NetScaler and StoreFront interop has undergone several improvements in the last few releases to reduce integration mistakes by administrator. Initial efforts were targeted to allow administrators to import NetScaler Gateway configuration into StoreFront through the management console with minimal administration effort.
The aim of this new integration improvement is to reduce the NetScaler configuration complexity by enabling NetScaler to authenticate users with StoreFront (via LDAP instead of the NetScaler Gateway performing an LDAP query to an Active Directory server. The NetScaler configuration will be reduced by providing a minimal amount of information: the FQDN of the StoreFront server, and the name of the domain where users authenticate.
A benefit of offloading authentication to StoreFront (instead of NetScaler) is that the Active Directory server does not need to be directly exposed to the DMZ, reducing the chance of an attack.
The following product versions support this integration:
One of the key aspects of this feature is to provide a configuration experience where the administrator does not have to enter an LDAP configuration on the NetScaler Gateway side. By allowing StoreFront to perform the LDAP authentication, StoreFront attempts to verify the user credentials and gather the user’s UPN (User Principal Name) and Active Directory group information, without any specific configuration information about the customer’s domain structure and AD environment.
While this approach provides a good experience for the administrator, it has some limitations that need to be recognized. These limitations restrict the type of domain and Active Directory deployments that are supported.
The key limitations to the supported domain infrastructure are: