Securing Citrix NetScaler Access Gateway AAGGE and Web Interface
Few steps to secure and reduce HTML / SQL Injection attempts and Brute Force Password Scripts from Attacking Securing Citrix NetScaler Access Gateway AAGGE and Web Interface.
- Setup Web Interface in HA and enable Automatic updates and set a variance of 30 mins for reboots. This should insure all Critical Microsoft Updates are installed on your DMZ Windows Servers and Internet facing servers and updated straight away.
- Implement End Point Analyse
- Implement CAPTHA
- Implement Visual Keyboard
- Implement Drop down select for PIN (Log me in style)
- Put 30 delay wait for retry for incorrect passwords
- Implement 2Factor authentication
- http://www.smspasscode.com/
- http://www.swivelsecure.com/devices/
- http://www.rsa.com
- Google Authenticator – http://support.citrix.com/article/CTX132808
- http://www.xenappblog.com/2010/how-to-load-balance-citrix-web-interface-with-nlb/
- https://www.duosecurity.com/editions
- http://blogs.citrix.com/2012/11/05/dual-factor-authentication-for-free-sms2/
- http://www.isager.dk/is/CICRadarR/Netscalerconfiguration.aspx
- Setup Double Hop DMZ
- .NET / Java SSL Visual Keyboard WIP
- http://stackoverflow.com/questions/13668131/java-swing-virtual-keyboard-on-jframe
- http://support.citrix.com/article/CTX118734
- http://www.greywyvern.com/code/javascript/
- http://net.tutsplus.com/tutorials/javascript-ajax/creating-a-keyboard-with-css-and-jquery/
- http://www.jquery4u.com/plugins/jquery-screen-keyboard-plugin/
- https://online.westpac.com.au/esis/Login/SrvPage?referrer=http%3A%2F%2Fwww.westpac.com.au%2FHomepageAlternative%2F
Reference