cancel
Showing results for 
Search instead for 
Did you mean: 

Pulse Secure + Mac OS X Sierra and SSO + Network Connect

wfmr452
New Contributor

Pulse Secure + Mac OS X Sierra and SSO + Network Connect

Using Pulse Secure 5.2.5 (869) + Mac OS X Sierra (10.12.2) using token based authentication is successful for me.
In our organization we are currently testing a solution that would replace the token based authentication with Single Sign On.
We have successfully tested the SSO configuration on Windows and mobile clients.

On Mac OS X we are facing the following issue:
1. Safari opens
2. The user is able to successfully login
3. Network Connect will start to launch
4. Network Connect will attempt to download the NetworkConnect.app
5. The installation will fail with the error message "An error occurred when attempting to extract one of the Network Connect components".

I am looking for advice on how to successfully configure Pulse Secure with SSO on a Mac such that a full tunnel can be established.

Thanks!
4 REPLIES 4
wfmr452
New Contributor

Re: Pulse Secure + Mac OS X Sierra and SSO + Network Connect

Addition:
I have already attempted following the steps as described in

https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB40225
zanyterp
Moderator

Re: Pulse Secure + Mac OS X Sierra and SSO + Network Connect

What do you mean by SSO?
There is no SSO into the Pulse appliance unless you are using a browser that already has a SAML or SiteMinder token
As you are aware, as well, Network Connect is not supported on Mac OS X starting with 10.9; the Pulse Secure client needs to be used for these endpoints
wfmr452
New Contributor

Re: Pulse Secure + Mac OS X Sierra and SSO + Network Connect

SSO = Single Sign On. I am aware that Network Connect is not supported on Mac.

We are using SSO to authenticate users. Pulse Secure will open Safari (regardless which browser is configured to be the default at OS level), log the user in and set a token. Instead of establishing a full tunnel at that time, the site will attempt to launch Network connect.
zanyterp
Moderator

Re: Pulse Secure + Mac OS X Sierra and SSO + Network Connect

From that description, it sounds like you are using SAML.
Does the police trace show, or list of roles assigned in the user access log, show the Pulse role as being the first in the list of assigned roles? If you are assigned a role that does not have Pulse enabled prior to the role with Pulse, Network Connect will be used.

What version of the appliance are you using; there were issues related to SAML & launching Pulse resolved in the latest 8.2 & 5.2 releases. Unfortunately, you seem to have found something we have not had reported yet. If you have not done so, please open a case with our support team so that we can investigate further on why Network Connect is being launched.

What you are seeing is expected (that Safari is the only supported browser for logging in from a macOS endpoint and the Pulse Secure client will force this when using SAML or other login technologies that need to be proxied through the browser)