SSO für Basic-, Digest- und NTLM-Authentifizierung
-
Grundlegende Authentifizierung
-
Digest Access-Authentifizierung
-
NTLM ohne Negotiate NTLM2-Schlüssel oder Negotiate-Zeichen
Nicht betroffene SSO-Typen
-
Kerberos-Authentifizierung
-
SAML-Authentifizierung
-
Formularbasierte Authentifizierung
-
OAuth-Trägerauthentifizierung
-
NTLM mit Negotiate NTLM2-Schlüssel oder Negotiate-Zeichen
Beeinträchtigte Single Sign-On-Konfigurationen
Globale Konfigurationen
set tmsessionparam -SSO ON
set vpnparameter -SSO ON
add tmsessionaction tm_act -SSO ON
add vpn sessionaction tm_act -SSO ON
Konfigurationen pro Datenverkehr
add vpn trafficaction tf_act http -SSO ON
add tm trafficaction tf_act -SSO ON
Anzuwendende Sicherheitsmaßnahmen
Traffic Action
add vpn trafficaction tf_act http -SSO ON
add tm trafficaction tf_act -SSO ON
Traffic Richtlinie
add tm trafficpolicy <name> <rule> tf_act
add vpn trafficpolicy <name> <rule> tf-act
AAA-TM
set tmsessionparam -SSO ON
add tm trafficaction tf_act -SSO ON
add tm trafficpolicy tf_pol true tf_act
bind lb vserver <LB VS Name> -policy tf_pol -priority 65345
add tmsessionaction tm_act -SSO ON
add tmsession policy <name> <rule> tm_act
add tm trafficaction tf_act -SSO ON
add tm trafficpolicy tf_pol <same rule as session Policy> tf_act
-
Der NetScaler AAA-Benutzer/die Gruppe für die vorherige Sitzungsrichtlinie muss durch eine Verkehrsrichtlinie ersetzt werden.
-
Binden Sie die folgende Richtlinie an die virtuellen Lastausgleichsserver für die vorherige Sitzungsrichtlinie:
bind lb vserver [LB VS Name] -policy tf_pol -priority 65345
-
Wenn eine Verkehrsrichtlinie mit einer anderen Priorität konfiguriert ist, ist der vorherige Befehl nicht hilfreich.
add tm trafficaction tf_act1 <Addition config>
add tm trafficaction tf_act2 <Addition config>
add tm trafficaction tf_act3 <Addition config>
add tm trafficpolicy tf_pol1 <rule1> tf_act1
add tm trafficpolicy tf_pol2 <rule2> tf_act2
add tm trafficpolicy tf_pol3 <rule3> tf_act3
bind lb vserver <LB VS Name> -policy tf_pol1 -priority 100
bind lb vserver <LB VS Name> -policy tf_pol2 -priority 200
bind lb vserver <LB VS Name> -policy tf_pol3 -priority 300
add tm trafficaction tf_act_default -SSO ON
add tm trafficpolicy tf_pol_default true tf_act_default
bind lb vserver <LB VS Name> -policy tf_pol_default -priority 65345
add tm trafficaction tf_act1 <Addition config> -SSO ON
add tm trafficaction tf_act3 <Addition config> -SSO ON
NetScaler Gateway -Fälle
set vpnparameter -SSO ON
add vpn trafficaction vpn_tf_act http -SSO ON
add vpn trafficpolicy vpn_tf_pol true vpn_tf_act
bind the following traffic policy to all VPN virtual server where SSO is expected:
bind vpn vserver vpn_vs -policy vpn_tf_pol -priority 65345
add vpn sessionaction vpn_sess_act -SSO ON
add vpnsession policy <name> <rule> vpn_sess_act
-
Der NetScaler AAA-Benutzer/die Gruppe für die vorherige Sitzungsrichtlinie muss durch eine Verkehrsrichtlinie ersetzt werden.
-
Binden Sie die folgende Richtlinie für die vorherige Sitzungsrichtlinie an die virtuellen LB-Server,
bind lb virtual server [LB VS Name] -policy tf_pol -priority 65345. -
Wenn eine Verkehrsrichtlinie mit einer anderen Priorität konfiguriert ist, ist der vorherige Befehl nicht hilfreich. Der folgende Abschnitt befasst sich mit Szenarien, die auf Konflikten mit mehreren Verkehrsrichtlinien im Zusammenhang mit dem Verkehr beruhen.
add vpn trafficaction tf_act1 <Addition config>
add vpn trafficaction tf_act2 <Addition config>
add vpn trafficaction tf_act3 <Addition config>
add vpn trafficpolicy tf_pol1 <rule1> tf_act1
add vpn trafficpolicy tf_pol2 <rule2> tf_act2
add vpn trafficpolicy tf_pol3 <rule3> tf_act3
bind vpn vserver <VPN VS Name> -policy tf_pol1 -priority 100
bind vpn vserver <VPN VS Name> -policy tf_pol2 -priority 200
bind vpn vserver <VPN VS Name> -policy tf_pol3 -priority 300
add vpn trafficaction tf_act_default -SSO ON
add vpn trafficpolicy tf_pol_default true tf_act_default
bind vpn vserver <VPN VS Name> -policy tf_pol_default -priority 65345
add vpn trafficaction tf_act1 [Additional config] -SSO ON
add vpn trafficaction tf_act3 [Additional config] -SSO ON