NetScaler as an Active Directory Federation Services proxy
-
Secure connectivity.
-
Authentication and handling of federated identity.
Advantages of ADFS proxy
-
Reduces the footprint in DMZ to cater the need for most of the enterprises.
-
Provides an SSO experience for end users.
-
Supports rich methods for pre-authentication and enables multifactor authentication.
-
Supports both active and passive clients.
Prerequisites for using NetScaler as ADFS proxy
-
A NetScaler appliance with 12.1 build or later.
-
Domain ADFS server.
-
Domain SSL certificate.
-
Virtual IP for Content Switching virtual server.
-
Enable Load Balancing, SSL Offload, Content Switching, Rewrite, and authentication, authorization, and auditing traffic management features on NetScaler appliance.
Configure NetScaler appliance as ADFS proxy
-
A client request to access Microsoft Office365 gets redirected to NetScaler deployed as ADFS proxy.
-
User’s credentials are passed to the ADFS server.
-
ADFS server authenticates the credentials with on-premises AD of the domain.
-
ADFS server upon successful validation of credentials with AD, generates a token which is passed to Microsoft Office365 for session establishment.
-
Create an SSL profile for the back-end and enable SNI in the SSL profile. Disable SSLv3/TLS1.
add ssl profile <new SSL profile> -sslprofileType backEnd -sniEnable ENABLED -ssl3 DISABLED -tls1 DISABLED -commonName <FQDN of ADFS> -
Disable SSLv3/TLS1 for the service.
set ssl service <adfs service name> -sslProfile <SSL profile created in the above step> -
Enable SNI extension for back-end server handshakes.
-
set vpn parameter –backendServerSni ENABLED -
set ssl parameter -denySSLReneg NONSECURE
-
Configure NetScaler appliance as ADFS proxy using the CLI
To configure ADFS service
-
Configure ADFS service on NetScaler for ADFS server.
add service <Domain_ADFS_Service> <ADFS Server IP> SSL 443 -gslb NONE -maxClient 0 -maxReq 0 -cip DISABLED -usip NO -useproxyport YES -sp OFF -cltTimeout 180 -svrTimeout 360 -CKA NO -TCPB NO -CMP NOExampleadd service CTXTEST_ADFS_Service 1.1.1.1 SSL 443 -gslb NONE -maxClient 0 -maxReq 0 -cip DISABLED -usip NO -useproxyport YES -sp OFF -cltTimeout 180 -svrTimeout 360 -CKA NO -TCPB NO -CMP NO -
Configure FQDN for content switching virtual server and enable SNI.
set ssl service <Domain_ADFS_Service> -SNIEnable ENABLED -commonName <sts.domain.com>Exampleset ssl service CTXTEST_ADFS_Service -SNIEnable ENABLED -commonName sts.ctxtest.com
To configure ADFS load balancing virtual server
-
Configure ADFS load balancing virtual server.
add lb vserver <Domain_ADFS_LBVS> SSL <IP_address> -persistenceType NONE -cltTimeout 180Exampleadd lb vserver CTXTEST_ADFS_LBVS SSL 192.168.1.0 -persistenceType NONE -cltTimeout 180 -
Bind ADFS load balancing virtual server to ADFS service.
bind lb vserver <Domain_ADFS_LBVS> <Domain_ADFS_Service>Examplebind lb vserver CTXTEST_ADFS_LBVS CTXTEST_ADFS_Service -
Bind an SSL virtual server certificate-key pair.
bind ssl vserver <Domain_ADFS_LBVS> -certkeyName <SSL_CERT>Examplebind ssl vserver CTXTEST_ADFS_LBVS -certkeyName ctxtest_newcert_2019
To configure content switching virtual server for domain
-
Create a content switching virtual server with free VIP.
add cs vserver <Domain_CSVS> SSL <FREE VIP> 443 -cltTimeout 180 -persistenceType NONEExampleadd cs vserver CTXTEST_CSVS SSL 2.2.2.2 443 -cltTimeout 180 -persistenceType NONE -
Bind content switching virtual server to load balancing virtual server.
bind cs vserver <Domain_CSVS> -lbvserver <Domain_ADFS_LBVS>Example-
bind cs vserver CTXTEST_CSVS -lbvserver CTXTEST_ADFS_LBVS -
set ssl vserver CTXTEST_CSVS -sessReuse DISABLED
-
-
Bind an SSL virtual server certificate-key pair.
bind ssl vserver <Domain_CSVS> -certkeyName <SSL_CERT>Examplebind ssl vserver CTXTEST_CSVS -certkeyName ctxtest_newcert_2019
Supported protocols
-
WS-Federation. For details, see Web Services Federation protocol.
-
ADFSPIP. For details, see Active Directory Federation Service Proxy Integration Protocol compliance.