When you configure an authorization policy, you can set it to allow or deny access to network resources in the internal network. For example, to allow users access to the 10.3.3.0 network, use the following expression:
CLIENT.IP.DST.IN_SUBNET(10.3.0.0/16)
Authorization policies are applied to users and groups. After a user is authenticated, NetScaler Gateway performs a group authorization check by obtaining the user’s group information from either an RADIUS, LDAP, or TACACS+ server. If group information is available for the user, NetScaler Gateway checks the network resources allowed for the group.
To control which resources users can access, you must create authorization policies. If you do not need to create authorization policies, you can configure default global authorization.
If you create an expression within the authorization policy that denies access to a file path, you can only use the subdirectory path and not the root directory. For example, use fs.path contains "\\\\dir1\\\\dir2" instead of fs.path contains "\\\\rootdir\\\\dir1\\\\dir2". If you use the second version in this example, the policy fails.
After you configure the authorization policy, you then bind it to a user or group.
By default, authorization policies are validated first against policies that you bind to the virtual server and then against policies bound globally. If you bind a policy globally and want the global policy to take precedence over a policy that you bind to a user, group, or virtual server, you can change the priority number of the policy. Priority numbers start at zero. A lower priority number gives the policy higher precedence.
For example, if the global policy has a priority number of one and the user has a priority of two, the global authentication policy is applied first.
For more details on advanced authorization policies, see article <https://support.citrix.com/article/CTX232237>.