SSL VPN Authentication with OIDC External Groups
Options
Zyxel_Lynn
Zyxel Employee
Zyxel Employee
SSL VPN with OIDC External Groups
Building on the OpenID Connect (OIDC) support introduced in previous versions, Zyxel firewalls now support OIDC External Groups specifically for SSL VPN authentication.
Configuration Workflow
- Server Setup: Configure the OIDC server settings (e.g., Microsoft Entra ID) and verify connectivity using the built-in validation test to retrieve group information.
2. External Group Creation: Create an "External Group User" on the firewall, linking it to the OIDC server and specifying the Group Identifier (Object ID) from the identity provider.

3. VPN Application: Set the SSL VPN's primary authentication server to the OIDC server.

This enhancement allows administrators to manage VPN access permissions centrally within their identity provider (IdP) rather than creating individual local users, streamlining large-scale deployments.
0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 237 Nebula Ideas
- 6.8K Security
- 740 USG FLEX H Series
- 376 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 319 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.3K FAQ
- 34 Documents
- 91 About Community
- 119 Security Highlight