If you plan to deploy the on-demand password based authentication in your user base using Deepnet T-Pass, then you will have to configure your Citrix NetScaler to work in the Two-Step Logon mode. In the Two-Step Logon process, Netscaler will use your DualShield Radius server as the primary authentication server. Your DualShield server will be responsible for verifying both users’ AD password and one-time passwords. There should be no secondary authentication servers. Please note that for on-demand password you must use two-step logon, but for one-time password you can use either one-step or two-step logon.
In the DualShield Management Console, edit the logon procedure for your NetScaler application. You will need to define two logon steps: the first step requires users to enter their static password (AD password), which will also trigger the DualShield server to send the user’s on-demand password. The second step will then ask users to enter their on-demand password.
![DualShield MFA Platform > Two-Step Logon [CTX-RADIUS] > image2015-9-7 10:18:52.png](/download/attachments/35946836/image2015-9-7%2010%3A18%3A52.png?version=1&modificationDate=1587385533000&api=v2)
![DualShield MFA Platform > Two-Step Logon [CTX-RADIUS] > UnifiedGatewayRadius.png](/download/attachments/35946836/UnifiedGatewayRadius.png?version=1&modificationDate=1587385533000&api=v2)
![DualShield MFA Platform > Two-Step Logon [CTX-RADIUS] > image2014-4-11 14:23:19.png](/download/attachments/35946836/image2014-4-11%2014%3A23%3A19.png?version=1&modificationDate=1587385533000&api=v2)
Navigate to the Citrix NetScaler Access Gateway logon page:
![DualShield MFA Platform > Two-Step Logon [CTX-RADIUS] > UnifiedGatewayRadius1.png](/download/attachments/35946836/UnifiedGatewayRadius1.png?version=1&modificationDate=1587385533000&api=v2)
Enter your username and your AD password.
Your DualShield server will send an on-demand password via the delivery channel defined in your T-Pass policy, e.g. SMS text message or email message.
NetScaler will then prompt you to enter your T-Pass one-time password:
![DualShield MFA Platform > Two-Step Logon [CTX-RADIUS] > UnifiedGatewayRadius2.png](/download/attachments/35946836/UnifiedGatewayRadius2.png?version=1&modificationDate=1587385533000&api=v2)
![DualShield MFA Platform > Two-Step Logon [CTX-RADIUS] > image2014-4-11 14:55:58.png](/download/attachments/35946836/image2014-4-11%2014%3A55%3A58.png?version=1&modificationDate=1587385533000&api=v2)
Once your AD password is authenticated, DualShield Server will send an on-demand password via the delivery channel defined in your T-Pass policy.
Citrix Receiver will then prompt you to enter your T-Pass one-time password.
![DualShield MFA Platform > Two-Step Logon [CTX-RADIUS] > image2014-4-11 14:58:42.png](/download/attachments/35946836/image2014-4-11%2014%3A58%3A42.png?version=1&modificationDate=1587385533000&api=v2)