Set up NetScaler SSO
Prerequisites for configuring NetScaler SSO
-
Configure a server and service for each web application server.
-
Configure a traffic management virtual server to handle traffic to and from your web application server.
To create a server and service by using the CLI
-
Configure the NetScaler server entity by specifying the FQDN of the web application server.
-
Configure the NetScaler server entity by specifying the IP address of the web application server, and assign the server entity the same name as the NetBios name of the web application server.
- add server name <serverFQDN>
- add service name serverName serviceType port
-
serverName. A name for the NetScaler appliance to use to refer to this server.
-
serverFQDN. The FQDN of the server. If the server has no domain assigned to it, use the server’s IP address and make sure that the server entity name matches the NetBios name of the web application server.
-
serviceName. A name for the NetScaler appliance to use to refer to this service.
-
type. The protocol used by the service, either HTTP or MSSQLSVC.
-
port. The port on which the service listens. HTTP services normally listen on port 80. Secure HTTPS services normally listen on port 443.
add server was1 was1.example.com
add service was1service was1 HTTP 80
add server WAS1 10.237.64.87
add service was1service WAS1 HTTP 80
To create a traffic management virtual server by using the CLI
add lb vserver <vserverName> <type> <IP> <port>
-
vserverName—A name for the NetScaler appliance to use to refer to this virtual server.
-
type—The protocol used by the service, either HTTP or MSSQLSVC.
-
IP—The IP address assigned to the virtual server. This would normally be an IANA-reserved, non-public IP address on your LAN.
-
port—The port on which the service listens. HTTP services normally listen on port 80. Secure HTTPS services normally listen on port 443.
add lb vserver tmvserver1 HTTP 10.217.28.20 80
bind lb vserver tmvserv1 wasservice1
To create an authentication virtual server by using the CLI
add authentication vserver <authvserverName> SSL <IP> 443
-
authvserverName —A name for the NetScaler appliance to use to refer to this authentication virtual server. Must begin with a letter, number, or the underscore character (\_), and must contain only letters, numbers, and the hyphen (-), period (.) pound (#), space ( ), at (@), equals (=), colon (:), and underscore characters. Can be changed after the authentication virtual server is added by using the rename authentication vserver command.
-
IP—The IP address assigned to the authentication virtual server. As with the traffic management virtual server, this address would normally be an IANA-reserved, non-public IP on your LAN.
-
domain—The domain assigned to the virtual server. This would usually be the domain of your network. It is customary, though not required, to enter the domain in all capitals when configuring the authentication virtual server.
add authentication vserver authvserver1 SSL 10.217.28.21 443
To configure a traffic management virtual server to use an authentication profile
- add authentication authnProfile <authnProfileName> {-authvserverName <string>} {-authenticationHost <string>} {-authenticationDomain <string>}
- set lb vserver \<vserverName\> -authnProfile <authnprofileName>
-
authnprofileName—A name for the authentication profile. Must begin with a letter, number, or the underscore character (\_), and must consist of from one to thirty-one alphanumeric or hyphen (-), period (.) pound (#), space ( ), at (@), equals (=), colon (:), and underscore characters.
-
authvserverName—The name of the authentication virtual server that this profile uses for authentication.
-
authenticationHost—Host name of the authentication virtual server.
-
authenticationDomain—Domain for which NetScaler SSO handles authentication. Required if the authentication virtual server performs authentication for more than one domain, so that the correct domain is included when the NetScaler appliance sets the traffic management virtual server cookie.
add authentication authnProfile authnProfile1 -authnvsName authvsesrver1
-authenticationHost authvsesrver1 -authenticationDomain example.com
set lb vserver vserver1 -authnProfile authnProfile1