Gateway Insight
Points to note
-
Gateway Insight is supported on the following deployments:
-
Access Gateway
-
Unified Gateway
-
-
The NetScaler ADM release and build must be the same or later than that of the NetScaler Gateway appliance.
-
One hour of Gateway Insight reports can be viewed for NetScaler instances with Advanced license. A Premium license is a must view Gateway Insight reports beyond one hour.
Limitations
-
NetScaler Gateway does not support Gateway Insight when the authentication method is configured as certificate-based authentication.
-
For Gateway Insight reporting, geo location information is not provided from the NetScaler appliance.
-
Successful user logons, latency, and application-level details for virtual ICA applications and desktops are visible only on the HDX™ Insight Users dashboard.
-
In a double-hop mode, visibility into failures on the NetScaler Gateway appliance in the second DMZ is not available.
-
Remote Desktop Protocol (RDP) desktop access issues are not reported.
-
Gateway Insight is supported for the following authentication types. If other authentication type is used other than these, you might see some discrepancies in Gateway Insight.
-
Local
-
LDAP
-
RADIUS
-
TACACS
-
SAML
-
Native OTP
-
OAuth-OpenID ConnectFor the OAuth-OpenID Connect authentication, NetScaler can act as an OAuth-OpenID connect relying party (RP) or OAuth-OpenID connect identity provider (IdP). When the authentication succeeds, the user name is reported under the Users tab in the Gateway Insight report. However, you cannot identify whether the session was created at IdP or RP.Note: OAuth-OpenID Connect authentication is supported from NetScaler ADM release 13.1 build 4.xx and later.
-
Enable Gateway Insight
-
Navigate to Infrastructure > Instances, and select the instance for which you want to enable AppFlow.
-
From the Select Action list, select Configure Analytics.
-
In the Configure Insight page, under Configure Analytics, select NetScaler Gateway.
-
Select the virtual server and then click Enable AppFlow.
-
On the Enable AppFlow screen, in the Select Expression list, click true.
-
Next to Transport Mode, select the Logstream check box.NoteYou can choose either IPFIX or Logstream as transport mode.For more information about IPFIX and Logstream, see Logstream overview.
-
Click OK.
For NetScaler ADM version 13.0 Build 41.x or later
-
Navigate to Infrastructure > Instances, and select the instance.
-
From the Select Action list, select Configure Analytics.
-
Select the virtual server and click Enable Analytics.
-
Under Advanced Options:
-
Select Logstream
-
Select NetScaler Gateway
-
-
Click OK.
Enable AppFlow authentication, authorization, and auditing user name logging on a NetScaler Gateway appliance by using the GUI
-
Navigate to Configuration > System > AppFlow > Settings, and then click Change AppFlow Settings.
-
In the Configure AppFlow Settings screen, select AAA Username, and then click OK.
Viewing Gateway Insight reports
To view EPA, SSO, authentication, authorization, and application launch failures
-
In NetScaler ADM, navigate to Gateway > Gateway Insight.
-
Select the time period for which you want to view the user details. You can use the time slider to further customize the selected period. Click Go.
-
Click the EPA (End Point Analysis), Authentication, Authorization, SSO (Single Sign On), or Application Launch tabs to display the failure details.

To view a summary of session modes, clients, and the number of users

Viewing Gateway Insight reports for users
-
All users associated with the NetScaler Gateway appliances.
-
The EPA, authentication, SSO, and application launch failures for a user.
-
The details of active and terminated sessions for a user.
-
The types of session modes such as Full Tunnel, clientless VPN, and ICA® Proxy.
To view user details
-
In NetScaler ADM, navigate to Gateway > Gateway Insight > Users.
-
Select the time period for which you want to view the user details. You can use the time slider to further customize the selected period. Click Go.
-
You can view the number of active users, number of active sessions, bytes, and licenses used by all users during the time period.

-
User details - You can view insights for each user associated with the ADC Gateway appliances. Navigate to Gateway > Gateway Insight > Users and click a user to view insights for the selected user such as Session Mode, Operating System, and Browsers.

-
Users and applications for the selected gateway - Navigate to Gateway > Gateway Insight > Gateway and click a gateway domain name to view the top 10 applications and top 10 users that are associated with the selected gateway.

