-
Getting Started with NetScaler
-
Solutions for Telecom Service Providers
-
Load Balance Control-Plane Traffic that is based on Diameter, SIP, and SMPP Protocols
-
Provide Subscriber Load Distribution Using GSLB Across Core-Networks of a Telecom Service Provider
-
Authentication, authorization, and auditing application traffic
-
Basic components of authentication, authorization, and auditing configuration
-
-
Client certificate authentication
-
Web proxy support for outbound calls to IDP or third party endpoints
-
Web Application Firewall protection for VPN virtual servers and authentication virtual servers
-
On-premises NetScaler Gateway as an identity provider to Citrix Cloud™
-
Authentication, authorization, and auditing configuration for commonly used protocols
-
Troubleshoot authentication and authorization related issues
-
Troubleshoot authentication, authorization and auditing issues
-
Configure EULA as an authentication factor in NetScaler nFactor system
-
Configure periodic Endpoint Analysis scan as a factor in nFactor authentication
-
Configure post-authentication Endpoint Analysis scan as a factor in NetScaler nFactor authentication
-
Configure pre-authentication Endpoint Analysis scan as a factor in nFactor authentication
-
Configure pre-auth and post-auth EPA scan as a factor in nFactor authentication
-
Configure prefill user name from certificate in NetScaler nFactor authentication
-
Configure protected user as an authentication factor in NetScaler nFactor authentication
-
Localize error messages generated by NetScaler nFactor system
-
Configure NetScaler Gateway preauthentication EPA scan for the domain check
-
-
-
-
-
-
-
Configure DNS resource records
-
Configure NetScaler as a non-validating security aware stub-resolver
-
Jumbo frames support for DNS to handle responses of large sizes
-
Caching of EDNS0 client subnet data when the NetScaler appliance is in proxy mode
-
Use case - configure the automatic DNSSEC key management feature
-
Use Case - configure the automatic DNSSEC key management on GSLB deployment
-
-
-
Source IP address whitelisting for GSLB communication channels
-
Use case: Deployment of domain name based autoscale service group
-
Use case: Deployment of IP address based autoscale service group
-
-
Persistence and persistent connections
-
Advanced load balancing settings
-
Gradually stepping up the load on a new service with virtual server–level slow start
-
Protect applications on protected servers against traffic surges
-
Retrieve location details from user IP address using geolocation database
-
Use source IP address of the client when connecting to the server
-
Use client source IP address for backend communication in a v4-v6 load balancing configuration
-
Set a limit on number of requests per connection to the server
-
Configure automatic state transition based on percentage health of bound services
-
-
Use case 2: Configure rule based persistence based on a name-value pair in a TCP byte stream
-
Use case 3: Configure load balancing in direct server return mode
-
Use case 6: Configure load balancing in DSR mode for IPv6 networks by using the TOS field
-
Use case 7: Configure load balancing in DSR mode by using IP Over IP
-
Use case 10: Load balancing of intrusion detection system servers
-
Use case 11: Isolating network traffic using listen policies
-
Use case 12: Configure Citrix Virtual Desktops for load balancing
-
Use case 13: Configure Citrix Virtual Apps and Desktops for load balancing
-
Use case 14: ShareFile wizard for load balancing Citrix ShareFile
-
Use case 15: Configure layer 4 load balancing on the NetScaler appliance
-
-
-
-
Support for hybrid Post Quantum cryptography on the frontend
-
-
Create a certificate signing request and use SSL certificates on a NetScaler appliance
-
Configure SSL acceleration with HTTP on the front end and SSL on the back end
-
Export certificates used on a NetScaler appliance as PFX file
-
Configure SSL monitoring when client authentication is enabled on the back-end service
-
Configure SSL action to forward client traffic if a cipher is not supported on the ADC
-
Configure synchronization of files in a high availability setup
-
-
-
Authentication and authorization for System Users
-
-
-
Configuring a CloudBridge Connector Tunnel between two Datacenters
-
Configuring CloudBridge Connector between Datacenter and AWS Cloud
-
Configuring a CloudBridge Connector Tunnel Between a Datacenter and Azure Cloud
-
Configuring CloudBridge Connector Tunnel between Datacenter and SoftLayer Enterprise Cloud
-
Configuring a CloudBridge Connector Tunnel Between a NetScaler Appliance and Cisco IOS Device
-
CloudBridge Connector Tunnel Diagnostics and Troubleshooting
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Client certificate authentication
Websites that contain sensitive content, such as online banking websites or websites with employee personal information, sometimes require client certificates for authentication. To configure authentication, authorization, and auditing to authenticate users based on client-side certificate attributes, you first enable client authentication on the traffic management virtual server and bind the root certificate to the authentication virtual server. Then, you implement one of two options. You can configure the default authentication type on the authentication virtual server as CERT, or you can create a certificate action that defines what the NetScaler must do to authenticate users based on a client certificate. In either case, your authentication server must support CRLs. You configure the ADC to extract the user name from the Subject:CN field or another specified field in the client certificate.
