Restrict access to NetScaler Gateway for members of one Active Directory group
-
LDAP search filter: Restricts logon access to NetScaler Gateway only to the user names that match the LDAP search filter (for example, Active Directory group membership).
-
NetScaler Gateway session policy: Restricts logon access to NetScaler Gateway only to users from groups included in session policy or profile. This method supports multiple Active Directory groups.
LDAP search filter method
Overview
Prerequisites
Steps to configure an LDAP Search Filter for members of one Active Directory group
-
Determine the Active Directory Group that has access permission, and get its full Distinguished Name.An easy way to get the full Distinguished Name of the group is through Active Directory Users and Computers.
-
In Active Directory Users and Computers, from the View menu, enable Advanced Features.

-
Browse the tree to the group object, right-click, and then and click Properties. Note: You cannot use Find. Instead, you must navigate through the tree to find the object.

-
On the right, switch to the Attribute Editor tab.
This tab is only visible if Advanced Features is enabled, and if you have not used the Find feature. -
Scroll down to distinguishedName, double-click it, and then copy it to the clipboard.

-
In the NetScaler Gateway GUI, navigate to NetScaler Gateway > Virtual Servers.
-
Select an existing NetScaler Gateway virtual server and click Edit.
-
In the Basic Authentication section, click LDAP Policies.
-
Right-click an existing LDAP policy, and click Edit Server.

-
In the Other Settings section, in the Search Filter field, type in memberOf= and then paste the Distinguished Name of the Active Directory group after the equals sign (=).
An example Search Filter is the following: memberOf=CN=Citrix® Remote,OU=Citrix,DC=corp,DC=local Note: By default, NetScaler® only searches for user names that are direct members of the Active Directory group. If you want to search nested groups, then add the Microsoft OID:: to the LDAP Search Filter. The OID is inserted between memberOf and =.Example: memberOf:1.2.840.113556.1.4.1941:=CN=Citrix Remote,OU=Citrix,DC=corp,DC=local -
Click OK.
NetScaler Gateway session policy method
set vpn sessionAction sessionActionName -allowedLoginGroups groupName
-
Navigate to NetScaler Gateway > Policies > Session.
-
In the details pane, click Add.
-
In Name, type a name for the policy.
-
Next to Profile, click Add.
-
In Name, type a name for the profile.
-
Click the Security tab and select Advanced Settings.
-
Next to Groups Allowed To Login, select Override Global, and then enter the Active Directory groups to be allowed to log in to NetScaler Gateway.
-
Click Create.