-
Getting Started with NetScaler
-
Solutions for Telecom Service Providers
-
Load Balance Control-Plane Traffic that is based on Diameter, SIP, and SMPP Protocols
-
Provide Subscriber Load Distribution Using GSLB Across Core-Networks of a Telecom Service Provider
-
Authentication, authorization, and auditing application traffic
-
Basic components of authentication, authorization, and auditing configuration
-
Web Application Firewall protection for VPN virtual servers and authentication virtual servers
-
On-premises NetScaler Gateway as an identity provider to Citrix Cloud™
-
Authentication, authorization, and auditing configuration for commonly used protocols
-
Troubleshoot authentication and authorization related issues
-
Troubleshoot authentication, authorization and auditing issues
-
Configure EULA as an authentication factor in NetScaler nFactor system
-
Configure periodic Endpoint Analysis scan as a factor in nFactor authentication
-
Configure post-authentication Endpoint Analysis scan as a factor in NetScaler nFactor authentication
-
Configure pre-authentication Endpoint Analysis scan as a factor in nFactor authentication
-
Configure pre-auth and post-auth EPA scan as a factor in nFactor authentication
-
Configure prefill user name from certificate in NetScaler nFactor authentication
-
Localize error messages generated by NetScaler nFactor system
-
Configure NetScaler Gateway preauthentication EPA scan for the domain check
-
-
-
-
-
-
Persistence and persistent connections
-
Advanced load balancing settings
-
Gradually stepping up the load on a new service with virtual server–level slow start
-
Protect applications on protected servers against traffic surges
-
Retrieve location details from user IP address using geolocation database
-
Use source IP address of the client when connecting to the server
-
Use client source IP address for backend communication in a v4-v6 load balancing configuration
-
Set a limit on number of requests per connection to the server
-
Configure automatic state transition based on percentage health of bound services
-
-
Use case 2: Configure rule based persistence based on a name-value pair in a TCP byte stream
-
Use case 3: Configure load balancing in direct server return mode
-
Use case 6: Configure load balancing in DSR mode for IPv6 networks by using the TOS field
-
Use case 7: Configure load balancing in DSR mode by using IP Over IP
-
Use case 10: Load balancing of intrusion detection system servers
-
Use case 11: Isolating network traffic using listen policies
-
Use case 12: Configure Citrix Virtual Desktops for load balancing
-
Use case 13: Configure Citrix Virtual Apps and Desktops for load balancing
-
Use case 14: ShareFile wizard for load balancing Citrix ShareFile
-
Use case 15: Configure layer 4 load balancing on the NetScaler appliance
-
-
-
-
Create a certificate signing request and use SSL certificates on a NetScaler appliance
-
Configure SSL acceleration with HTTP on the front end and SSL on the back end
-
Export certificates used on a NetScaler appliance as PFX file
-
Configure SSL monitoring when client authentication is enabled on the back-end service
-
Configure SSL action to forward client traffic if a cipher is not supported on the ADC
-
Configure support for HTTP strict transport security (HSTS)
-
Configure synchronization of files in a high availability setup
-
-
-
Authentication and authorization for System Users
-
-
Configuring a CloudBridge Connector Tunnel between two Datacenters
-
Configuring CloudBridge Connector between Datacenter and AWS Cloud
-
Configuring a CloudBridge Connector Tunnel Between a Datacenter and Azure Cloud
-
Configuring CloudBridge Connector Tunnel between Datacenter and SoftLayer Enterprise Cloud
-
Configuring a CloudBridge Connector Tunnel Between a NetScaler Appliance and Cisco IOS Device
-
CloudBridge Connector Tunnel Diagnostics and Troubleshooting
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Configure support for HTTP strict transport security (HSTS)
HTTP Strict Transport Security (HSTS) helps protect websites against various attacks, such as SSL stripping, cookie hijacking, and protocol downgrade. Using HSTS, a server can enforce the use of an HTTPS connection for all communication with a client. That is, the site can be accessed only by using HTTPS.
NetScaler appliances support HSTS as an in-built option in SSL profiles and SSL virtual servers. Support for HSTS is required for A+ certification from SSL Labs.
Enable HSTS in an SSL front-end profile or on an SSL virtual server. If you enable SSL profiles, then you must enable HSTS on an SSL profile instead of enabling it on an SSL virtual server.
Specify the time (in seconds) for which a browser must not accept unencrypted connections. Use the maxage parameter to specify that HSTS is in force for that duration for that client. By default, the HSTS header applies only to the root domain. You can specify whether subdomains must be included. For example, you can specify that subdomains for www.example.com, such as www.abc.example.com and www.xyx.example.com, can be accessed only using HTTPS by setting the IncludeSubdomains parameter to YES. The subdomains must support HTTPS. However, they do not each need to have HSTS enabled.
If you access any websites that support HSTS, the response header from the server contains an entry similar to the following:

