外部ユーザー認証
ns.log ファイルに「ユーザーが存在しません」というエラーメッセージを生成します。これは、システムが systemuser_systemcmdpolicy_binding コマンドを実行してユーザーの GUI を初期化するためです。
LDAP 認証 (外部 LDAP サーバーを使用)
-
セキュリティで保護されていない LDAP 接続の場合は 389
-
636 セキュアな LDAP 接続の場合
-
Microsoftのセキュアでない LDAP 接続の場合は 3268
-
MicrosoftのセキュアLDAP接続の場合は 3269
| LDAP サーバ | ベース DN |
|---|---|
| Microsoft Active Directory | DC=Citrix、DC=ローカル |
| Novell eDirectory | DC=Citrix、dc=net |
| IBM Directory Server | cn=users |
| Lotus Domino | OU=都市、O=Citrix、C=米国 |
| Sun ONE ディレクトリ (旧iPlanet) | ou=人、DC=Citrix、dc=com |
| LDAP サーバ | バインド DN |
|---|---|
| Microsoft Active Directory | CN=管理者、CN=ユーザー、DC=Citrix、DC=ローカル |
| Novell eDirectory | cn=管理者、DC=Citrix、dc=net |
| IBM Directory Server | LDAP_dn |
| Lotus Domino | cn=Notes 管理者、O=Citrix、C=米国 |
| Sun ONE ディレクトリ (旧iPlanet) | uid=admin、OU=管理者、OU=トポロジ管理、o=NetscapeRoot |
CLI を使用して LDAP ユーザー認証を構成する
LDAP ポリシーを構成する
add authentication ldapAction <name> {-serverIP <ip_addr|ipv6_addr|*> | {-serverName <string>}} >] [-authTimeout <positive_integer>] [-ldapBase <string>] [-ldapBindDn <string>] {-ldapBindDnPassword } [-ldapLoginName <string>] [-groupAttrName <string>] [-subAttributeName <string>]
add authentication ldapAction ldap_act -serverIP <IP> -authTimeout 30 -ldapBase "CN=xxxxx,DC=xxxx,DC=xxx" -ldapBindDn "CN=xxxxx,CN=xxxxx,DC=xxxx,DC=xxx" -ldapBindDnPassword abcd -ldapLoginName sAMAccountName -groupattrName memberOf -subAttributeName CN
add authentication ldapPolicy <name> <rule> [<reqAction>]
add authentication ldappolicy ldap_pol_classic ns_true ldap_act
add authentication Policy <name> <rule> [<reqAction>]
add authentication policy ldap_pol_advance -rule true -action ldap_act
bind system global <policyName> [-priority <positive_integer]
bind system global ldap_pol_advanced -priority 10
NetScaler GUIを使用してLDAPユーザー認証を構成する
NetScaler GUIを使用してLDAP認証用の認証ポリシーをシステムグローバルにバインドします
LDAP ディレクトリの属性を決定する
<http://www.ldapbrowser.com>からダウンロードできます。ブラウザをインストールしたら、次の属性を設定します。
-
LDAP サーバーのホスト名または IP アドレス。
-
LDAP サーバーのポート。デフォルトは 389 です。
-
ベース DN フィールドは空白のままにすることができます。
-
Anonymous Bind チェックは、LDAP サーバがブラウザに接続するためにユーザクレデンシャルを必要とするかどうかを判断します。LDAP サーバがクレデンシャルを必要とする場合は、チェックボックスをオフのままにします。
LDAP ユーザーに対するキーベース認証のサポート
-
取得した公開キーを格納でき、LDAP アクションはこの属性を使用して LDAP サーバーから SSH キー情報を取得します。
-
最大 24 KB の属性名を抽出できます。
-
SSH デーモンは、パスワードフィールドを空にして AAA_AUTHENTICATE 要求を認証、承認、および監査デーモンポートに送信します。
-
LDAP が SSH 公開鍵を格納するように設定されている場合、認証、承認、および監査は、他の属性とともに
sshPublicKey属性を使って応答します。 -
SSH デーモンは、これらのキーをクライアントキーで検証します。
-
SSH デーモンはリクエストペイロードでユーザー名を渡し、認証、承認、および監査は、このユーザーに固有のキーと汎用キーを返します。
-
追加操作では、
ldapActionコマンドの設定中に「sshPublicKey」属性を追加できます。add authentication ldapAction <name> {-serverIP <ip_addr|ipv6_addr|*> | {-serverName <string>}} [-serverPort <port>] … [-Attribute1 <string>] … [-Attribute16 <string>][-sshPublicKey <string>][-authentication off] -
設定操作では、すでに追加されている ldapAction コマンドに「sshPublicKey」属性を設定できます。
set authentication ldapAction <name> [-sshPublicKey <string>][-authentication off]
RADIUS認証(外部RADIUSサーバーを使用)
-
NAS IPの使用を有効にすると、アプライアンスは、RADIUS接続の確立に使用されるソースIPアドレスではなく、構成済みのIPアドレスをRADIUSサーバに送信します。
