12.2 Configuring Integration with Citrix NetScaler

These instructions will help you to configure integration of Advanced Authentication Appliance Edition with the Citrix NetScaler VPX to refuse non-secure passwords.

The advanced authentication in Citrix NetScaler is represented on the following diagram.

To get started, ensure that you have:

  • Citrix NetScaler VPX (version NS11.0 was used to prepare these instructions)

  • Advanced Authentication v5 appliance

Configure the Advanced Authentication RADIUS server:

  1. Open the Advanced Authentication Admin Interface.

  2. Go to the Events section.

  3. Open properties of the Radius Server event.

  4. Set the Radius Server event to the ON mode.

  5. Select one or more chains from the list of Used chains (make sure that they are enabled and set to the users group in the Chains section).

  6. Add a Client, enter an IP address of the Citrix NetScaler VPX, specify a secret, confirm it and set the Enabled option.

  7. Click the Save button in the Client string. Click the Save button at the bottom of the Events view to save changes.

Configure the Citrix NetScaler appliance:

  1. Sign-in to the Citrix NetScaler configuration portal as nsroot.

  2. Browse menu Configuration -> Authentication -> Dashboard.

  3. Click Add.

  4. Select RADIUS from the Choose Server Type dropdown menu.

  5. Specify the Name of the Advanced Authentication server, its IP Address, Secret Key and Confirm Secret Key, change Time-out (seconds) to 120-180 seconds in case of usage of the Smartphone, SMS, Email or Voice methods.

  6. Click More and ensure that pap is selected in the Password Encoding dropdown menu.

  7. Click Create. If connection to the RADIUS server is valid, the Up status will be displayed.

  8. Browse menu Configuration -> System -> Authentication -> RADIUS -> Policy.

  9. Click Add.

  10. Specify the Name of the Authentication RADIUS Policy, select the created RADIUS server from the Server dropdown menu, select ns_true from the Saved Policy Expressions list.

  11. Click Create.

  12. Select the created policy and click Global Bindings.

  13. Click the Select Policy field.

  14. Select the created policy.

  15. Click Bind.

  16. Click Done. The check mark will be displayed in the Globally Bound column.

How to authenticate in Citrix NetScaler using the Advanced Authentication:

  1. Enter user’s credentials and click Login.

  2. Accept authentication on your smartphone.

NOTE:Advanced authentication can be configured with other authentication chains.