Overview First of all, when using Microsoft Exchange Server OnPrem, try to use Modern-Authentication Methods like HMA (Hybrid Modern Authentication with Entra ID) or OAuth with ADFS (with NetScaler in front of 🙂 ) when
Continue reading
It's all about EUC
Overview First of all, when using Microsoft Exchange Server OnPrem, try to use Modern-Authentication Methods like HMA (Hybrid Modern Authentication with Entra ID) or OAuth with ADFS (with NetScaler in front of 🙂 ) when
Continue reading
Overview Enabling the enhanced Authentication Feedback on NetScaler’s AAA gives Endusers a better understanding of WHAT is wrong with their credentials (Username, Password, OTP) but is also a lack of security, as potential password spraying
Continue reading
Overview There is a great post about DTLS 1.2 from Ferroque Systems for using EDT with HDX. I tried that config for the usage of DTLS 1.2 within SSLVPN, so the tunnel in Citrix Secure
Continue reading
Overview This Post contains informations about restricting the Usage of Citrix DaaS (Cloud Workspace customer.cloud.com) for limited Countries / Geo-Locations. In this scenario I’m using NetScaler as IdP of Citrix DaaS – so this is
Continue reading
Overview Recently a customer had to switch from User-Cert Authentication (CBA) to Device-Cert Authentication, so I had to create a new nFactor flow with EPA for Device-Cert Check. This Post will cover the following requirements:
Continue reading
Overview Quick Post about what is the hijacking of an authenticated NetScaler user session and how to protect yourself from it. This feature starts with 13.1 Build 53.17 and 14.1 Build 25.53 There are two
Continue reading
Overview Finally, with 14.1 Build 21.57 and 13.1 Build 53.17 there’s the long awaited support for using NetScaler’s Web Application Firewall (WAF) for all kind of Gateway vServer and AAA vServer. This is a Quickpost
Continue reading
Overview Quick Post about a latest finding of an Issue when using NetScaler as OAuth IdP (doesn’t matter with which SP) and there is the need of sending some User-Attributes to the SP. Update –
Continue reading
Overview You’re using Microsoft Entra ID (SAML or OAuth) as IdP for your OnPrem CVAD or DaaS Environment. Your default is to use Citrix FAS so the User-Logon to the VDA happens with a virtual
Continue reading
Overview In a latest SSLVPN Project with NetScaler and the Windows Secure Access Client (formerly Citrix Gateway Plugin) we had some problems with the rollout of the client via SCCM. Especially when there is a
Continue reading