External user authentication
ns.log file. The occurrence is because the system runs the systemuser_systemcmdpolicy_binding command to initialize the GUI for the user.
LDAP authentication (using external LDAP servers)
StartTLS is sent to the server over the connection. If the LDAP server supports StartTLS, the connection is converted to a secure LDAP connection by using TLS.
-
389 for unsecured LDAP connections
-
636 for secure LDAP connections
-
3268 for Microsoft unsecure LDAP connections
-
3269 for Microsoft secure LDAP connections
StartTLS command use port number 389. If port numbers 389 or 3268 are configured on the appliance, it tries to use StartTLS to make the connection. If any other port number is used, connection attempts use SSL/TLS. If StartTLS or SSL/TLS cannot be used, the connection fails.
| LDAP server | Base DN |
|---|---|
| Microsoft Active Directory | DC=Citrix, DC=local |
| Novell eDirectory | dc=Citrix, dc=net |
| IBM Directory Server | cn=users |
| Lotus Domino | OU=City, O=Citrix, C=US |
| Sun ONE directory (formerly iPlanet) | ou=People, dc=Citrix, dc=com |
| LDAP server | Bind DN |
|---|---|
| Microsoft Active Directory | CN=Administrator, CN=Users, DC=Citrix, DC=local |
| Novell eDirectory | cn=admin, dc=Citrix, dc=net |
| IBM Directory Server | LDAP_dn |
| Lotus Domino | CN=Notes Administrator, O=Citrix, C=US |
| Sun ONE directory (formerly iPlanet) | uid=admin, ou=Administrators, ou=TopologyManagement, o=NetscapeRoot |
Configure LDAP user authentication by using the CLI
Configure LDAP policy
add authentication ldapAction <name> {-serverIP <ip_addr|ipv6_addr|*> | {-serverName <string>}} >] [-authTimeout <positive_integer>] [-ldapBase <string>] [-ldapBindDn <string>] {-ldapBindDnPassword } [-ldapLoginName <string>] [-groupAttrName <string>] [-subAttributeName <string>]
add authentication ldapAction ldap_act -serverIP <IP> -authTimeout 30 -ldapBase "CN=xxxxx,DC=xxxx,DC=xxx" -ldapBindDn "CN=xxxxx,CN=xxxxx,DC=xxxx,DC=xxx" -ldapBindDnPassword abcd -ldapLoginName sAMAccountName -groupattrName memberOf -subAttributeName CN
add authentication Policy <name> <rule> [<reqAction>]
add authentication policy ldap_pol_advance -rule true -action ldap_act
add authentication ldapPolicy <name> <rule> [<reqAction>]
add authentication ldappolicy ldap_pol_classic ns_true ldap_act
bind system global <policyName> [-priority <positive_integer]
bind system global ldap_pol_advanced -priority 10
Configure LDAP user authentication by using the NetScaler GUI
-
Navigate to System > Authentication > Advanced Policies > Policy.
-
Click Add to create an authentication policy of type LDAP.
-
Click Create and Close.
Bind an authentication policy to the system global for LDAP authentication using the NetScaler GUI
-
Navigate to System > Authentication > Advanced Policies > Policy.
-
In the details pane, click Global Bindings to create system global authentication policy binding.
-
Click Global Bindings.
-
Select an authentication profile.
-
Select the LDAP policy.
-
In the System Global Authentication Policy Binding page, set the following parameters:
-
Select Policy.
-
Binding Details
Select LDAP policy -
-
Click Bind and Done.
-
Click Global Bindings to confirm that the policy bounded to the system global.
Determining attributes in the LDAP directory
<http://www.ldapbrowser.com>. After the browser is installed, set the following attributes:
-
The host name or IP address of your LDAP server.
-
The port of your LDAP server. The default is 389.
-
The base DN field can be left blank.
-
The information provided by the LDAP browser can help you determine the base DN needed for the Authentication tab.
-
The Anonymous Bind check determines whether the LDAP server requires user credentials for the browser to connect to it. If the LDAP server requires credentials, leave the checkbox cleared.
Key-based authentication support for LDAP users
-
Can store the retrieved public key, and the LDAP action uses this attribute to retrieve SSH key information from the LDAP server.
-
Can extract attribute names of up to 24 KB.
-
SSH daemon sends an AAA\_AUTHENTICATE request with password field empty to authentication, authorization, and auditing daemon port.
-
If LDAP is configured to store the SSH public key, authentication, authorization, and auditing responds with the
sshPublicKeyattribute along with other attributes. -
The SSH daemon verifies these keys with the client keys.
-
SSH daemon passes the user name in the request payload, and authentication, authorization, and auditing returns the keys specific to this user along with generic keys.
-
With add operation, you can add “sshPublicKey” attribute while configuring the
ldapActioncommand.add authentication ldapAction <name> {-serverIP <ip_addr|ipv6_addr|*> | {-serverName <string>}} [-serverPort <port>] … [-Attribute1 <string>] … [-Attribute16 <string>][-sshPublicKey <string>][-authentication off] -
With set operation, you can configure the “sshPublicKey” attribute to an already added ldapAction command.
set authentication ldapAction <name> [-sshPublicKey <string>][-authentication off]
RADIUS authentication (using external RADIUS servers)
-
If you enable use of the NAS IP, the appliance sends its configured IP address to the RADIUS server, rather than the source IP address used in establishing the RADIUS connection.
