Endpoint Analysis
-
Endpoint Analysis is intended to analyze the user device against pre-determined compliance criteria and does not enforce or validate the security of end-user devices. It is recommended to use endpoint security systems to protect devices from local admin attacks.
-
The EPA client is available as a standalone client and is also bundled along with the Citrix Secure Access™ client. The Citrix® EPA client and Citrix Secure Access client are independent from each other.
How Endpoint policies work
-
Preauthentication policy that uses a Yes or No parameter. The scan determines if the user device meets the specified requirements. If the scan fails, the user cannot enter credentials on the logon page.
-
Session policy that is conditional and can be used for SmartAccess.
-
Client device check expression within a session policy. If the user device fails to meet the requirements of the Client device check expression, you can configure users to be placed into a quarantine group. If the user device passes the scan, users can be placed into a different group that might require other checks.
-
Examines an initial set of information about the user device to determine which scans to apply.
-
Runs all applicable scans. When users try to connect, the Endpoint Analysis plug-in checks the user device for the requirements specified within the pre-authentication or session policy. If the user device passes the scan, users are allowed to log on. If the user device fails the scan, users are not allowed to log on.Note: Endpoint Analysis scans complete before the user session uses a license.
-
Compares the property values detected on the user device with the desired property values listed in your configured scans.
-
Produces an output verifying whether the desired property values are found.
Sample EPA expressions
-
Windows:
-
Kill process:
sys.client_expr(\“proc_0_perl\“) -killProcess processToKill.exe -
Device certificate :
sys.client_expr(“device-cert_0_0”) -
Delete files :
sys.client_expr(\“proc_0_perl\“) -deletefiles “C:/removefile.txt”
-
-
MAC
-
Kill process:
sys.client_expr(\“proc_0_perl\“) -killProcess processToKill.exe -
Device cert:
sys.client_expr(“device-cert_0_0”) -
Delete files:
sys.client_expr(\“proc_0_perl\“) -deletefiles “C:/removefile.txt”
-
Evaluate user logon options
-
Configure the global settings with ICA® Proxy enabled and all other necessary settings if the specified application is not running on the user device.
-
Create a session policy and profile that enables the Citrix Secure Access client.
-
Create an expression within the rule portion of the session policy to specify the application, such as
(client.application.process(symantec.exe) exists)When users log on, the session policy is applied first. If Endpoint Analysis fails or the user skips the scan, NetScaler Gateway ignores the settings in the session policy (the expression in the session policy is considered false). As a result, users have restricted access using clientless access. If Endpoint Analysis passes, NetScaler Gateway applies the session policy and users have full access with the Citrix Secure Access client.
Skip the EPA scan
<https://support.citrix.com/article/CTX200748>.
Endpoint Analysis scans supported for Ubuntu
-
File
-
Existence: sys.client_expr("file_0_/home/user/test.txt")
-
MD5 Checksum: sys.client_expr("file_0_/home/user/test.txt_md5_ ce780e271debcc29f551546e8db3368f")
-
Text within a file (regular expression support): sys.client_expr("file_0_/home/user/test.txt_search_cloud”)
-
-
Process
-
Existence: sys.client_expr("proc_0_perl")
-
MD5 Checksum: sys.client_expr("proc_0_perl_md5_ c060d3a5f97e27066cef8c116785567a")
-
Path: sys.client_expr("proc_0_perl_path_/usr/bin/perl")
-
-
File system device or Mountpoint name: sys.client_expr("mountpoint_0_/sys”)
-
In the Expression Editor page, for the Linux client, you can select Common, and then select Process, File or Mount Point.
-
EPA scan for MAC addresses is not supported for Linux clients.