Preauthentication device check expressions for user devices
-
Antispam
-
Antivirus
-
File policies
-
Internet security
-
Operating system
-
Personal firewall
-
Process policies
-
Registry policies
-
Service policies
Configure antivirus, firewall, internet security, or antispam expressions
-
Component: The type of client security, such as antivirus, firewall, or registry entry.
-
Name: The name of the application, process, file, registry entry, or operating system.
-
Qualifier: The version or the value of the component for which the expression checks.
-
Operator: Checks if the value exists or is equal to the value.
-
Value: The application version for antivirus, firewall, Internet security, or antispam software on the user device.
-
Frequency: Frequency with which a post-authentication scan is run, in minutes.
-
Error weight: A weight assigned to each error message contained in a nested expression when multiple expressions have different error strings. The weight determines which error message appears.
-
Freshness: Defines how old a virus definition can be. For example, you can configure the expression so virus definitions are no older than three days.
To add a client device check policy to a preauthentication or session policy
-
In the configuration utility, in the navigation pane, do one of the following: a. In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > Policies and then click Session. b. In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > Policies > Authentication/Authorization, and then click Pre-Authentication EPA.
-
In the details pane, on the Policies tab, click Add.
-
In Name, type a name for the policy.
-
Next to Match Any Expression, click Add.
-
In the Add Expression dialog box, in Expression Type, select Client Security.
-
Configure the settings for the following: a. In Component, select the item for which to scan. b. In Name, type the name of the application. c. In Qualifier, select Version. d. In Operator, select the value. e. In Value, type the client device check string, click OK, click Create, and then click Close.
Configure service policies
To configure a service policy
-
In the configuration utility, in the navigation pane, do one of the following: a. In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > Policies and then click Session. b. In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > Policies > Authentication/Authorization, and then click Pre-Authentication EPA.
-
In the details pane, on the Policies tab, click Add.
-
In Name, type a name for the policy.
-
Next to Match Any Expression, click Add.
-
In the Add Expression dialog box, in Expression Type, select Client Security.
-
Configure the settings for the following: a. In Component, select Service. b. In Name, type the name of the service. c. In Qualifier, leave blank or select Version. d. Depending on your selection in Qualifier, do one of the following:
-
If left blank, in Operator, select == or \!=
-
If you selected Version, in Operator, in Value, type the value, click OK, and then click Close.
-
Configure process policies
To configure a process policy
-
In the configuration utility, in the navigation pane, do one of the following: a. In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway \ > Policies and then click Session. b. In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway \> Policies \ > Authentication/Authorization, and then click Pre-Authentication EPA.
-
In the details pane, on the Policies tab, click Add.
-
In Name, type a name for the policy.
-
Next to Match Any Expression, click Add.
-
In the Add Expression dialog box, in Expression Type, select Client Security.
-
Configure the settings for the following: a. In Component, select Process. b. In Name, type the name of the application. c. In Operator, select EXISTS or NOTEXISTS, click OK and then click Close.
Configure operating system policies
| Operating system | Value |
|---|---|
| macOS X | macOS |
| Windows 8.1 | win8.1 |
| Windows 8 | win8 |
| Windows 7 | win7 |
| Windows Vista | vista |
| Windows XP | winxp |
| Windows Server 2008 | win2008 |
| Windows Server 2003 | win2003 |
| Windows 2000 Server | win2000 |
| Windows 64-bit platform | win64 |
To configure an operating system policy by using the GUI
-
In the navigation pane, do one of the following: a. Navigate to NetScaler Gateway > Policies and then click Session. b. Navigate to NetScaler Gateway > Policies > Preauthentication.
-
In the details pane, on the Policies tab, click Add.
-
In Name, type a name for the policy.
-
In Request Action select an existing action or create one.
-
Click Expression Editor.
-
In Select Expression Type, select Client Security.
