML 2.0.
It was working fine before


Are there any way to resolve this issue?

Wayuphag has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

1 Reconfirm time sync across all devices.

2 Re-import fresh SAML metadata and certificates on both sides.

3 Double-check all SAML URLs, entity IDs, and RelayState settings.

4 Test via private/incognito browser to rule out cached SAML tokens.

5 Temporarily bypass NGAF/IAM security layers and test again.
Is this answer helpful?
Wayuphag Lv1Posted May-29-2025 16:35
  
1 Reconfirm time sync across all devices.

2 Re-import fresh SAML metadata and certificates on both sides.

3 Double-check all SAML URLs, entity IDs, and RelayState settings.

4 Test via private/incognito browser to rule out cached SAML tokens.

5 Temporarily bypass NGAF/IAM security layers and test again.
Sheikh_Shani Lv2Posted May-29-2025 17:07
  
Here are a few ways to resolve this:

1. Disable or Relax the IP/MAC Binding Check
Log in to your IAG admin console.

Navigate to the Authentication policy or Security settings.

Look for a setting related to IP/MAC binding or session binding.

Try disabling it or setting it to IP-only (if MAC address is not necessary).

Note: Disabling this check could lower security, so evaluate the risk first.

2. Allow Dynamic IP/MAC Changes
Some systems allow session continuation even if the MAC/IP changes slightly — look for a tolerance or grace period setting.

Ensure the session persistence or sticky session option is enabled if you're behind a load balancer.

3. Whitelist Trusted Networks or Devices
If only specific users are impacted, consider whitelisting their devices or networks.

You might allow exceptions to the binding policy under specific conditions (e.g., internal network, known device).

4. Check for Recent Changes
If it was working before, look into:

Recent firmware/software updates on the IAG.

Changes in the network configuration (e.g., VPN, DHCP scope).

Any browser or OS-level changes affecting network adapters.

5. User-Side Checks
Ensure users are not switching networks (e.g., Wi-Fi to mobile data) during authentication.

Avoid browser plugins or proxies that might alter IP/MAC info.

pmateus Lv3Posted Jun-04-2025 21:18
  
Hi,
Please check the logs about errors related with this issue to verify what is causing this issue.

thanks,

I Can Help:

Change

Moderator on This Board

910
182
94

Started Topics

Followers

Follow

Board Leaders