Users can be authenticated either internally by NetScaler® ADM, externally by an authenticating server, or both. If local authentication is used, the user must be in the NetScaler ADM security database. If the user is authenticated externally, the user “external name” must match the external user identity registered with the authenticating server, depending on the selected authentication protocol.
NetScaler ADM supports external authentication by RADIUS, LDAP, and TACACS servers. This unified support provides a common interface to authenticate and authorize all the local and external Authentication, Authorization, and Accounting server users who are accessing the system. NetScaler ADM can authenticate users regardless of the actual protocols they use to communicate with the system. When a user attempts to access a NetScaler ADM implementation that is configured for external authentication, the requested application server sends the user name and password to the RADIUS, LDAP, or TACACS server for authentication. If the authentication is successful, the user is granted access to NetScaler ADM.