-
If you configure the NAS ID, the appliance sends the identifier to the RADIUS server. If you do not configure the NAS ID, the appliance sends its host name to the RADIUS server.
-
When the NAS IP address is enabled, the appliance ignores any NAS ID that it used for communicating with the RADIUS server.
Configure RADIUS user authentication by using the CLI
add authentication radiusaction <name> -serverip <ip> -radkey <key> -radVendorID <id> -radattributetype <value>
radVendorID RADIUS vendor ID attribute, used for RADIUS group extraction. radAttributeType RADIUS attribute type, used for RADIUS group extraction.
add authentication radiusaction RADserver531 rad_action -serverip 1.1.1.1 -radkey key123 -radVendorID 66 -radattributetype 6
add authentication policy <policyname> -rule true -action <radius action name>
add authentication policy rad_pol_advanced -rule true -action radserver531rad_action
add authentication radiusPolicy <name> <rule> [<reqAction>]
add authentication radiuspolicy radius_pol_classic ns_true radius_act
bind system global <policyName> -priority <positive_integer
bind system global radius_pol_advanced -priority 10
Configure RADIUS user authentication by using the GUI
-
Navigate to System > Authentication > Advanced Policies > Policy.
-
Click Add to create an authentication policy of type RADIUS.
-
Click Create and Close.
Bind the authentication policy to the system global for RADIUS authentication by using the GUI
-
Navigate to System > Authentication > Advanced Policies > Policy.
-
In the details pane, click Global Bindings to create system global authentication policy binding.
-
Click Global Bindings.Bind authentication policy to the system global for RADIUS
-
Select RADIUS.
-
In the System Global Authentication Policy Binding page, set the following parameters:
-
Select a policy.
-
Binding Details.
System Global Authentication Policy Binding -
-
Click Bind and Close.
-
Click Global Bindings to confirm that the policy is bound to the system global.RADIUS authentication policy global bindings
Choose RADIUS user authentication protocols
-
Password Authentication Protocol
-
Challenge-Handshake Authentication Protocol (CHAP)
-
Microsoft Challenge-Handshake Authentication Protocol (MS-CHAP Version 1 and Version 2)
Configure IP address extraction
-
Allows a remote RADIUS server to supply an IP address from the internal network for a user logged on to the appliance.
-
Allows configuration for any RADIUS attribute using the type ip-address, including that are vendor encoded.
Group extraction for RADIUS by using the GUI
-
Navigate to System > Authentication > Advanced Policies > Radius, and select a policy.
-
Select or create a RADIUS policy.
-
In the Configure Authentication RADIUS Server page, set the following parameters.
-
Group Vendor Identifier
-
Group Attribute Type
-
-
Click OK and Close.
TACACS+ authentication (using external TACACS+ servers)
-
Citrix recommends that you do not modify any TACACS-related configurations when you run a “clear ns config” command.
-
TACACS related configuration related to advanced policies is cleared and reapplied when the
RBAconfigparameter is set to NO in “clear ns config” command for advanced policy. -
When the
RBAconfigparameter is set to NO as part of the "clear config" operation, NetScaler retains the management access sessions, in addition to retaining the RBA configurations and TACACS policies.
Configure TACACS+ authentication by using the GUI
-
Navigate to System > Authentication > Advanced Policies > Policy.
-
Click Add to create an authentication policy of type TACACS.
-
Click Create and Close.
Bind authentication policies to the system global entity by using the CLI
bind system global <policyName> [-priority <positive_integer>]
bind system global pol_classic -priority 10
Bind authentication policies to the system global entity by using the GUI
-
Navigate to System > Authentication > Advanced Policies > Authentication Policies > Policy.
-
In the details pane, click Global Bindings to create system global authentication policy binding.
-
Click Global Bindings.Bind authentication policy to the system global for TACACS authentication
-
Select the TACACS policy.
-
In the System Global Authentication Policy Binding page, set the following parameters:
-
Select Policy.
-
Binding Details
System global for TACACS authentication -
-
Click Bind and Close.
-
Click Global Bindings to confirm the policy bounded to the system global.System global binding confirmation for TACACS
Display number of unsuccessful logon attempts for external users
set aaa parameter -maxloginAttempts <value> -failedLoginTimeout <value> -persistentLoginAttempts (ENABLED | DISABLED )]
set aaa parameter –maxloginAttempts 5 -failedLoginTimeout 4 –persistentLoginAttempts ENABLED
Following msg will be seen to external user when he tries 1 invalid login attempt before successfully login to the ADC management access.
Connection established.
To escape to local shell, press 'Ctrl+Alt+]'.
###############################################################################
# #
# WARNING: Access to this system is for authorized users only #
# Disconnect IMMEDIATELY if you are not an authorized user! #
# #
###############################################################################
WARNING! The remote SSH server rejected X11 forwarding request.
Last login: Mon Aug 24 17:09:00 2020 from 10.10.10.10
The number of unsuccessful login attempts since the last successful login : 1
Done
>
The number of unsuccessful login attempts since the last successful login : 1
Done
>