Server access control for MCP Gateway
-
Ensures that only approved MCP servers are accessible.
-
Prevents unauthorized or malicious MCP endpoints.
-
Provides centralized governance for MCP access.
-
Provides a clear rejection response for disallowed requests.
Important considerations
x-netscaler-target-mcp-server. We recommend that you:
-
Configure a deny policy as default.
-
Combine with authentication and rate limiting for full security.
Prerequisites
-
An MCP Gateway is configured on NetScaler using content switching and load balancing virtual servers.
-
Backend MCP servers are configured.
-
The client sends the target MCP header.
Configure allow list and block list using the CLI
Sample allow list configuration
add cs policy allow_app1 "HTTP.REQ.HEADER(\"x-netscaler-target-mcp-server\").CONTAINS(\"app1.com\")"
bind cs vserver mcp_cs -policyName allow_app1 -priority 10 -gotoPriorityExpression NEXT
Sample block list configuration
add responder action deny_res_act respondwith q<"HTTP/1.1 403 Forbidden\r\nContent-Type: application/json\r\nContent-Length: 42\r\nConnection: close\r\n\r\n{\"error\":\"Unauthorized MCP server access\"}">
add responder policy deny_res_pol "HTTP.REQ.HEADER(\"x-netscaler-target-mcp-server\").CONTAINS(\"untrusted.com\")" deny_res_act
bind cs vserver mcp_cs -policyName deny_res_pol -priority 100 -gotoPriorityExpression END -type REQUEST
Sample default deny policy
add responder policy default_deny "TRUE" deny_res_act
bind cs vserver mcp_cs -policyName default_deny -priority 1000 -gotoPriorityExpression END -type REQUEST