Wallix Trustelem SSO (SAML)
To secure access to ngrok with Wallix Trustelem Single Sign-On using SAML:
This article details how to configure Wallix Trustelem as the primary Identity Provider for ngrok tunnels. By integrating Wallix Trustelem SSO with ngrok, you can:
- Restrict access to ngrok tunnels only to users authenticated via Wallix Trustelem.
- Use Wallix Trustelem security policies and MFA authenticators.
- Use Wallix Trustelem's Dashboard to facilitate access to ngrok apps.
Requirements
To configure ngrok tunnels with Wallix Trustelem, you must have:
- a Wallix Trustelem account with administrative rights to create apps.
- an ngrok Enterprise Account with an authtoken or admin access to configure edges with SAML.
Configuration Steps
To integrate ngrok with Wallix Trustelem SSO, you will need to:
- Configure Wallix Trustelem with the ngrok app.
- Configure ngrok with the SSO settings provided by Wallix Trustelem.
Step 1: Configure Wallix Trustelem
-
Access the WALLIX Trustelem administration console, and sign in using your Trustelem account.
-
On the Dashboard page, click Apps on the left menu, click Add an application and click the SAML 2 application tile in the Generic models section.
-
On the Settings popup, enter
ngrok saml
in the Name field, click Save, click Download metadata files, save the XML file on your desktop, and then click Close.
Step 2: Configure ngrok
To configure an edge with Wallix Trustelem:
-
Access the ngrok Dashboard and sign in using your ngrok account.
-
On the left menu, click Cloud Edge and then click Edges.
-
If you don't have an edge already set to add Wallix Trustelem SSO, create a test edge:
- Click + New Edge.
- Click Create HTTPS Edge.
- Click the pencil icon next to "no description", enter
Edge with Trustelem SSO SAML
as the edge name, and click Save.
-
On the edge settings menu, click SAML.
-
On the SAML page, click Begin setup, click Upload XML, and then open the XML metadata file you downloaded from Wallix Trustelem (See Download the IdP metadata).
-
Click Save at the top.
-
On the SAML page of your ngrok edge, make note of the URL of both the Entity ID and ACS URL fields.
Step 3: Link Wallix Trustelem with ngrok
-
On the WALLIX Trustelem administration console, click Apps on the left menu, and then click your application.
-
On the Settings popup, click Edit, paste the Entity ID URL in the EntityID field and the ACS URL URL in the Assertion Consumer Service field. Tip: You copied both URLs from the previous step.
-
Click Save.
Step 4: Start a Tunnel
- Access the ngrok edges page, click your edge, and then click Start a tunnel.
For this step, we assume you have an app running locally (i.e. on localhost:3000) with the ngrok client installed.
-
Click the copy icon next to the tunnel command.
-
Launch a tunnel:
- Launch a terminal.
- Paste the command but replace
http://localhost:80
with your localhost app address (i.e.,http://localhost:3000
). - Click Enter and an ngrok tunnel associated with your edge configuration will launch.
-
To confirm that the tunnel is connected to your edge:
- Return to the ngrok dashboard
- Close the Start a tunnel and the Tunnel group tabs
- Refresh the test edge page. Under traffic, You will see the message You have 1 tunnel online. Start additional tunnels to begin load balancing.
-
In the test edge, copy the endpoint URL. (You use this URL to test the Wallix Trustelem Authentication)
Grant access to Wallix Trustelem users
Wallix Trustelem allows their users to access SAML-integrated apps. To create a user follow the instructions below:
-
On the left menu the WALLIX Trustelem administration console, click Users and then click Create User.
-
Enter values for First Name, Last Name, and Primary Email fields, and then click Save.
Test the integration
-
In your browser, launch an incognito window.
-
Access your ngrok tunnel (i.e.,
https://trustelem-sso-test.ngrok.io
or using the copied endpoint URL). -
You should be prompted to log in with your Wallix Trustelem credentials.
-
After logging in, you should be able to see your web app.