Administrator Guide

Table Of Contents
Configuring Citrix ADC using DUO
About this task
To configure the Citrix ADC (formerly NetScaler) using DUO authentication, do the following:
Steps
1. Go to NetScaler > NetScaler Gateway > Virtual Servers, and click Edit.
2. Ensure that the primary authentication is RADIUS that is configured with the DUO authentication RADIUS.
3. Ensure that the secondary authentication is none.
4. Enter the broker address in the ThinOS user interface.
Example
For more information about configuring Citrix ADC with DUO authentication, see the Citrix NetScaler Gateway Guide at
www.duo.com.
Configure Citrix ADC using CensorNet MFA authentication
Prerequisites
SMS PASSCODE is re-branded as CensorNet MFA. You can configure the Citrix ADC (formerly NetScaler) to use a One
Time Passcode/Password (OTP) in the form of a personal identification number (PIN) or passcode. To obtain this one-time
password, you must install CensorNet app on your mobile. After you enter the passcode or PIN, the authentication server
invalidates the one-time password. You cannot enter the same PIN or password again. For more information about configuring
one-time passcode, see the Citrix documentation.
Prerequisites
Citrix ADC (formerly NetScaler) v12.0 and later is installed on your client.
SMS PASSCODE v9.0 SP1 or later is installed and configured in your network. You can download the SMS PASSCODE v9.0
file from download.smspasscode.com/public/6260/SmsPasscode-900sp1.
Remote Authentication Dial-In User Service (RADIUS) authentication policy is configured and bind to the Citrix ADC server.
CensorNet app is installed and configured on your mobile device.
About this task
To use the one-time passcode on ThinOS, do the following:
Steps
1. Log in to ThinOS and connect to the ADC URL.
2. Enter your credentials, and press Enter.
The PASSCODE dialog box is displayed. You will receive a push notification from the CensorNet App on your phone with the
code.
3. Click OK.
If the authentication is successful, you are logged into the Citrix session.
Citrix ADC Native OTP
Citrix ADC (formerly NetScaler) Native OTP enables Citrix ADC Gateway to use one-time passwords (OTPs) for authentication
without the need of an extra authenticating server. A one-time password that is generated by Google Authenticator is
considered to be highly secure as passcodes are randomly generated.
If you access the Broker agent using Citrix ADC native OTP authentication, lock terminal is not supported as it is a web-based
authentication. When you try to use lock terminal, a message is displayed where you can click either Continue to log off or click
Cancel to stay on the screen. You are automatically signed off from the account in sixty seconds for security purposes.
Configuring connection brokers
65