Authentication policies
-
The virtual server is checked for any bound authentication policies.
-
If authentication policies are not bound to the virtual server, NetScaler checks for global authentication policies.
-
If an authentication policy is not bound to a virtual server or globally, the user is authenticated through the default authentication type.
On the GUI
Create or modify an advanced authentication policy
-
Navigate to Security > AAA - Application Traffic > Policies > Authentication > Advanced Policies > Policy.
-
On the Authentication Policies page, perform one of the following tasks:
-
To create an authentication policy, click Add. The Create Authentication Policy page appears.
-
Update the required fields and click Create.
-
To modify an authentication policy, select the action, and then click Edit. The Configure Authentication Policy page is displayed. Modify the required fields and click OK.
-
Name: Name of the advanced authentication policy.
-
Action Type: The type of the authentication action for which the policy is being created.
-
Action: Name of the authentication action (LDAP, RADIUS, SAML) to be performed if the policy matches. If there is no authentication action in the drop-down list, click Add.
-
Expression: Name of the NetScaler named rule or expression that the policy uses to determine whether to attempt to authenticate the user with the authentication virtual server. For more information about advanced policy expressions, see Advanced policy expressions.
-
-
Remove an authentication policy
-
Navigate to Security > AAA - Application Traffic > Policies > Authentication > Advanced Policies > Policy.
-
On the Authentication Policies page, select the policy that you want to remove and click Delete.
-
Click Yes to confirm your action.
Bind the authentication policy
-
Create an authentication virtual server.
-
Navigate to Security > AAA - Application Traffic > Virtual Servers.
-
On the Authentication Virtual Servers page, and click Add. Update the required fields and click OK.
-
If an authentication virtual server exists, select the relevant server on the Authentication Virtual Servers page.
-
In the Advanced Authentication Policies section, select the authentication policy.
-
On the Policy Binding page, select the policy and click Add. Provide the binding details such as the priority, GoTo expression, and the next factor, and then click Bind.
-
-
Create a VPN virtual server.
-
Navigate to NetScaler Gateway > Virtual servers.
-
On the NetScaler Gateway Virtual Servers page, click Add.
-
On the VPN Virtual Server page, update the required fields and click OK.
Create VPN virtual server -
-
Create an authentication profile.
-
Navigate to Security > AAA - Application Traffic > Authentication Profile.
-
On the Authentication Profile page, click Add.
-
Update the required fields and click Create.
Create authentication profile -
-
Link the authentication virtual server to the VPN virtual server by using the authentication profile.
-
Navigate to NetScaler Gateway > NetScaler Gateway Virtual Servers and select the VPN virtual server. The VPN Virtual Server page appears.
-
In the Authentication profile section, select the authentication profile from the drop-down list and click OK.
-
Alternatively, you can navigate to the Advanced settings section on the VPN Virtual server page, click + Authentication Profile, select the authentication profile from the drop-down list, and click OK.
-
Click Done.
