Citrix NetScaler - RADIUS Configuration - Authentication Manager - RSA Ready Implementation Guide
This article describes how to integrate Authentication Manager (AM) with Citrix NetScaler using RADIUS.
Configure AM
Perform these steps to configure AM.
Procedure
- Sign in to Security Console.
- Navigate to RADIUS > RADIUS Servers and make a note of the IP address of the selected RADIUS server.
- Navigate to RADIUS > RADIUS Clients > Add New.
- On the Add RADIUS Client page, enter the following:
- Client Name: Enter a descriptive name for the RADIUS client.
- IPv4 Address: Enter the IP address of the RADIUS client (NetScaler IP Address - NSIP).
- Make/Model: Standard Radius.
- Shared Secret: Create and enter a secure shared secret. This secret will be used for secure communication between the RADIUS client and the RADIUS server.
- Click Save & Create Associated RSA Agent.
- On the Add New Authentication Agent page, click Save, then confirm by clicking Yes, Save Agent.
Notes
- RSA Authentication Manager RADIUS server listens on ports UDP 1645 and UDP 1812.
- The relationship of the agent host record to the RADIUS client in the Authentication Manager can be 1 to 1, 1 to many, or 1 to all (global).
- Shared Secret must be an alphanumeric string between 1 and 31 characters in length and is case-sensitive.
Configure Citrix NetScaler
Perform these steps to configure Citrix NetScaler.
Procedure
- Log in to the NetScaler ADC VPX with nsroot account.
- In the left pane, navigate to Security > AAA - Application Traffic > Policies > Authentication > Basic Policies > RADIUS.
- On the Servers tab, click Add, enter values for the following parameters, and click Create.
- Name: Name of the RADIUS server.
- Choose Server IP to enter the IP address of the RADIUS server.
- IP Address: Enter the IP address of the RSA Identity Router.
- Secret Key: Enter the secret key for RADIUS communication. This should match the same key entered in the RSA configuration section.
- Transport: UDP
- Time-out: Increase the timeout value to 30 seconds.
- Test RADIUS Reachability: Click the button to ensure successful communication between the RADIUS server and the client over UDP before committing and creating the RADIUS server.
- Create a corresponding RADIUS policy.
- Navigate to Security > AAA - Application Traffic > Policies > Authentication > Advanced Policies > Policy and click Add.
- On the Create Authentication Policy page, provide the following details:
- Name: Specify a name for the RADIUS policy.
- Action Type: Select RADIUS as the authentication action type.
- Action: Select the RADIUS server profile created to bind the RADIUS policy with.
- Expression: Displays the name of the rule or expression that the RADIUS policy uses to determine if the user must authenticate with the RADIUS server. In the textbox, set the value true for the policy to take effect and the corresponding RADIUS action to be run.
- Bind the RADIUS policy to the authentication virtual server.
- Navigate to Security > AAA - Application Traffic > Virtual Servers.
- In the Virtual Server settings, associate the RADIUS policy created above with the authentication virtual server.
- Associate the authentication server with the appropriate traffic management virtual server.
- Navigate to Traffic Management > Load Balancing (or Content Switching) > Virtual Servers, select the virtual server, and associate the authentication virtual server with it.
- Navigate to Traffic Management > Load Balancing (or Content Switching) > Virtual Servers, select the virtual server, and associate the authentication virtual server with it.
The configuration is complete.
Related Articles
Citrix NetScaler - RSA Ready Implementation Guide 48Number of Views Citrix NetScaler - RADIUS Configuration - Cloud Access Service - RSA Ready Implementation Guide 1Number of Views CyberArk Password Vault Web Access - RADIUS Configuration with Authentication Manager - RSA Ready Implementation Guide 153Number of Views Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 674Number of Views Okta Agent - RADIUS Configuration - Authentication Manager - RSA Ready Implementation Guide 119Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager Upgrade Process Unsuccessful Registration of the RSA Authenticator app for iOS or Android with a registration code from the Cloud Administ…
Don't see what you're looking for?