When a user logs on to an authentication virtual server for which an authentication policy and a global cascade is not configured, the user name is extracted from the specified certificate field. The authentication succeeds if the required field is successfully extracted. The authentication fails if the user name extraction fails. It also fails if the user does not provide a valid certificate during the TLS handshake or if the submitted client certificate is marked as BAD during the TLS handshake. After validating the client certificate, the ADC presents a logon page to the user.
The following procedures assume that you have already created a functioning authentication, authorization, and auditing configuration, and therefore they explain only how to enable authentication by using client certificates. These procedures also assume that you have obtained your root certificate and client certificates and have placed them on the ADC in the /nsconfig/ssl directory.
Configure client certificate authentication
Configure client certificate parameters by using the GUI
-
Install a CA certificate and bind it to an authentication virtual server.
- Navigate to Security > AAA - Application Traffic > Virtual Servers.
- On the Authentication Virtual Servers page that appears, select the virtual server that you want to configure to handle client certificate authentication, and then click Edit.
- On the Authentication Virtual Server page, navigate to the Certificate section and click the right arrow “>” next to CA Certificate.
-
On the CA Certificate Binding page, select a CA certificate, update the other required fields, and click Bind.

- If a CA certificate is not available, then select Add.
- On the Install CA Certificate page, update the following fields and click Install and then click Close.
- Certificate-Key Pair Name: Name for the certificate and private-key pair.
- Certificate File Name: The name of the certificate file that is used to form the certificate-key pair. The certificate file must be present on the NetScaler’s hard-disk drive or solid-state drive. Storing a certificate in any location other than the default might cause inconsistency in a high availability setup. The default path is /nsconfig/ssl/.
- Notification Period: Number of days before certificate expiration at which NetScaler notifies the admin that the certificate is about to expire.
- Notify When Expires: Enable this option to receive an alert when the certificate is about to expire.

- Once the CA certificate is installed, go to the CA Certificate Binding page, bind it to an authentication virtual server.
- Return to the Security > AAA - Application Traffic > Virtual Servers page.
- Navigate to Security > AAA - Application Traffic > Policies > Authentication > Basic Policies > CERT.
- Select the policy that you want to configure to handle client certificate authentication, and then click Edit.
- On the Configure Authentication CERT Policy page, go to the Server drop-down list and select the virtual server that is configured to handle client certificate authentication.
-
Click OK.

Configure client certificate parameters by using the CLI
At the command prompt, type the following commands, in the order shown, to configure the certificate and verify the configuration:
add ssl certKey <certkeyName> -cert <certFile> -key <keyFile> -password -inform <inform> -expiryMonitor <expiryMonitor> -notificationPeriod <notificationPeriod>
bind ssl certKey [<certkeyName>] [-ocspResponder <string>] [-priority <positive_integer>]
show ssl certKey [<certkeyName>]
set aaa parameter -defaultAuthType CERT
show aaa parameter
set aaa certParams -userNameField "Subject:CN"
show aaa certParams
<!--NeedCopy-->
Configure client certificate advanced authentication policies by using the GUI
-
Install a CA certificate and bind it to a certificate-key pair.
- Navigate to Security > AAA - Application Traffic > Virtual Servers.
- On the Authentication Virtual Servers page that appears, select the virtual server that you want to configure to handle client certificate authentication, and then click Edit.
- On the Authentication Virtual Server page, navigate to the Certificate section and click the right arrow “>” next to CA Certificate.
- On the CA Certificate Binding page, select a CA certificate, update the other required fields, and click Bind.
- If a CA certificate is not available, then select Add.
- On the Install Certificate page, update the following fields and click Install and then click Close.
- Certificate-Key Pair Name: Name for the certificate and private-key pair
- Certificate File Name: The name of the certificate file that is used to form the certificate-key pair. The certificate file must be present on the NetScaler’s hard-disk drive or solid-state drive. Storing a certificate in any location other than the default might cause inconsistency in a high availability setup. The default path is /nsconfig/ssl/.
- Notification Period: Number of days before certificate expiration at which NetScaler notifies the admin that the certificate is about to expire.
- Notify When Expires: Enable this option to receive an alert when the certificate is about to expire.
- Once the CA certificate is installed, go to the CA Certificate Binding page and repeat step 4.
-
Return to the Security > AAA - Application Traffic > Virtual Servers page.
Note:
If you have imported a valid CA certificate and server certificate for the virtual server you can skip steps 1 and 2.
- Navigate to Security > AAA - Application Traffic > Policies > Authentication > Advanced Policies, and then select Policy.
-
On the Authentication Policies page, do one of the following:
- To create a policy, click Add.
