Configure clientless VPN access with NetScaler Gateway
-
Enabling clientless access either globally or by using a session policy bound to a user, group, or virtual server.
-
Selecting the web address encoding method.
-
Citrix Secure Access client. Users are allowed to log on by using the Citrix Secure Access client only.
-
Use the Citrix Secure Access client and allow access scenario fallback. Users log on to NetScaler Gateway with the Citrix Secure Access client. If the user device fails an endpoint analysis scan, users are permitted to log on using clientless access. When this occurs, users have limited access to network resources.
-
Allow users to log on using a Web browser and clientless access. Users can log on only by using clientless access and receive limited access to network resources.
How clientless VPN access policies Work
-
Outlook Web Access and Outlook Web App
-
SharePoint 2007
-
All other Web applications
-
They are configured automatically and cannot be changed.
-
Each policy is bound at the global level.
-
Each policy is not enforced unless you enable clientless access either globally or by creating a session policy.
-
You cannot remove or modify global bindings, even if you do not enable clientless access.
Enable clientless VPN access
-
On. Enables clientless access. If you disable client choices and you do not configure or disable StoreFront™, users log on by using clientless access.
-
Off. Clientless access is not enabled by default. Clientless access is enabled after users log on with the Citrix Secure Access client. If you disable client choices and you do not configure or disable StoreFront, users log on with the Citrix Secure Access client. If endpoint analysis fails when users log on, users receive the choices page with clientless access available.
-
Disabled. Clientless access is disabled. When you select Disabled, users cannot log on by using clientless access and the icon for clientless access does not appear on the choices page.
To enable clientless access globally
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway and then click Global Settings.
-
In the details pane, under Settings, click Change global settings.
-
On the Client Experience tab, next to Clientless Access, select ON, and then click OK.
To enable clientless access by using a session policy
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > Policies > Session.
-
In the details pane, on the Policies tab, click Add.
-
In Name, type a name for the policy.
-
Next to Request Profile, click New.
-
In Name, type a name for the profile.
-
On the Client Experience tab, next to Clientless Access, click Override Global, select On, and then click Create.
-
In the Create Session Policy dialog box, next to Named Expressions, select General, select True value, click Add Expression, click Create, and then click Close.
-
Click Create, and then click Close.
Encode the web address
-
Obscure. This uses standard encoding mechanisms to obscure the domain and protocol part of the resource.
-
Clear. The web address is not encoded and is visible to users.
-
Encrypt. The domain and protocol are encrypted by using a session key. When the web address is encrypted, the URL is different for each user session for the same web resource. If users bookmark the encoded web address, save it in the web browser and then log off, when users log on and try to connect to the web address again using the bookmark, they cannot connect to the web address. Note: If users save the encrypted bookmark in the Access Interface during their session, the bookmark works each time the user logs on.
Configure web address encoding globally
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway and then click Global Settings.
-
In the details pane, under Settings, click Change global settings.
-
On the Client Experience tab, next to Clientless Access URL Encoding, select the encoding level and then click OK.
Configure web address encoding by creating a session policy
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > Policies and then click Session.
-
In the details pane, on the Policies tab, click Add.
-
In Name, type a name for the policy.
-
Next to Request Profile, click New.
-
In Name, type a name for the profile.
-
On the Client Experience tab, next to Clientless Access URL Encoding, click Override Global, select the encoding level, and then click OK.
-
In the Create Session Policy dialog box, next to Named Expressions, select General, select True value, click Add Expression, click Create, and then click Close.
Create clientless access policies
Create a clientless access policy using default settings
-
In the configuration utility, on the navigation pane, expand NetScaler Gateway > Policies and then click Clientless Access.
-
In the details pane, on the Policies tab, click a default policy and then click Add.
-
In Name, type a new name for the policy, click Create, and then click Close.
Bind a clientless access policy to a virtual server
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway and then click Virtual Servers.
-
In the details pane, select a virtual server and then click Open.
-
In the configure NetScaler Gateway Virtual Server dialog box, click the Policies tab, and then click Clientless.
-
Click Insert Policy, select a policy from the list, and then click OK.
Create and evaluate clientless access policy expressions
-
In the configuration utility, on the navigation pane, expand NetScaler Gateway > Policies and then click Clientless Access.
-
In the details pane, on the Policies tab, click a default policy and then click Add.
-
In Name, type a name for the policy.
-
Next to Profile, click New.
-
In Name, type a name for the profile.
-
Configure the rewrite settings and then click Create.
-
In the Create Clientless Access Policy dialog box, under Expression, click Add.
-
In the Add Expression dialog box, create the expression, and then click OK.
-
In the Create Clientless Access Policy dialog box, click Evaluate, and if the expression tests as correct, click Create.