Gateway

Configuring SafeWord Authentication

The SafeWord product line helps to provide secure authentication by using a token-based passcode. After users enter a passcode, it is invalidated by SafeWord and cannot be used again.

If NetScaler Gateway is replacing the Secure Gateway in a Secure Gateway and StoreFront deployment, you can choose to not configure authentication on NetScaler Gateway and continue to allow StoreFront to provide SafeWord authentication for incoming HTTP traffic.

NetScaler Gateway supports SafeWord authentication for the following products:

  • SafeWord 2008
  • SafeWord PremierAccess
  • SafeWord for Citrix
  • SafeWord RemoteAccess

You can configure NetScaler Gateway to authenticate using SafeWord products in the following ways:

  • Configure authentication to use a PremierAccess RADIUS server that is installed as part of SafeWord PremierAccess and allow it to handle authentication.
  • Configure authentication to use the SafeWord IAS agent, which is a component of SafeWord RemoteAccess, SafeWord for Citrix, and SafeWord PremierAccess 4.0.
  • Install the SafeWord Web Interface Agent to support StoreFront. You do not have to configure authentication on NetScaler Gateway and StoreFront can handle this. This configuration does not use the PremierAccess RADIUS server or the SafeWord IAS Agent.

When configuring the SafeWord RADIUS server, you need the following information:

  • The IP address of NetScaler Gateway. When you configure client settings on the RADIUS server, use the NetScaler Gateway IP address.
  • A shared secret.
  • The IP address and port of the SafeWord server.
Configuring SafeWord Authentication