Polling during authentication
Points to note
-
The Polling configuration is supported for LDAP, RADIUS, and TACACS authentication methods.
-
Client can probe authentication requests from second factor onwards.
Why configure Polling?
Understanding the Polling mechanism
-
An endpoint (App or Web browser) authenticates with credentials.
-
The user name and password is verified against an existing first factor directory (LDAP/Active Directory).
-
If the correct credentials are supplied, the authentication moves to the next factor.
-
At this point, the NetScaler appliance sends request to the RADIUS Push server.
-
While the NetScaler appliance waits for a response from the RADIUS server, the endpoint drops TCP connection.
-
The NetScaler receives a response from the RADIUS Push server.
-
As no client TCP connection is found, the NetScaler appliance drops session and the login fails.
-
An endpoint (App or Web browser) authenticates with credentials.
-
The user name and password is verified against an existing first factor directory (LDAP/Active Directory).
-
If the correct credentials are supplied, the authentication moves to the next factor.
-
At this point, the NetScaler appliance sends request to the RADIUS Push server.
-
While the NetScaler appliance waits for a response from the RADIUS server, the endpoint drops TCP connection.
-
Endpoint sends a poll (probe) to the NetScaler appliance to check for the authentication status.
-
As the NetScaler appliance does not hear back from the RADIUS server, it requests the endpoint to continue polling.
-
The NetScaler appliance receives response from the RADIUS Push server.
-
As no client TCP connection is found, ADC saves the session state.
-
Endpoint again polls to check for the authentication status.
-
NetScaler appliance establishes the session and the login succeeds.
Configure Polling using CLI
Configure First factor
add authentication ldapAction ldap-new -serverIP 10.106.40.65 -serverPort 636 -ldapBase "dc=aaatm-test,dc=com" -ldapBindDn administrator@aaatm-test.com -ldapBindDnPassword 2f63d3659103464a4fad0ade65e2ccfd4e8440e36ddff941d29796af03e01139 -encrypted -encryptmethod ENCMTHD_3 -ldapLoginName sAMAccountName -groupAttrName memberof -subAttributeName CN -secType SSL -alternateEmailAttr userParameters
add authentication Policy ldap-new -rule true -action ldap-new
bind authentication vserver avs -policy ldap-new -priority 1 -nextFactor rad_factor
Configure Second factor
add authentication radiusAction rad1 -serverIP 10.102.229.120 -radKey 1b1613760143ce2371961e9a9eb5392c86a4954a62397f29a01b5d12b42ce232 -encrypted -encryptmethod ENCMTHD_3
add authentication Policy rad -rule true -action rad1
Configure Poll.xml login schema
add authentication loginSchema polling_schema -authenticationSchema LoginSchema/Poll.xml
add authentication policylabel rad_factor -loginSchema polling_schema
bind authentication policylabel rad_factor -policyName rad -priority 1 -gotoPriorityExpression NEXT
Configure Polling using GUI
-
Create a first factor for authentication, for example LDAP.
-
Create a second factor for authentication, for example RADIUS.
-
Add Poll.xml present in NetScaler (/nsconfig/loginschema/LoginSchema/) as login schema for the second factor.