Session policies
-
Session policies always override global settings in the configuration.
-
Any attributes or parameters that are not set using a session policy are set on policies established for the virtual server.
-
Any other attributes that are not set by a session policy or by the virtual server are set by the global configuration.
Create a session policy
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > Policies and then click Session.
-
In the details pane, on the Policies tab, click Add.
-
In Name, type a name for the policy.
-
Next to Request Profile, click New.
-
In Name, type a name for the profile.
-
Complete the settings for the session profile and then click Create.
-
In the Create Session Profile dialog box, add an expression for the policy, click Create and then click Close. Note: In the expression, select True value so the policy is always applied to the level to which it is bound.
Sample session policy expressions
-
add vpn sessionPolicy sessPol1 "HTTP.REQ.HEADER(\"User-Agent\").CONTAINS(\"CitrixReceiver\") || HTTP.REQ.HEADER(\"User-Agent\").CONTAINS(\"CitrixWorkspace\")" sessAct1 -
add vpn sessionPolicy sessPol2 "HTTP.REQ.HEADER(\"User-Agent\").CONTAINS(\"CitrixReceiver\").NOT" sessAct2 -
add vpn sessionPolicy sessPol3 true sessAct3
Bind session policies
-
Users
-
Groups
-
Virtual servers
-
Globally
Bind a session policy to a virtual server by using the GUI
-
Navigate to NetScaler Gateway > Virtual Servers.
-
Select a virtual server and click Edit. You can also create a new virtual server.
-
Scroll down to the Policies section, and click the + icon.
-
In Choose Policy, select Session.
-
In Choose Type, select Request, and click Continue.
-
In Select Policy, select the policy that you want to bind to this virtual server.
-
In Priority, enter the priority number of the policy.
-
Click Bind.
Create a session profile
Configure network settings for user connections in a session profile
-
DNS server
-
WINS server IP address
-
Mapped IP address that you can use as an intranet IP address
-
Spillover settings for address pools (intranet IP addresses)
-
Intranet IP DNS suffix
-
HTTP ports
-
Forced time-out settings
Configure connection settings in a session profile
-
Access Interface or customized home page
-
Web address for web-based email, such as Outlook Web Access
-
plug-in type (Citrix Secure Access™ client for Windows, or Citrix Secure Access client for macOS X)
-
Split tunneling
-
Session and idle time-out settings
-
Clientless access
-
Clientless access URL encoding
-
plug-in type (Windows, or Mac)
-
Single sign-on to web applications
-
Credential index for authentication
-
Single sign-on with Windows
-
Client cleanup behavior
-
Logon scripts
-
Client debug settings
-
Split DNS
-
Access to private network IP addresses and local LAN access
-
Client choices
-
Proxy settings
-
The Citrix Secure Access client supports split DNS resolution for both TCP and UDP based DNS requests. DNS resolution works based on the split DNS setting as follows:
-
Remote: All DNS requests are resolved at the remote DNS server.
-
Local: DNS requests for host names matching the DNS suffix or tunneled applications are sent to the remote DNS server. DNS requests for other host names are sent to the local DNS server.
-
Both: All DNS requests matching the DNS suffix or tunneled applications are sent to the remote DNS server. DNS requests for other host names are sent to both local and remote servers and the first successful response is accepted.
-
-
Starting from the Citrix Secure Access client for Windows version 24.8.1.15, the split DNS feature is applicable to TCP based DNS requests in addition to UDP based requests.
-
Starting from Citrix Secure Access for Linux version 25.2.2, the split DNS feature (Remote, Local, and Both) is applicable to both TCP and UDP based DNS requests. The split DNS setting Both functions the same as the split DNS setting Local.
Configure security settings in a session profile
-
Default authorization action (allow or deny)
-
Secure Browse for connections from iOS devices
-
Quarantine groups
-
Authorization groups
Configure Citrix Virtual Apps and Desktops settings in a session profile
-
ICA Proxy, which is client connections using Citrix Workspace app
-
Web Interface address
-
Web Interface portal mode
-
Single sign-on to the server farm domain
-
Citrix Workspace app home page
-
Account Services Address
To create a session profile by using the GUI
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > Policies, and then click Session.
-
In the details pane, click the Profiles tab, and then click Add.
-
Configure the settings for the profile, click Create, and then click Close.
To add a profile to a session policy by using the GUI
-
In the configuration utility, in the navigation pane, expand Access Gateway > Policies and then click Session.
-
On the Policies tab, do one of the following:
-
Click Add to create a session policy.
-
Select a policy, and then click Open.
-
-
In Request Profile, select a profile from the list.
-
Finish configuring the session policy, and then do one of the following:
-
Click Create, and then click Close to create the policy.
-
Click OK, and then click Close to modify the policy.
-