SSL VPN Authentication with OIDC External Groups

Options
Zyxel_Lynn
Zyxel_Lynn image  Zyxel Employee
5 Answers First Comment Friend Collector First Anniversary
edited August 18 in Other Topics

SSL VPN with OIDC External Groups

Building on the OpenID Connect (OIDC) support introduced in previous versions, Zyxel firewalls now support OIDC External Groups specifically for SSL VPN authentication.

Configuration Workflow

  1. Server Setup: Configure the OIDC server settings (e.g., Microsoft Entra ID) and verify connectivity using the built-in validation test to retrieve group information.

    2. External Group Creation: Create an "External Group User" on the firewall, linking it to   
       the OIDC server and specifying the Group Identifier (Object ID) from the identity provider.


    3. VPN Application: Set the SSL VPN's primary authentication server to the OIDC server.

This enhancement allows administrators to manage VPN access permissions centrally within their identity provider (IdP) rather than creating individual local users, streamlining large-scale deployments.