Link authentication virtual server and VPN virtual server -
On the CLI
add authentication policy <name> -rule <expression> -action <string>
show authentication policy <name>
bind authentication vserver <name> -policy <policyname> [-priority <priority>][-secondary]
show authentication vserver <name>
add authentication policy Authn-Pol-1 true
show authentication policy Authn-Pol-1
Name: Authn-Pol-1 Rule: true Request action: LOCAL
bind authentication vserver Auth-Vserver-2 -policy Authn-Pol-1
show authentication vserver Auth-Vserver-2
Auth-Vserver-2 (10.102.29.77:443) - SSL Type: CONTENT State: UP Client Idle
Timeout: 180 sec Down state flush: DISABLED
Disable Primary Vserver On Down : DISABLED
Authentication : ON
Current AAA Users: 0
Authentication Domain: myCompany.employee.com
Primary authentication policy name: Authn-Pol-1 Priority: 0
Modify an authentication policy
set authentication policy <name> [-rule <expression>] [-action <string>] [-undefAction <string>] [-comment <string>] [-logAction <string>]
set authentication policy Authn-Pol-1 -rule true
Remove an authentication policy
rm authentication policy <name>
rm authentication localPolicy Authn-Pol-1
Bind the authentication policy
add authentication authnProfile <name> {-authnVsName <string>} {-AuthenticationHost <string>}{-AuthenticationDomain <string>}[-AuthenticationLevel <positive_integer>]
add authentication authnProfile Authn-Prof-1 -authnVsName Auth-Vserver-2 -AuthenticationDomain "myCompany.employee.com"
add vpn vserver VPN-Vserver-2 ssl -authentication ON -authnprofile Authn-Prof-1
Add an authentication action
add authentication tacacsAction <name> -serverip <IP> [-serverPort <port>][-authTimeout <positive_integer>][ ... ]
add authentication tacacsaction Authn-Act-1 -serverip 10.218.24.65 -serverport 1812 -authtimeout 15 -tacacsSecret "minotaur" -authorization OFF -accounting ON -auditFailedCmds OFF -defaultAuthenticationGroup "users"
Configure an authentication action
set authentication tacacsAction <name> -serverip <IP> [-serverPort <port>][-authTimeout <positive_integer>][ ... ]
set authentication tacacsaction Authn-Act-1 -serverip 10.218.24.65 -serverport 1812 -authtimeout 15 -tacacsSecret "minotaur" -authorization OFF -accounting ON -auditFailedCmds OFF -defaultAuthenticationGroup "users"
Remove an authentication action
rm authentication radiusAction <name>
rm authentication tacacsaction Authn-Act-1
The noAuth authentication
noAuthAction command, when a user performs this policy. The administrator can check for the presence of this group in the user's group to determine the user's navigation through the noAuth policy.
To configure a noAuth authentication
add authentication noAuthAction <name> [-defaultAuthenticationGroup <string>]
add authentication noAuthAction noauthact –defaultAuthenticationGroup mynoauthgroup
Default global authentication types
-
You cannot use the NetScaler Gateway wizard to configure SAML authentication.
-
You can use the Quick Configuration wizard to configure LDAP, RADIUS, and client certificate authentication. When you run the wizard, you can select from an existing LDAP or RADIUS server configured on NetScaler Gateway. You can also configure the settings for LDAP or RADIUS. If you use two-factor authentication, it is recommended that you use LDAP as the primary authentication type.
Configure default global authentication types
-
In the GUI, on the Configuration tab, in the navigation pane, expand NetScaler Gateway, and then click Global Settings.
-
In the details pane, under Settings, click Change authentication settings.
-
In Maximum Number of Users, type the number of users who can be authenticated by using this authentication type.
-
In NAT IP address, type the unique IP address for authentication.
-
Select Enable static caching to deliver logon pages faster.
-
Select Enable Enhanced Authentication Feedback to provide a message to users if authentication fails. The message users receive include the password errors, the account disabled or locked, or the user is not found, to name a few.
-
In Default Authentication Type, select the authentication type.
-
Configure the settings for your authentication type, and then click OK.
Support to retrieve current login attempts for a user
aaa.user.login_attempts. This expression takes either one argument (user name) or no argument. If there is no argument, the expression fetches the user name from the aaa_session or aaa_info.
aaa.user.login_attempts expression with authentication policies for further processing.
To configure the number of login attempts per user
add expression er aaa.user.login_attempts
aaa.user.login_attempts expression does not work if the Persistent Login Attempts parameter is enabled. For details about the Persistent Login Attempts parameter, see System user account lockout.
-
Authentication virtual server
set authentication vserver av_vs -maxLoginAttempts 5 -failedLoginTimeout 100For details about the authentication virtual server and its supported parameters, see Authentication virtual server. -
NetScaler Gateway virtual server
set vpn vserver vpn_vs -maxLoginAttempts 5 -failedLoginTimeout 100For details about a NetScaler Gateway virtual server, see the Virtual servers section. -
Lock out a system user account
set aaa parameter -maxloginAttempts 3 -failedLoginTimeout 10For details about the system user account lockout, see Lock system user account for management access.Parameter descriptions:-
maxLoginAttempts: Maximum number of login attempts allowed before a user is locked out. -
failedLoginTimeout: Number of seconds allowed before the login fails. The user must restart the login process.
-