Configuring Authorization Policies
-
Classic authorization policies are applied only on TCP traffic.
-
Advanced authorization policy can be applied on all types of traffic (TCP/UDP/ICMP/DNS).
-
To apply policy on UDP/ICMP/DNS traffic, policies must be bound at type UDP_REQUEST, ICMP_REQUEST, and DNS_REQUEST respectively.
-
While binding, if "type" is not explicitly mentioned or "type" is set to REQUEST, the behavior does not change from earlier builds, that is these policies are applied only to TCP traffic.
-
The policies bound at UDP_REQUEST do not apply for DNS traffic. For DNS, policies must be explicitly bound to DNS_REQUEST TCP_DNS is similar to other TCP requests.
-
Sample authorization policy expressions
-
add authorization policy athzPol1 "HTTP.REQ.USER.IS_MEMBER_OF(\"allowedGroup\")" ALLOW -
add authorization policy athzPol2 "CLIENT.IP.DST.BETWEEN(192.0.2.10,192.0.2.20)" DENY -
add authorization policy athzPol3 "HTTP.REQ.HOSTNAME.CONTAINS(\"portal-srv") || CLIENT.IP.DST.IN_SUBNET(192.0.2.0/25)" ALLOW
To configure an authorization policy by using the GUI
-
Navigate to NetScaler Gateway > Policies > Authorization.
-
In the details pane, click Add.
-
In Name, type a name for the policy.
-
In Action, select Allow or Deny.
-
In Expression, click Expression Editor.
-
To start to configure the expression, click Select and choose the necessary elements.
-
Click Done when your expression is complete.
-
Click Create.
To bind an authorization policy to a user by using the GUI
-
Navigate to NetScaler Gateway > User Administration.
-
Click AAA Users.
-
In the details pane, select a user and then click Edit.
-
In Advanced Settings, click Authorization Policies.
-
In Policy Binding page, select a policy or create a policy.
-
In Priority, set the priority number.
-
In Type, select the request type and then click OK.
To bind an authorization policy to a group by using the GUI
-
Navigate to NetScaler Gateway > User Administration.
-
Click AAA Groups.
-
In the details pane, select a group and then click Edit.
-
In Advanced Settings, click Authorization Policies.
-
In Policy Binding page, select a policy or create a policy.
-
In Priority, set the priority number.
-
In Type, select the request type and then click OK.