The client stores this information for the time specified in the max-age parameter. For subsequent requests to that website, the client checks its memory for an HSTS entry. If an entry is found, it accesses that website only by using HTTPS. For example, if you set the maxage parameter to 31536000, the browser remembers to use only HTTPS to access the domain for one year.
You can configure HSTS at the time of creating an SSL profile or an SSL virtual server by using the add command. You can also configure HSTS on an existing SSL profile or SSL virtual server by modifying it using the set command.
Configure HSTS by using the CLI
At the command prompt, type:
add ssl vserver <vServerName> -maxage <positive_integer> -IncludeSubdomains ( YES | NO)
set ssl vserver <vServerName> -HSTS ( ENABLED | DISABLED )
<!--NeedCopy-->
OR
add ssl profile <name> -maxage <positive_integer> -IncludeSubdomains ( YES | NO )
set ssl profile <name> -HSTS ( ENABLED | DISABLED )
Arguments
HSTS
State of HTTP Strict Transport Security (HSTS) on an SSL virtual server or SSL profile. Using HSTS, a server can enforce the use of an HTTPS connection for all communication with a client.
Possible values: ENABLED, DISABLED
Default: DISABLED
maxage
Set the maximum time, in seconds, in the strict transport security (STS) header during which the client must send only HTTPS requests to the server.
Default: 0
Minimum: 0
Maximum: 4294967294
IncludeSubdomains
Enable HSTS for subdomains. If set to Yes, a client must send only HTTPS requests for subdomains.
Possible values: YES, NO
Default: NO
<!--NeedCopy-->
In the following examples, the client must access the website and its subdomains for 157,680,000 seconds only by using HTTPS.
add ssl vserver VS-SSL –maxage 157680000 –IncludeSubdomain YES
set ssl vserver VS-SSL –HSTS ENABLED
<!--NeedCopy-->
add sslProfile hstsprofile –maxage 157680000 –IncludeSubdomain YES
set sslProfile hstsprofile –HSTS ENABLED
<!--NeedCopy-->
Configure HSTS by using the GUI
- Navigate to Traffic Management > Load Balancing > Virtual Servers.
- Select a virtual server of type SSL and click Edit.
Perform the following steps if the default SSL profile is enabled on the appliance.
-
Select an SSL profile and click Edit.
-
In Basic Settings, click the pencil icon to edit the settings. Scroll down and select HSTS and Include Subdomains.

Perform the following steps if the default SSL profile is not enabled on the appliance.
-
In Advanced Settings, select SSL Parameters.
-
Select HSTS and Include Subdomains.

Support for HSTS preload
An HSTS header protects the web application by preventing browsers from making unencrypted connections to a domain. However, if a user is accessing the website for the first time, the browser has not yet seen the HSTS header. An attacker might take over the connection before the web server can tell the browser to use HTTPS.
To address this problem, the NetScaler appliance supports adding an HSTS preload in the HTTP response header. To include the preload, you must set the preload parameter in the SSL virtual server or SSL profile to YES. The appliance then includes the preload in the HTTP response header to the client. You can configure this feature using both the CLI and the GUI. For more information about HSTS preload, see https://hstspreload.org/.
Following are examples of valid HSTS headers with preload:
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
<!--NeedCopy-->
Strict-Transport-Security: max-age=63072000; preload
<!--NeedCopy-->
Configure HSTS preload by using the CLI
At the command prompt, type:
add ssl vserver <vServerName> -maxage <positive_integer> -preload ( YES | NO )
set ssl vserver <vServerName> -HSTS ( ENABLED | DISABLED )
<!--NeedCopy-->
OR
add ssl profile <name> -maxage <positive_integer> -IncludeSubdomains ( YES | NO ) -preload ( YES | NO )
set ssl profile <name> -HSTS ( ENABLED | DISABLED )
<!--NeedCopy-->
Configure HSTS preload by using the GUI
Perform the following steps if the default SSL profile is enabled on the appliance.
-
Navigate to System > Profiles > SSL Profiles. Select an SSL profile and click Edit.
-
In Basic Settings, click the pencil icon to edit the settings. Scroll down and select HSTS and Preload.

Perform the following steps if the default SSL profile is not enabled on the appliance.
- Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
Select a virtual server of type SSL and click Edit.
-
In Advanced Settings, select SSL Parameters.
-
Select HSTS and Preload.

Use case
User1 wants to securely visit some websites using a web browser. The site exemple.com offers a secure browsing experience to their clients.
User1 has an account with exemple.com and regularly transacts using this website. User1 needs to transfer money to a friend and accesses exemple.com by typing www.exemple.com in a web browser. The browser converts the URL to http://www.exemple.com. The browser detects the name exemple.com and communicates with the DNS server to get the IP address for the host server. The browser contacts the IP address by using port 80. The banking website redirects the request to https://www.exemple.com. An SSL handshake is performed resulting in establishing an SSL connection. The padlock in the URL changes to green and shows locked. User1 can now enter the credentials to make a transaction.
Problem Scenario
Even if a website turns on HTTPS, a client might still try to connect over HTTP. The website can redirect the request to HTTPS, but this redirect is insecure because an attacker can capture the user information or redirect the user to a fake website. For example, a man-in-the-middle can intercept the resolving request for exemple.com and send User1 its own server IP address. When a request is made to this IP address on port 80, the man-in-the-middle can redirect User1 to a similar named website on port 443, such as https://www.example.com (note the slight change in spelling). User1 might not notice the discrepancy (example.com instead of exemple.com) and enter the credentials.
Solution
Perform the following steps on the NetScaler appliance to protect your website against attacks. At the CLI prompt, type:
add ssl profile sample-profile -maxage 63072000 -IncludeSubdomains YES -preload YES
set ssl profile sample-profile -HSTS ENABLED
<!--NeedCopy-->
Because HSTS is enabled, the appliance includes the preload in the HTTP response to the client. Also, HSTS is in force for the duration specified and subdomains are also included. As a result, only HTTPS connections are accepted from a client.
Share
Share
This Preview product documentation is Cloud Software Group Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Cloud Software Group Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Cloud Software Group product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.