Administrator Guide

Table Of Contents
Citrix ADC
ThinOS supports Citrix Application Delivery Controller (ADC), formerly known as Citrix NetScaler. The following authentication
methods are supported on ThinOS:
Lightweight Directory Access Protocol (LDAP)
RSA
DUO
SMS PASSCODE
Native OTP
Federated Authentication Service with Azure active directory
OKTA
Citrix two-factor authentication
ThinOS supports Citrix two-factor authentication that authenticates the identity of the user twice before granting access,
adding an extra level of security.
For local authentication, there must be a user profile that is created in the Citrix ADC database. For external authentication,
the username and password that is entered must be the same as registered in the authentication server. After a successful
validation of the username and password, the user is requested for another level of authentication.
ThinOS supports LDAP, RSA+LDAP, SMS Passcode, DUO, OKTA, and Azure MFA authentications by default. The user must only
provide the Citrix ADC gateway address.
To log in to NetScaler Gateway that uses LDAP with RSA authentication, you must select LDAP+RSA in the Wyse
Management Suite policy. You can also go to Admin Policy Tool and configure the NetScaler/ADC Authentication Method
option in the Citrix Broker Settings window.
For specific users who want to use Citrix ADC authentication methods, such as RSA, it is recommended that you configure the
NetScaler/ADC Authentication Method with RSA either using the Wyse Management Suite policy or Admin Policy Tool.
For specific users who want to use Citrix ADC authentication methods, such as LDAP with MFA, it is recommended that you
configure the NetScaler/ADC Authentication Method with LDAP either using the Wyse Management Suite policy or the
Admin Policy tool.
Configure Citrix ADC using LDAP and RSA
About this task
This section describes how to configure the Citrix ADC (formerly NetScaler) using LDAP and RSA authentication.
Steps
1. Go to NetScaler > NetScaler Gateway > Virtual Servers, and click Edit.
2. Set the primary and secondary authentications based on the following scenarios:
If you use LDAP and RSA login, ensure that the primary authentication is LDAP and secondary authentication is RADIUS.
You must also ensure that the NetScaler Gateway Authentication Method in the Wyse Management Suite policy or
the Admin Policy Tool is configured as LDAP+RSA.
If you use RSA and LDAP login, ensure that the primary authentication is RADIUS and secondary authentication is LDAP.
If you use only LDAP login, ensure that the primary authentication is LDAP and secondary authentication is none.
3. Go to System Setup > Remote Connections and select Citrix Virtual Apps and Desktops from the Broker type
drop-down list.
4. Enter the Citrix ADC server address in the Broker Server field.
5. Log off from the client desktop, or restart the thin client.
The login window for Citrix ADC is displayed.
For more information about configuring Citrix ADC with LDAP, RSA authentication, see the Citrix NetScaler Gateway Guide
at www.citrix.com.
64
Configuring connection brokers