Introduction As you might know I’m a big fan of the integrated WAF for Gateway an AAA (With newer 14.1 – also for WebGUI MGMT) – I’ve stumbled across some issues where that WAF is
Continue reading
It's all about EUC
Introduction As you might know I’m a big fan of the integrated WAF for Gateway an AAA (With newer 14.1 – also for WebGUI MGMT) – I’ve stumbled across some issues where that WAF is
Continue reading
Overview Recently I’ve stumbled across two identical issues in different environments. One with 13.1 60.29 and the other with 14.1 51.72 (did the same tests with 14.1 56.71, too) A negotiate Auth-Policy, linked to an
Continue reading
Overview In the recent released NetScaler Firmware 14.1 51.72 they’ve added first Support for the new NIST standard (hybrid) Post-Quantum Cryptography Key Exchange (PQC KX). Let’s have a first look on how to configure the
Continue reading
Overview We all did some Firmware-Updates during the last weeks regarding the current CVE’s for NetScaler and NetScaler Console. I did a lot of updates for NetScaler to 14.1 47.46 and NetScaler Console (NSC) to
Continue reading
Overview First of all, when using Microsoft Exchange Server OnPrem, try to use Modern-Authentication Methods like HMA (Hybrid Modern Authentication with Entra ID) or OAuth with ADFS (with NetScaler in front of 🙂 ) when
Continue reading
Overview Enabling the enhanced Authentication Feedback on NetScaler’s AAA gives Endusers a better understanding of WHAT is wrong with their credentials (Username, Password, OTP) but is also a lack of security, as potential password spraying
Continue reading
Overview There is a great post about DTLS 1.2 from Ferroque Systems for using EDT with HDX. I tried that config for the usage of DTLS 1.2 within SSLVPN, so the tunnel in Citrix Secure
Continue reading
Overview This Post contains informations about restricting the Usage of Citrix DaaS (Cloud Workspace customer.cloud.com) for limited Countries / Geo-Locations. In this scenario I’m using NetScaler as IdP of Citrix DaaS – so this is
Continue reading
Overview Recently a customer had to switch from User-Cert Authentication (CBA) to Device-Cert Authentication, so I had to create a new nFactor flow with EPA for Device-Cert Check. This Post will cover the following requirements:
Continue reading
Overview Quick Post about what is the hijacking of an authenticated NetScaler user session and how to protect yourself from it. This feature starts with 13.1 Build 53.17 and 14.1 Build 25.53 There are two
Continue reading