Web認証
-
認証ルール— NetScalerアプライアンスの詳細ポリシーの式で、Webサーバーが想定する形式でユーザーの資格情報が含まれます。
-
スキーム:HTTP(暗号化されていない Web 認証の場合)または HTTPS(暗号化された Web 認証の場合)。
-
成功ルール— Webサーバーの応答文字列と一致するNetScalerアプライアンスの詳細ポリシーの式で、ユーザーが正常に認証されたことを示します。
コマンドラインインターフェイスを使用して Web 認証アクションを構成するには
add authentication webAuthAction <name> -serverIP <ip_addr|ipv6_addr|\*> -serverPort <port|\*> [-fullReqExpr <string>] -scheme ( http | https ) -successRule <expression> [-defaultAuthenticationGroup <string>][-Attribute1 <string>][-Attribute2 <string>] [-Attribute3 <string>][-Attribute4 <string>] [-Attribute5 <string>][-Attribute6 <string>] [-Attribute7 <string>][-Attribute8 <string>] [-Attribute9 <string>][-Attribute10 <string>] [-Attribute11 <string>][-Attribute12 <string>] [-Attribute13 <string>][-Attribute14 <string>] [-Attribute15 <string>][-Attribute16 <string>]
add policy expression post_data ""username=" + http.REQ.BODY(1000).SET_TEXT_MODE(IGNORECASE).AFTER_STR("login=").BEFORE_STR("&") + "&passwort=" + http.REQ.BODY(1000).SET_TEXT_MODE(IGNORECASE).AFTER_STR("passwd=")"
add policy expression length_post_data "("username= " + http.REQ.BODY(1000).SET_TEXT_MODE(IGNORECASE).AFTER_STR("login=").BEFORE_STR("&") + "passwort=" + http.REQ.BODY(1000).SET_TEXT_MODE(IGNORECASE).AFTER_STR("passwd=")).length"
add authentication webAuthAction webAuth_POST -serverIP 10.106.187.54 -serverPort 80 -fullReqExpr q{"POST /MyPHP/auth.php HTTP/" + http.req.version.major + "." + http.req.version.major + "\r\nAccept:\*/\*\r\nHost: 10.106.187.54\r\nReferer: http://10.106.187.54/MyPHP/auth.php\r\nAccept-Language: en-US\r\nUser-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)\r\nContent-Type: application/x-www-form-urlencoded\r\n" + "Content-Length: " + length_post_data + "\r\nConnection: Keep-Alive\r\n\r\n" + post_data} -scheme http -successRule "http.res.status.eq(200)"
構成ユーティリティを使用して Web 認証アクションを構成するには
-
セキュリティ > AAA アプリケーショントラフィック > ポリシー > LDAPにナビゲートして下さい。
-
-
「認証を検証する式」テキスト領域に、ユーザー認証が成功したことを示すWebサーバー応答の情報を説明するNetScalerアプライアンスの高度なポリシー式を入力します。
-
一般的な認証アクションのドキュメントの説明に従って、残りのフィールドに入力します。
-
[OK] をクリックします。