- To modify an existing policy, select the policy, and then click Edit.
-
On the Create Authentication Policy or Configure Authentication Policy page, type or select values for the parameters.
- Name: Policy name. You cannot change the name of a previously configured policy.
- Action Type: Type of the authentication action.
- Action: Name of the authentication action to be performed if the policy matches. You can choose an existing authentication action, or click Add and create an action.
- Expression: The rule that selects the connections to which you want to apply the action that you specified. The rule can be simple (“true” selects all traffic) or complex. You enter expressions by first choosing the type of expression in the leftmost drop-down list beneath the Expression window, and then by typing your expression directly into the expression text area, or by clicking Add to open the Add Expression dialog box and using the drop-down lists in it to define your expression.
- Log Action: The name of the audit action to use when an authentication request matches this policy. You can choose an existing audit action, or click Add to create an action.
- Comment: You can type a comment that describes the type of traffic that this authentication policy applies to. This field is optional.
- Click Create or OK, and then click Close.
Client certificate pass-through
The NetScaler can now be configured to pass client certificates through to protected applications that require client certificates for user authentication. The ADC first authenticates the user, then inserts the client certificate into the request and sends it to the application. This feature is configured by adding appropriate SSL policies.
The exact behavior of this feature when a user presents a client certificate depends upon the configuration of the VPN virtual server.
- If the VPN virtual server is configured to accept client certificates but not require them, the ADC inserts the certificate into the request and then forwards the request to the protected application.
- If the VPN virtual server has client certificate authentication disabled, the ADC renegotiatiates the authentication protocol and reauthenticates the user before it inserts the client certificate in the header and forwards the request to the protected application.
- If the VPN virtual server is configured to require client certificate authentication, the ADC uses the client certificate to authenticate the user, then inserts the certificate in the header and forwards the request to the protected application.
In all of these cases, you configure the client certificate pass-through as follows.
Create and configure client certificate pass-through by using the CLI
At the command prompt, type the following commands:
add vpn vserver <name> SSL <IP> 443
<!--NeedCopy-->
For name, substitute a name for the virtual server. The name must contain from one to 127 ASCII characters, beginning with a letter or underscore (_), and containing only letters, numbers, and the underscore, hash (#), period (.), space, colon (:), at (@), equals (=), and hyphen (-) characters. For <IP>, substitute the IP address assigned to the virtual server.
set ssl vserver <name> -clientAuth ENABLED -clientCert <clientcert>
<!--NeedCopy-->
For <name>, substitute the name of the virtual server that you created. For <clientCert>, substitute one of the following values:
- disabled—disables client certificate authentication on the VPN virtual server.
- mandatory—configures the VPN virtual server to require client certificates to authenticate.
- optional—configures the VPN virtual server to allow client certificate authentication, but not to require it.
bind vpn vserver <name> -policy local
<!--NeedCopy-->
For <name>, replace the name of the VPN virtual server that you created.
bind vpn vserver <name> -policy cert
<!--NeedCopy-->
For <name>, substitute the name of the VPN virtual server that you created.
bind ssl vserver <name> -certkeyName <certkeyname>
<!--NeedCopy-->
For <name>, substitute the name of the virtual server that you created. For <certkeyName>, substitute the client certificate key.
bind ssl vserver <name> -certkeyName <cacertkeyname> -CA -ocspCheck Optional
<!--NeedCopy-->
For <name>, substitute the name of the virtual server that you created. For <cacertkeyName>, substitute the CA certificate key.
add ssl action <actname> -clientCert ENABLED -certHeader CLIENT-CERT
<!--NeedCopy-->
For <actname>, substitute a name for the SSL action.
add ssl policy <polname> -rule true -action <actname>
<!--NeedCopy-->
For <polname>, substitute a name for your new SSL policy. For <actname>, substitute the name of the SSL action that you created.
bind ssl vserver <name> -policyName <polname> -priority 10
<!--NeedCopy-->
For <name>, replace the name of the VPN virtual server.
Example
add vpn vserver vs-certpassthru SSL 10.121.250.75 443
set ssl vserver vs-certpassthru -clientAuth ENABLED -clientCert optional
bind vpn vserver vs-certpassthru -policy local
bind vpn vserver vs-certpassthru -policy cert
bind ssl vserver vs-certpassthru -certkeyName mycertKey
bind ssl vserver vs-certpassthru -certkeyName mycertKey -CA -ocspCheck Optional
add ssl action act-certpassthru -clientCert ENABLED -certHeader CLIENT-CERT
add ssl policy pol-certpassthru -rule true -action act-certpassthru
bind ssl vserver vs-certpassthru -policyName pol-certpassthru -priority 10
<!--NeedCopy-->
Share
Share
This Preview product documentation is Cloud Software Group Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Cloud Software Group Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Cloud Software Group product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.