Preauthentication policies and profiles
-
Expression. Includes the following settings to help you to create expressions:
-
Expression. Displays all expressions.
-
Match Any Expression. Configures the policy to match any of the expressions that are present in the list of selected expressions.
-
Match All Expressions. Configures the policy to match all the expressions that are present in the list of selected expressions.
-
Tabular Expressions. Creates a compound expression with the existing expressions by using the
OR (||) or AND (&&)operators. -
Advanced Free-Form. Creates custom compound expressions by using the expression names and the
OR (||) and AND (&&)operators. Choose only those expressions that you require and omit other expressions from the list of selected expressions. -
Add. Creates an expression.
-
Modify. Modifies an existing expression.
-
Remove. Removes the selected expression from the compound expressions list.
-
Named Expressions. Select a configured named expression. You can select named expressions from the menu of expressions already present on NetScaler Gateway.
-
Add Expression. Adds the selected named expression to the policy.
-
Replace Expression. Replaces the selected named expression to the policy.
-
Preview Expression. Displays the detailed string that is configured on NetScaler Gateway when you select a named expression.
-
Configure preauthentication profile
To configure a preauthentication profile globally by using the GUI
-
On the Configuration tab, click NetScaler Gateway, and then click Global Settings.
-
In the details pane, under Settings, click Change pre-authentication settings.
-
In the Global Pre-authentication settings dialog box, configure the settings:
-
In Action, select Allow or Deny.Denies or allows users to log on after the Endpoint Analysis occurs.
-
In Processes to be canceled, enter the process.This specifies the processes that the Endpoint Analysis plug-in must stop.
-
In Files to be deleted, enter the file name.This specifies the files that the Endpoint Analysis plug-in must delete. When you delete or cancel a process, a notification is displayed to the end users.

-
-
In Expression you can leave the expression ns_true or build an expression for a specific application, such as antivirus or security software, and then click OK.
To configure a preauthentication profile by using the GUI
-
Navigate to NetScaler Gateway > Policies > Authentication/Authorization, and then click Pre-Authentication EPA.
-
In the details pane, on the Profiles tab, click Add.
-
In Name, type the name of the application to be checked.
-
In Action, select ALLOW or DENY.
-
In Processes to be canceled, type the name of the process to be stopped.
-
In Files to be deleted, type the name of the file to be deleted, such as c:\clientext.txt, click Create, and then click Close.This specifies the files that the Endpoint Analysis plug-in must delete. When you delete or cancel a process, a notification is displayed to the end users.

Add a preconfigured expression to a preauthentication policy
Add a named expression to a preauthentication policy
-
Navigate to NetScaler Gateway > Policies > Authentication/Authorization, and then click Pre-Authentication EPA.
-
In the details pane, select a policy and then click Open.
-
Next to Named Expressions, select Anti-Virus, select the antivirus product from the list.
-
Click Add Expression, click Create, and then click Close.
Configure custom expressions
Create a preauthentication policy and custom expression
-
Navigate to NetScaler Gateway > Policies > Authentication/Authorization, and then click Pre-Authentication EPA.
-
In the details pane, click Add.
-
In Name, type a name for the policy.
-
Next to Request Profile, click New.
-
In the Create Authentication Profile dialog box, in Name, type a name for the profile and in Action, select Allow, and then click Create.
-
In the Create Pre-Authentication Policy dialog box, next to Match Any Expression, click Add.
-
In Expression Type, select Client Security.
-
Configure the following: a. In Component, select Anti-Virus. b. In Name, type a name for the application. c. In Qualifier, select Version. d. In Operator, select ==. e. In Value, type the value. f. In Freshness, type 3, and then click OK.
-
In the Create Pre-Authentication Policy dialog box, click Create, and then click Close.
Configure compound expressions
-
Symantec Antivirus 10
-
McAfee Antivirus 11
-
Sophos Antivirus 4
av_5_Symantec_10 || av_5_McAfeevirusscan_11 || av_5_sophos_4
Bind preauthentication policies
Create and bind a preauthentication policy globally
-
On the Configuration tab, click NetScaler Gateway, and then click Global Settings.
-
In the details pane, click Change pre-authentication settings.
-
In the Global Pre-Authentication Settings dialog box, in Action, select Allow or Deny.
-
In Name, type a name for the policy.
-
In the Global Pre-authentication settings dialog box, next to Named Expressions, select General, select True value, click Add Expression, click Create, and then click Close.
Bind a preauthentication policy to a virtual server
-
On the Configuration tab, click NetScaler Gateway, and then click Virtual Servers.
-
In the details pane, select a virtual server, and then click Open.
-
In the configure NetScaler Gateway Virtual Server dialog box, click the Policies tab, and then click Pre-authentication.
-
Under Details, click Insert Policy, and then under Policy Name, select the preauthentication policy.
-
Click OK.
Unbind and remove preauthentication policies
Unbind a global preauthentication policy
-
Navigate to NetScaler Gateway > Policies > Authentication/Authorization, and then click Pre-Authentication EPA.
-
In the details pane, select a policy and then in Action, click Global Bindings.
-
In the Bind/Unbind Pre-authentication Policies to Global dialog box, select a policy, click Unbind Policy, and then click OK.
Unbind a preauthentication policy from a virtual server
-
On the Configuration tab, click NetScaler Gateway, and then click Virtual Servers.
-
In the Configure NetScaler Gateway Virtual Server dialog box, click the Policies tab, and then click Preauthentication.
-
Select the policy and then click Unbind Policy.
Remove a preauthentication policy
-
Navigate to NetScaler Gateway > Policies > Authentication/Authorization, and then click Pre-Authentication EPA.
-
in the details pane, select a policy and then click Remove.
Set the priority of preauthentication policies
Change the priority of a preauthentication policy
-
On the Configuration tab, click NetScaler Gateway, and then click Virtual Servers.
-
In the details pane, select a virtual server, and then click Open.
-
On the Policies tab, click Pre-authentication.
-
Under Priority, type the priority number for the policy, and then click OK.