Authentication, authorization, and auditing provides security for a distributed internet environment by allowing any client with the proper credentials to connect securely to protected application servers from anywhere on the Internet. This feature incorporates the three security features of authentication, authorization, and auditing. Authentication enables the NetScaler to verify the client's credentials, either locally or with a third-party authentication server, and allow only approved users to access protected servers. Authorization enables the ADC to verify which content on a protected server it allows each user to access. Auditing enables the ADC to keep a record of each user's activity on a protected server.
To understand how authentication, authorization, and auditing works in a distributed environment, consider an organization with an intranet that its employees access in the office, at home, and when traveling. The content on the intranet is confidential and requires secure access. Any user who wants to access the intranet must have a valid user name and password. To meet these requirements, the ADC does the following:
-
Redirects the user to the login page if the user accesses the intranet without having logged in.
-
-
Verifies that the user is authorized to access specific intranet content before delivering the user's request to the application server.
-
Maintains a session timeout after which users must authenticate again to regain access to the intranet. (You can configure the timeout.)
-
Logs the user accesses, including invalid login attempts, in an audit log.