-
NAS IDを構成すると、アプライアンスはRADIUSサーバーにこの識別子を送信します。NAS IDを構成しないと、アプライアンスはRADIUSサーバーにホスト名を送信します。
-
NAS IPアドレスが有効になっている場合、アプライアンスはRADIUSサーバーとの通信に使用されたNAS IDを無視します。
CLI を使用して RADIUS ユーザー認証を構成する
add authentication radiusaction <name> -serverip <ip> -radkey <key> -radVendorID <id> -radattributetype <value>
radVendorID RADIUS ベンダー ID 属性は、RADIUS グループの抽出に使用されます。 radAttributeType RADIUS グループ抽出に使用される RADIUS 属性タイプ。
add authentication radiusaction RADserver531 rad_action -serverip 1.1.1.1 -radkey key123 -radVendorID 66 -radattributetype 6
add authentication radiusPolicy <name> <rule> [<reqAction>]
add authentication radiuspolicy radius_pol_classic ns_true radius_act
add authentication policy <policyname> -rule true -action <radius action name>
add authentication policy rad_pol_advanced -rule true -action radserver531rad_action
bind system global <policyName> -priority <positive_integer
bind system global radius_pol_advanced -priority 10
GUI を使用して RADIUS ユーザー認証を構成する
GUI を使用して、RADIUS 認証用に認証ポリシーをシステムグローバルにバインドします
RADIUSユーザー認証プロトコルを選択
-
パスワード認証プロトコル
-
チャレンジハンドシェイク認証プロトコル (CHAP)
-
Microsoftのチャレンジハンドシェイク認証プロトコル (MS-CHAP バージョン 1 およびバージョン 2)
IP アドレス抽出を構成する
-
リモートRADIUSサーバが、アプライアンスにログオンしたユーザーの内部ネットワークからのIPアドレスを提供できるようにします。
-
IP アドレスタイプを使用する任意の RADIUS属性の設定(ベンダーエンコードを含む)を許可します。
GUI を使用した RADIUS のグループ抽出
TACACS+ 認証(外部 TACACS+ サーバを使用)
-
「clear ns config」コマンドを実行するときは、TACACS関連の設定を変更しないことをお勧めします。
-
詳細ポリシーに関する TACACS 関連の設定は、詳細ポリシーの「clear ns config」 コマンドで
RBAconfigパラメータが NO に設定されると、クリアされ、再適用されます。 -
「構成のクリア」 操作の一部として
RBAconfigパラメータを「いいえ」に設定すると、NetScaler ADCはRBA構成とTACACSポリシーを保持するだけでなく、管理アクセスセッションも保持します。
GUIを使用してTACACS +認証を構成します
CLI を使用して認証ポリシーをシステムグローバルエンティティにバインドする
bind system global <policyName> [-priority <positive_integer>]
bind system global pol_classic -priority 10
GUIを使用して、RADIUS認証用に認証ポリシーをシステムグローバルにバインドします
-
システム > 認証 > 詳細ポリシー > 認証ポリシー > ポリシーに移動します。
-
「 グローバルバインディング」をクリックします。

-
TACACS ポリシーを選択します。
-
-
「ポリシー」を選択します 。
-
バインディングの詳細

-
-

外部ユーザーのログオン試行の失敗回数を表示する
set aaa parameter -maxloginAttempts <value> -failedLoginTimeout <value> -persistentLoginAttempts (ENABLED | DISABLED )]
set aaa parameter –maxloginAttempts 5 -failedLoginTimeout 4 –persistentLoginAttempts ENABLED
Following msg will be seen to external user when he tries 1 invalid login attempt before successfully login to the ADC management access.
Connection established.
To escape to local shell, press 'Ctrl+Alt+]'.
###############################################################################
# #
# WARNING: Access to this system is for authorized users only #
# Disconnect IMMEDIATELY if you are not an authorized user! #
# #
###############################################################################
WARNING! The remote SSH server rejected X11 forwarding request.
Last login: Mon Aug 24 17:09:00 2020 from 10.10.10.10
The number of unsuccessful login attempts since the last successful login : 1
Done
>
The number of unsuccessful login attempts since the last successful login : 1
Done
>





