Configure domain drop-down, username, and password field in the first factor and policy evaluation based on groups in the next factor
-
User logs in to Citrix Workspace and gets redirected to authentication virtual server.
-
NetScaler presents a logon form with a domain drop-down list, username, and password field.Domain nFactor
-
User selects a value from the domain drop-down list and enters credentials.
-
NetScaler presents a logon form based on the user input.
Configure domain drop-down, username, and password field in the first factor and policy evaluation based on groups in the next factor using nFactor visualizer
-
Navigate to Security > AAA-Application Traffic > nFactor Visualizer > nFactor Flow and click Add.
-
Click the plus icon to add a factor in the nFactor Flow.Domain drop2
-
Enter a name for the Factor.Domain drop3
-
Add the schema for the First Factor by clicking on Add Schema.Domain drop4
-
Create a EULA_Schema by selecting the DomainDropdown.xml login schema.Domain drop5
-
Choose the schema for the first factor created in step 5.Domain drop6
-
Click Add Policy and choose the LDAP Policy for first authentication.Domain drop7
-
Click the plus icon to create a decision block.Domain drop8For more information on creating LDAP Authentication see, Configuring LDAP Authentication
-
Select Create decision block and enter a name in Decision Factor Name field.Domain 9
-
Click Add Policy to create a policy for the domain check.Domain 10
-
To create a policy to check for domain, select NO_AUTHN under Action Type.Domain 11
-
Choose the previously created policy to add in decision block.Domain 12
-
Click the plus icon below the newly created policy to add another policy for checking
AAATM.COM.Domain 13 -
Create another policy to check for the second domain.Domain 14
-
Choose the policy created in the previous step to add in decision block.Domain 15
-
Select the + sign next to
AAATM.COMto add factor that is evaluated if user is a part ofAAATM.COM. In this case, add an LDAP Policy.Domain 16 -
Choose a schema for domain
AAATM.COMusers. In this example, password only schema is used that gives user a text field to enter the Password.Domain 17 -
Follow step 7 add the policy for authenticating users of
AAATM.COMdomain -
Select the + sign next to
NSI-TEST.COMto add factor that will be evaluated if user is a part ofNSI-TEST.COM. In this example RADIUS authentication menthod is used.Domain 19 -
Follow step 17 to add a schema password only and then add the policy for RADIUS as shown in step 7.
-
Click Done. The configuration is saved automatically.
-
Select the nFactor Flow just created and bind it to a AAA Virtual Server by clicking Bind to Authentication Server and clicking CreateDomain 22
-
Select the nFactor Flow and click Show Bindings.
-
Select the Authentication VServer and click Unbind.
Configure domain drop-down, username, and password field in the first factor and policy evaluation based on groups in the next factor using CLI
add lb vserver lbn HTTP 10.217.28.166 80 -persistenceType NONE -cltTimeout 180 -AuthenticationHost auth.nsi-test.com -Authentication ON -authnVsName avn
add authentication vserver avn SSL 10.217.28.167 443 -AuthenticationDomain nsi-test.com
add authentication login Schema nfactor-domain -authenticationSchema domain-dropdown.xml
add authentication policylabel nfactor-domain-pol -loginSchema nfactor-domain
add authentication Policy radius-auth -rule "HTTP.REQ.BODY(500).AFTER_STR(\"domain=\").CONTAINS(\"NSI-TEST.COM\")" -action <RADIUS-ACTION>
add authentication Policy next_ldap -rule "HTTP.REQ.BODY(500).AFTER_STR(\"domain=\").CONTAINS(\"AAATM.COM\")" -action <LDAP-ACTION>
bind authentication vserver avn -policy radius-auth -priority 10 -gotoPriorityExpression NEXT
bind authentication vserver avn -policy next_ldap -priority 20 -gotoPriorityExpression END