
Chapter 4 Securing the Enterprise 107
Usage
Remote Control Connections
1. Select a configuration from the connectivity matrix above and set up a
supported client configuration. (For instructions about installing and
configuring a connection with an ICA Client, see the Citrix MetaFrame
documentation.
2. Initiate a connection to the MetaFrame server using one of the supported
protocols. The standard MetaFrame logon screen appears.
3. Log on to the MetaFrame server. If the user specified belongs to the local user
group Sdlocal or domain Sdlocal (see “Domain Controller Installations”
below), you must provide a SecurID authentication passcode.
4. Respond to the SecurID challenge with a passcode from a SecurID token card.
Bypassing Authentication on a Per-Session Basis
Windows 2000
contains a fix that allows you to configure sessions to bypass
SecurID logon authentication (not RAS authentication) on a per-session basis. If
the user is a member of the Sdlocal group or the server is configured to challenge
all users, the user is not challenged. To bypass SecurID authentication for a
session:
1. Start Citrix Connection Configuration.
2. Select a session.
3. Select Advanced Session.
4. Check the Use Default Authentication box and click OK to save the changes.
Remote Node Connections
1. Configure a machine as specified in the above configuration matrix. Dial into a
RAS port. Be sure that the client software is configured to display terminal
mode after dialup. This step is essential or you cannot log on. Each user
configured in the Sdremote or domain Sdremote user groups is prompted for
the domain, username, and password.
2. Upon successful authentication, your username and password are taken from
the RAS client’s configuration and verified by the network as with a normal
RAS logon.
Your RAS logon username and your ACE/Server name must be
identical.
Domain Controller Installations
If the ACE/Agent software is installed on a MetaFrame server that is also a
domain controller, two additional groups are created during the installation:
domain Sdremote and domain Sdlocal. These two groups allow users on any
Note
Comentarios a estos manuales