-
View more option for applications and users – For more than 10 applications and users, you can click the more icon in Applications and Users to view all users and applications details that are associated with the selected gateway.
-
View details by clicking the bar graph – When you click a bar graph, you can view the relevant details. For example, navigate to Gateway > Gateway Insight > Gateway and click the gateway bar graph to view the gateway details.

-
The user Active Sessions and Terminated Sessions.

-
The gateway domain name and gateway IP address in Active Sessions.
-
The user login duration.

-
The reason for the user logout session. The logout reasons can be:
-
Session timed out
-
Logged out because of internal error
-
Logged out because of inactive session timed out
-
User has logged out
-
Administrator has stopped the session
-
Viewing Gateway Insight reports for applications
To view application details
-
In NetScaler ADM, navigate to Gateway > Gateway Insight > Applications.
-
Select the time period for which you want to view the application details. You can use the time slider to further customize the selected time period. Click Go.
Viewing Gateway Insight reports for gateways
To view gateway details
-
In NetScaler ADM, navigate to Gateway > Gateway Insight > Gateways.
-
Select the time period for which you want to view the gateway details. You can use the time slider to further customize the selected time period. Click Go.
Exporting reports
-
Users with read only access cannot export reports.
-
Geo map reports are exported only if the NetScaler ADM has internet connectivity.
To export a report
-
On the Dashboard tab, in the right pane, click the export button.
-
Under Export Now, select the required format, and then click Export.
-
On the Dashboard tab, in the right pane, click the export button.
-
Under Schedule Export, specify the details and click Schedule.
-
On the Configuration tab, navigate to Settings > Notifications > Email.
-
In the right pane, select Email Server, to add an email server, or select Email Distribution list to create an email distribution list.
-
Specify the details and click Create.
-
On the Dashboard tab, in the right pane, click the export button.
-
Under Export Now, select PDF format, and then click Export.
Gateway Insight use cases
A user is not able to log in to the NetScaler Gateway appliance or to the internal web servers
-
Authentication
-
End-point analysis (EPA)
-
Single sign-on
Authentication failures
-
In NetScaler ADM, navigate to Gateway > Gateway Insight.
-
In the Overview section, select the time period for which you want to view the authentication errors. You can use the time slider to further customize the selected time period. Click Go.

-
Click the Authentication tab. You can view the number of authentication errors at any given time in the Failures graph.

EPA failures
-
EPA failures are reported only when classic expressions are configured.
-
EPA failures are not reported if advanced expression is configured in the pre-authentication or post-authentication policy.
-
EPA failures are not reported if EPA is configured as one of the factors in an nFactor authentication flow.
-
In NetScaler ADM, navigate to Gateway > Gateway Insight.
-
In the Overview section, select the time period for which you want to view the EPA errors. You can use the time slider to further customize the selected time period. Click Go.

-
Click the EPA (End Point Analysis) tab. You can view the number of EPA errors at any given time in the Failures graph.

SSO failures
-
In NetScaler ADM, navigate to Gateway > Gateway Insight.
-
In the Overview section, select the time period for which you want to view the SSO errors. You can use the time slider to further customize the selected time period. Click Go.

-
Click the SSO (Single Sign On) tab. You can view the number of SSO errors at any given time in the Failures graph.

After successfully logging on to NetScaler Gateway, a user is not able to launch any virtual application
-
In NetScaler ADM, navigate to Gateway > Gateway Insight.
-
In the Overview section, select the time period for which you want to view the SSO errors. You can use the time slider to further customize the selected time period. Click Go.

-
Click the Application Launch tab. You can view the number of application launch failures at any given time in the Failures graph.

After successfully launching a new application, a user wants to view the total bytes and bandwidth consumed by that application
A user has logged on to NetScaler Gateway successfully, but is unable to access certain network resources in the internal network
-
In NetScaler ADM, navigate to Gateway > Gateway Insight > Applications.
-
On the screen that appears, scroll down, and on the Other Applications tab, select the application to which the user was unable to log on.

-
Scroll down and in the Users table, all the users that have access to that application are displayed.
Different users might be using different NetScaler Gateway deployments or might log on to NetScaler Gateway through different access modes. The administrator must be able to view details about the deployment types and access modes
-
In NetScaler ADM, navigate to Gateway > Gateway Insight.
-
In the Overview section, scroll down to view the Session Mode, Operating Systems, Browsers, and User Logon Activity charts display the different session modes used by users to log on, the types of clients, and the number of users logged on every hour.

