Information
This article documents a change to the behavior of NetScaler Gateway 10.5 when configuring Single Sign-on to hosts on public IP addresses.
Background
NetScaler Gateway 10.5 build 54.9 brings a change in behavior when authenticating against hosts using public IP addresses using Single Sign-on (SSO). For builds earlier than 54.9 and releases earlier than 10.5 the NetScaler Gateway supported connecting to host on public IP addresses using SSO. There are security concerns around allowing SSO to publicly based hosts so the behavior is changed.
To support SSO to hosts on Public IPs a traffic profile and policy must be configured.
Note: If traffic does not match the traffic policy rule, then SSO to public IPs will not succeed even when SSO is ON at VPN parameter or at the Session Policy level.
Use Cases
The following are the two use cases for Traffic Profiles/Policies to support SSO to public IPs.
Use Case 1 - Clientless VPN (CVPN) and Secure Browse
From Command Line Interface
Run the following command from the command line interface:
> add vpn trafficAction TraffProf_CVPN_SBrowse http -SSO ON > add vpn trafficPolicy TraffPol_CVPN_SBrowse "REQ.HTTP.HEADER Host == host.cloud.com" TraffProf_CVPN_SBrowse > bind vpn vserver test-sslvpn -policy TraffPol_CVPN_SBrowse -priority 100
From User Interface
-
Navigate to Configuration > NetScaler Gateway > Policies > Traffic.
-
Click the Traffic Profiles tab and click Add.
-
Give the Traffic Profile a name, select HTTP radio button and select ON from the Single Sign-on drop-down list.
-
Click OK.
-
In Configuration > NetScaler Gateway > Policies > Traffic select the Traffic Policies tab.
-
Click Add.
-
Enter a name for the Traffic Policy.
-
Select the Traffic Profile you created in steps 1-4.
-
Create an expression. In this example the policy will only trigger on traffic where the HTTP host header has a value of "netscaler.cloud.com".
Note: This policy only works if the traffic is HTTP, as this is the only time that the NetScaler will see the host header. -
Click Create.
-
Navigate to Configuration > NetScaler Gateway > Virtual Servers. Open the virtual server of your choice by double-clicking the entry in the list.
-
Scroll down to Policies and click the + (plus) icon.
-
Select Traffic from the Choose Policy drop-down list and Request is selected automatically from the Choose Type list.
-
Click Continue.
-
Click the right-arrow in the Select Policy area.
-
Select the Traffic Policy created in steps 5-10.
-
Click OK.
-
Click Bind in the Policies dialog window.
-
Click Done at the bottom of the Virtual Server window.
Use Case 2 - Full VPN and Micro VPN
From Command Line Interface
Run the following command from the command line interface:
> add vpn trafficAction TraffProd_FVPN_MVPN tcp -SSO ON > add vpn trafficPolicy TraffPol_FVPN_MVPN "REQ.IP.DESTIP == 200.100.50.25" TraffProf_FVPN_MVPN > bind vpn vserver test-sslvpn -policy TraffPol_FVPN_MVPN -priority 90
From User Interface
-
Navigate to Configuration > NetScaler Gateway > Policies > Traffic.
-
Click the Traffic Profiles tab and click Add.
-
Give the Traffic Profile a name, select TCP radio button and click Create.
-
Double click the TraffProf_FVPN_MVPN traffic profile in the UI and select ON from the Single Sign-on drop-down list. Click OK.
-
In Configuration > NetScaler Gateway > Policies > Traffic select the Traffic Policies tab.
-
Click Add.
-
Enter a name for the Traffic Policy.
-
Select the Traffic Profile you created in steps 1-4.
-
Create an expression.
Note: The NetScaler can never perform SSO for HTTPS traffic in VPN mode, because the NetScaler cannot see the HTTP correspondence inside SSL. For this reason you need to use suitable expressions. In this example the policy will only trigger on traffic where the destination IP of the request is equal to a specific address. In this example the IP address used is a public IP. -
Click Create.
-
Navigate to Configuration > NetScaler Gateway > Virtual Servers. Open the virtual server of your choice by double clicking the entry in the list.
-
Scroll down to Policies and click the + (plus) icon.
-
Select Traffic from the Choose Policy drop-down list and Request is selected automatically from the Choose Type list.
-
Click Continue.
-
Click the right arrow in the Select Policy area.
-
Select the Traffic Policy created in steps 5-10.
-
Click OK.
-
Click Bind in the Policies dialog window.
-
Click Done at the bottom of the Virtual Server window.
Additional Resources
For more information refer to NetScaler Gateway 10.5 release notes.
NetScaler Gateway does not support single sign-on (SSO) to public servers unless single sign-on is enabled in a traffic profile or if split tunneling is enabled.
[From Build 54.9] [#518414]
Supporto Citrix
Traduzione automatica
Questo articolo ??¨ stato tradotto da un sistema di traduzione automatica e non ??¨ stata valutata da persone. Citrix fornisce traduzione automatica per aumentare l'accesso per supportare contenuti; tuttavia, articoli automaticamente tradotte possono possono contenere degli errori. Citrix non ??¨ responsabile di incongruenze, errori o danni derivanti dell'uso di articoli automaticamente tradotte.
Citrix技術支持
自動翻譯
這篇文章被翻譯由一個自動翻譯系統,並沒有受到人們的審查。 Citrix提供自動翻譯,增加獲得支持的內容;但是,自動翻譯的文章可能可以包含錯誤。思傑不負責不一致,錯誤或損壞因使用自動翻譯的文章的結果。
Поддержка Citrix
Tradução automática
Эта статья была переведена автоматической системой перевода и не был рассмотрен людьми. Citrix обеспечивает автоматический перевод с целью расширения доступа для поддержки контента; Однако, автоматически переведенные статьи могут может содержать ошибки. Citrix не несет ответственности за несоответствия, ошибки, или повреждения, возникшие в результате использования автоматически переведенных статей.
시트릭스 지원
자동 번역
이 문서 자동 번역 시스템에 의해 번역 된 사람들에 의해 검토되지 않았다. 시트릭스는 컨텐츠를 지원하기 위해 접근을 높이기 위해 자동 번역을 제공합니다; 그러나, 자동으로 번역 기사 오류를 포함 할 수있다. 시트릭스는 자동으로 번역 된 기사의 사용의 결과로 발생하는 불일치, 오류 또는 손해에 대해 책임을지지 않습니다.