SSO for Basic, Digest, and NTLM authentication
-
Basic authentication
-
Digest Access authentication
-
NTLM without Negotiate NTLM2 Key or Negotiate Sign
Non-impacted SSO types
-
Kerberos authentication
-
SAML authentication
-
Form based authentication
-
OAuth bearer authentication
-
NTLM with Negotiate NTLM2 Key or Negotiate Sign
Impacted SSO configurations
Global configurations
set tmsessionparam -SSO ON
set vpnparameter -SSO ON
add tmsessionaction tm_act -SSO ON
add vpn sessionaction tm_act -SSO ON
Per traffic configurations
add vpn trafficaction tf_act http -SSO ON
add tm trafficaction tf_act -SSO ON
Security measures to be applied
Traffic Action
add vpn trafficaction tf_act http -SSO ON
add tm trafficaction tf_act -SSO ON
Traffic Policy
add tm trafficpolicy <name> <rule> tf_act
add vpn trafficpolicy <name> <rule> tf-act
AAA-TM
set tmsessionparam -SSO ON
add tm trafficaction tf_act -SSO ON
add tm trafficpolicy tf_pol true tf_act
bind lb vserver <LB VS Name> -policy tf_pol -priority 65345
add tmsessionaction tm_act -SSO ON
add tmsession policy <name> <rule> tm_act
add tm trafficaction tf_act -SSO ON
add tm trafficpolicy tf_pol <same rule as session Policy> tf_act
-
NetScaler AAA user/group for the preceding session policy must be replaced by traffic policy.
-
Bind the following policy to the load balancing virtual servers for the preceding session policy,
bind lb vserver [LB VS Name] -policy tf_pol -priority 65345
-
If a traffic policy with other priority is configured, the preceding command does not serve good.
add tm trafficaction tf_act1 <Addition config>
add tm trafficaction tf_act2 <Addition config>
add tm trafficaction tf_act3 <Addition config>
add tm trafficpolicy tf_pol1 <rule1> tf_act1
add tm trafficpolicy tf_pol2 <rule2> tf_act2
add tm trafficpolicy tf_pol3 <rule3> tf_act3
bind lb vserver <LB VS Name> -policy tf_pol1 -priority 100
bind lb vserver <LB VS Name> -policy tf_pol2 -priority 200
bind lb vserver <LB VS Name> -policy tf_pol3 -priority 300
add tm trafficaction tf_act_default -SSO ON
add tm trafficpolicy tf_pol_default true tf_act_default
bind lb vserver <LB VS Name> -policy tf_pol_default -priority 65345
add tm trafficaction tf_act1 <Addition config> -SSO ON
add tm trafficaction tf_act3 <Addition config> -SSO ON
NetScaler Gateway cases
set vpnparameter -SSO ON
add vpn trafficaction vpn_tf_act http -SSO ON
add vpn trafficpolicy vpn_tf_pol true vpn_tf_act
bind the following traffic policy to all VPN virtual server where SSO is expected:
bind vpn vserver vpn_vs -policy vpn_tf_pol -priority 65345
add vpn sessionaction vpn_sess_act -SSO ON
add vpnsession policy <name> <rule> vpn_sess_act
-
NetScaler AAA user/group for the preceding session policy must be replaced by traffic policy.
-
Bind the following policy to the LB virtual servers for the preceding session policy,
bind lb virtual server [LB VS Name] -policy tf_pol -priority 65345. -
If a traffic policy with other priority is configured, the preceding command does not serve good. The following section deals with scenarios based on conflict with multiple traffic policies associated with traffic.
add vpn trafficaction tf_act1 <Addition config>
add vpn trafficaction tf_act2 <Addition config>
add vpn trafficaction tf_act3 <Addition config>
add vpn trafficpolicy tf_pol1 <rule1> tf_act1
add vpn trafficpolicy tf_pol2 <rule2> tf_act2
add vpn trafficpolicy tf_pol3 <rule3> tf_act3
bind vpn vserver <VPN VS Name> -policy tf_pol1 -priority 100
bind vpn vserver <VPN VS Name> -policy tf_pol2 -priority 200
bind vpn vserver <VPN VS Name> -policy tf_pol3 -priority 300
add vpn trafficaction tf_act_default -SSO ON
add vpn trafficpolicy tf_pol_default true tf_act_default
bind vpn vserver <VPN VS Name> -policy tf_pol_default -priority 65345
add vpn trafficaction tf_act1 [Additional config] -SSO ON
add vpn trafficaction tf_act3 [Additional config] -SSO ON