Post authentication policies
Configure a post-authentication policy
To configure a post-authentication policy by using the GUI
-
Expand NetScaler Gateway > Policies and then click Session.
-
In the details pane, on the Policies tab, click Add.
-
In Name, type a name for the policy.
-
Next to Request Profile, click New.
-
In Name, type a name for the profile.
-
On the Security tab, click Advanced Settings.
-
Under Client Security, click Override Global, and then click New.
-
Configure the client device check expression, and then click Create.
-
Under Client Security, in Quarantine Group, select a group.
-
In Error Message, type the message you want users to receive if the post-authentication scan fails.
-
Under Authorization Groups, click Override Global, select a group, click Add, click OK, and then click Create.
-
In the Create Session Policy dialog box, next to Named Expressions, select General, select True value, click Add Expression, click Create, and then click Close.
Configure the frequency of post-authentication scans
Quarantine and authorization groups
Configuring Quarantine Groups
To configure the client device check expression for a quarantine group
-
Navigate to NetScaler Gateway > Policies and then click Session.
-
In the details pane, on the Policies tab, click Add.
-
In Name, type a name for the policy.
-
Next to Request Profile, click New.
-
In Name, type a name for the profile.
-
On the Security tab, click Advanced Settings.
-
Under Client Security, click Override Global, and then click New.
-
In the Client Expression dialog box, configure the client device check expression and, then click Create.
-
In Quarantine Group, select the group.
-
In Error Message, type a message that describes the problem for users and then click Create.
-
In the Create Session Policy dialog box, next to Named Expressions, select General, select True value, click Add Expression.
-
Click Create, and then click Close.
To configure a global quarantine group
-
Expand NetScaler Gateway and then click Global Settings.
-
In the details pane, under Settings, click Change global settings.
-
On the Security tab, click Advanced Settings.
-
In Client Security, configure the client device check expression.
-
In Quarantine Group, select the group.
-
In Error Message, type a message that describes the problem for users, and then click OK.