Configure Access Scenario Fallback
-
If client choices are enabled, users can log on to StoreFront by using the Citrix Workspace app only.
-
If clientless access and client choices are disabled, users can be quarantined into a group that provides access only to StoreFront.
-
If clientless access and StoreFront are enabled on NetScaler Gateway and ICA Proxy is disabled, users fall back to clientless access.
-
If StoreFront is not configured and clientless access is set to allow, users fall back to clientless access.
-
Define client security parameters for the fallback post-authentication scan.
-
Define the Web Interface home page.
-
Disable client choices.
-
If user devices fail the client security check, users are placed into a quarantine group that allows access only to StoreFront and to published applications.
Create policies for Access Scenario Fallback
-
Create a quarantine group in which users are placed if the endpoint analysis scan fails.
-
Create a global StoreFront setting that is used if the endpoint analysis scan fails.
-
Create a session policy that overrides the global setting and then bind the session policy to a group.
-
Create a global client security policy that is applied if the endpoint analysis fails.
-
Using client choices or access scenario fallback requires the Endpoint Analysis plug-in for all users. If endpoint analysis cannot run or if users select Skip Scan during the scan, users are denied access. Note: The option to skip the scan is removed in NetScaler Gateway 10.1, Build 120.1316.e
-
When you enable client choices, if the user device fails the endpoint analysis scan, users are placed into the quarantine group. Users can continue to log on with either the Citrix Secure Access client or the Citrix Workspace app to StoreFront. Note: Citrix® recommends that you do not create a quarantine group if you enable client choices. User devices that fail the endpoint analysis scan are quarantined are treated in the same way as user devices that pass the endpoint scan.
-
If the endpoint analysis scan fails and the user is put in the quarantine group, the policies that are bound to the quarantine group are effective only if there are no policies bound directly to the user that have an equal or lower priority number than the policies bound to the quarantine group.
-
You can use different web addresses for the Access Interface and StoreFront. When you configure the home pages, the Access Interface home page takes precedence for the Citrix Secure Access client and the Citrix Workspace app home page takes precedence for StoreFront.
Create a quarantine group
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > User Administration, and then click AAA Groups.
-
In the details pane, click Add.
-
In Group Name, type a name for the group, click Create, and then click Close.Important:The name of the quarantine group must not match the name of any domain group to which users might belong. If the quarantine group matches an Active Directory group name, users are quarantined even if the user device passes the endpoint analysis security scan.
Configure settings to quarantine user connections
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway and then click Global Settings.
-
In the details pane, under Settings, click Change global settings.
-
In the Global NetScaler Gateway Settings dialog box, on the Published Applications tab, next to ICA Proxy, select OFF.
-
Next to Web Interface Address, type the web address for StoreFront.
-
Next to Single Sign-On Domain, type the name of your Active Directory domain, and then click OK.
Create a session policy for Access Scenario Fallback
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > Policies and then click Session.
-
In the details pane, click Add.
-
In Name, type a name for the policy.
-
Next to Request Profile, click New.
-
On the Published Applications tab next to ICA Proxy, click Override Global, select On, and then click Create.
-
In the Create Session Policy dialog box, next to Named Expressions, select General, select True value, click Add Expression, click Create, and then click Close.
Bind the session policy to the quarantine group
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > User Administration, and then click AAA Groups.
-
In the details pane, select a group, and then click Open.
-
Click Session.
-
On the Policies tab, select Session, and then click Insert Policy.
-
Under Policy Name, select the policy, and then click OK.
Create a global client security policy
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway and then click Global Settings.
-
In the details pane, under Settings, click Change global settings.
-
On the Security tab, click Advanced Settings.
-
In Client Security, enter the expression. For more information about configuring system expressions, see Configuring System Expressions and Configuring Compound Client Security Expressions
-
In Quarantine Group, select the group you configured in the group procedure, and then click OK.