Citrix NetScaler RADIUS

Introduction

Multi Factor Authentication (MFA) is an extra layer of security used when logging into websites or apps. Individuals are authenticated through more than one required security and validation procedure that only you know or have access to.

RADIUS is a protocol commonly used to authenticate, authorize, and account for user access and actions. Citrix NetScalerTM is an application delivery and load balancing solution that provides a high-quality user experience for your web and cloud-based applications. Acceptto, as a Citrix Ready Partner, offers a simple method for adding MFA to Citrix NetScaler via its RADIUS solution.

Pre-Requisites
  1. An Acceptto Appliance connected to your user directory (for example Microsoft™ ‘Active Directory™’).
  2. A user with administrative privileges for the Acceptto Appliance.
  3. The user population that is going to be authenticated via RADIUS must be enrolled in the It’sMe™ mobile Application.
  4. A user with administrative privileges for the Netscaler Gateway.
Configure the Acceptto Appliance RADIUS interface
  1. Login to the Acceptto Appliance admin panel with an administrative account, select RADIUS and enter the following values.
  2. Radius settings
    • NETBIOS domain - enter the NETBIOS domain name.
    • Assigned Computer Name - Enter the computer name that you want to be created in Active Directory. For example, radius1.
    • REALM - Enter the realm that is appended to your username. Usually, this is your domain name.
    • MFA Active Directory Group - Enter the LDAP group that contains the users that can login via MFA (note that by default users outside of this group will have their access denied).
    • MFA Login message - enter the message that your users are going to see on the It’sMe mobile application.
    • Radius eGuardian UID - enter the UID of Radius application in your eGuardian Admin Panel.
    • Radius eGuardian Secret - enter the Secret of Radius application in your eGuardian Admin Panel.
  3. Click on Save Changes.
Configure your Citrix Netscaler Gateway
  1. Login to your Citrix NetScaler with an administrative account.
  2. Navigate to NetScaler Gateway > Policies > Authentication and click RADIUS.
  3. NetScaler Policies
  4. Go to the Servers tab and click Add.
  5. NetScalers servers tab
  6. Fill the fields based on the following table, then click Create.
  7. Name Optional
    Server Name or IP Address The hostname or IP address of the Acceptto Appliance
    Port The port configured for RADIUS in Acceptto Appliance. Default is 1812
    Time-out (seconds) 90
    Secret Key RADIUS shared key in Acceptto Appliance
    Confirm Secret Key RADIUS shared key in Acceptto Appliance
    Radius authentication server creation
  8. Navigate to Citrix Gateway > Virtual Servers and click Add.
  9. Citrix virtual server
  10. Fill the fields and click Ok.
  11. Citrix virtual server details
  12. Click + to create Basic Authentication.
  13. Basic Authentication
  14. Select Radius.
  15. Radius selection
  16. Bind the preferred policy. Then you can login to Netscaler with Radius authentication.
  17. Binding Policy
  18. After binding you can login in Netscaler with Radius authentication.
Test Your Setup
  1. Go to the Citrix Gateway Virtual Server and enter your credentials.
  2. Citrix gateway login page
  3. You’ll receive a push notification on your It’sMe mobile application and can enter after approval.
  4. It'sMe transaction
Support

If you require assistance, please email us at support@acceptto.com

Sales

Want to learn more about our MFA solutions? Contact our Professional Services for a Demo today.

Disclaimer

All product names, trademarks, and registered trademarks are the property of their respective owners.
All company, product, and service names used in this document are for identification purposes only. Use of these names, trademarks, and brands does not constitute endorsement by the Acceptto Corporation.
Citrix, NetScaler, and ‘Netscaler Gateway’ are either registered trademarks or trademarks of Citrix and/or one or more of its subsidiaries in the United States and/or other countries.
Microsoft and 'Active Directory' are either registered trademarks or trademarks of Microsoft and/or one or more of its subsidiaries in the United States and/or other countries.