If you create an action specifying client-side authentication on a per-directory basis, a client identified by a policy associated with the action is not authenticated as part of the initial SSL handshake. Instead, authentication is carried out every time the client wants to access a specific directory on the web server.
For example, you might have multiple divisions in the company and each division might have a folder in which all its files are stored. Enable per-directory client authentication for a directory to know the identity of each client that tries to access files from that directory.
To enable per-directory client authentication, first configure client authentication as an SSL action, and then create a policy that identifies the directory that you want to monitor. When you create the policy, specify your client-authentication action as the action associated with the policy. Then, bind the policy to the SSL virtual server that receives the SSL traffic.