-
Configure the settings for the following: a. In Component, select Operating System. b. In Name, type the name of the operating system. c. In Qualifier, do one of the following:
-
Leave the field blank
-
Select Service Pack
-
Select Hotfix
-
Select Version (for macOS only) d. Depending on your selection in step 7, in Operator, do one of the following:
-
If Qualifier is blank, in Operator, select EQUAL (= =), NOTEQUAL (\!=), EXISTS or NOTEXISTS.
-
If you selected Service Pack or Hotfix, select the operator and in Value, type the value.
-
-
Click Done and then click Close.
(winxp).sp, if a number is not in the Value field, NetScaler Gateway returns an error message because the expression is invalid.
Configure registry policies
-
Four backslashes are used to separate keys and subkeys, such asHKEY\_LOCAL\_MACHINE\\\\\\\\SOFTWARE
-
Underscores are used to separate the subkey and the associated value name, such asHKEY\_LOCAL\_MACHINE\\\\\\\\SOFTWARE\\\\\\\\VirusSoftware\_Version
-
A backslash (\\) is used to denote a space, such as in the following two examples:HKEY\_LOCAL\_MACHINE\\\\\\\\SOFTWARE\\\\Citrix\\\\\\\\Secure\\ Access\\ Client\_ProductVersionCLIENT.REG(HKEY\_LOCAL\_MACHINE\\\\\\\\Software\\\\\\\\Symantec\\\\Norton\\ AntiVirus\_Version).VALUE == 12.8.0.4 -frequency 5
secureaccess).VALUE==HKEY\_LOCAL\_MACHINE\\\\\\\\SOFTWARE\\\\\\\\CITRIX\\\\\\\\Secure\\Access\\Client\_ProductVersion
-
HKEY\_CLASSES\_ROOT
-
HKEY\_CURRENT\_USER
-
HKEY\_LOCAL\_MACHINE
-
HKEY\_USERS
-
HKEY\_CURRENT\_CONFIG
-
StringFor the string value type, case-sensitivity is checked.
-
DWORDFor the DWORD type, the value is compared and must be equal.
-
Expanded StringOther types, such as Binary and Multi-String, are not supported.
-
Only the '==' comparison operator is supported.
-
Other comparison operators, such as \<, \> and case-sensitive comparisons are not supported.
-
The total registry string length must be less than 256 bytes.
To configure a registry policy
-
In the configuration utility, in the navigation pane, do one of the following: a. In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway \ > Policies and then click Session. b. In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway \> Policies \ > Authentication/Authorization, and then click Pre-Authentication EPA.
-
In the details pane, on the Policies tab, click Add.
-
In Name, type a name for the policy.
-
Next to Match Any Expression, click Add.
-
In the Add Expression dialog box, in Expression Type, select Client Security.
-
Configure the settings for the following: a. In Component, select Registry. b. In Name, type the name of the registry key. c. In Qualifier, leave blank or select Value. d. In Operator, do one of the following:
-
If Qualifier is left blank, select EXISTS or NOTEXISTS
-
If you selected Value in Qualifier, select either == or \!== e. In Value, type the value as it appears in the registry editor, click OK and then click Close.
-
Configure compound client device check expressions
-
And (&&)
-
Or (||)
-
Not (\!)
Configure policies with the AND (&&) operator
CLIENT.APPLICATION.AV(sophos).version==7.0 AND CLIENT.SVC(netlogon) EXISTS
CLIENT.APPLICATION.AV(sophos).version==7.0 && CLIENT.SVC(netlogon) EXISTS
Configure policies with the OR ( || ) operator
(||) operator works by combining two device check strings. The compound check passes when either check is true. The expression is evaluated from left to right and if the first check passes, the second check is not carried out. If the first check does not pass, the second check is carried out.
(||) operator using the keyword OR or the symbol ||.
c:\\file.txt on it or the putty.exe process running on it.
client.file(c:\\\\\\\\file.txt) EXISTS) OR (client.proc(putty.exe) EXISTS
client.file(c:\\\\\\\\file.txt) EXISTS) || (client.proc(putty.exe) EXISTS
Configure policies using the NOT (\!) operator
\!(client.file(c:\\\\\\\\sophos\_virus\_defs.dat).timestamp==2dy)