Jump to content
Welcome to our new Citrix community!

NetScaler 11 - Two-Factor Authentication - Admin Console

Mark Kroehler 2

Recommended Posts

Was wondering if anyone has attempted to configure a two-factor authentication setup for the administration of the NetScaler, not for application traffic?


I know that there is plenty of guidance on setting up MFA for NetScaler Gateway and access to applications, but I haven't found anything written to address MFA for the Administrative Console.


A client of mine is looking at setting up MFA for NetScalers being hosted in the cloud. Since the corporate standard for remote access to systems is MFA, they'd like to do the same for systems being managed in the cloud.


Internally, they have a test implementation using a Content Switch, which has an Authentication Profile pointing to a RADIUS profile. The profile points to a load balanced RADIUS server being authenticated against. Additionally, an LDAP policy is configured on the NetScaler.


While it appears to work, the client says that it doesn't work consistently and doesn't work well when moving to another appliance (they have quite a few VPX instances). 


Was wondering if anyone else had attempted something similar or can point to Citrix guidance on how to setup something like this? I haven't found anything.


Also, curious as to why this functionality isn't native to the platform, given that nsroot can't be deleted/replaced or disabled. You'd think protecting the platform would be just as important, if not more so, than protecting the apps...

  • Like 1
Link to comment
Share on other sites

  • 1 year later...
  • 6 months later...
  • 1 month later...
  • 1 year later...

You know something, I posted to this thread originally close to two years ago... the thread is 4 years old.. is it still not an option? Really? Especially after CVE-2019-19781 this is still not in there (not sure it would have helped any, but it does highlight the point that this is a security device and any kind of programming faux pas needs to be mitigated on all fronts)

Link to comment
Share on other sites

  • 7 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Create New...