Advanced Secure Private Access features
The following are some of the advanced features supported by Secure Private Access:
-
Advanced data center configuration: Secure Private Access hybrid deployment is supported in a multi-data center with multi-sites configuration using NetScaler GSLB in active-active site deployment with site persistency method for GSLB connection proxy. For details, see Advanced data center configuration.
-
Global server load balancing connection proxy: The global server load balancing (GSLB) connection proxy enables NetScaler Gateway to transparently detect misrouted requests and proxy them to the correct site without any user intervention. For details, see Global server load balancing connection proxy.
-
Configure a global server load balancer domain URL: To set up multi-site redundancy for Secure Private Access, you must configure a global server load balancer (GSLB) address. This address acts as a single entry point, routing users to a specific data center’s Secure Private Access gateway based on your traffic policies, such as static proximity. For details, see Configure a global server load balancer domain URL.
-
Context-based application routing: When an app is configured, routing types are defined for the application URL and its related domains or app destinations under app configuration. The routing type defined here applies to all users who have access to the app. However, there can be scenarios where admins want to route the same app differently based on user context. For example, an internal app URL or destination must be routed directly instead of via Secure Private Access when users are inside the corporate network. For details, seeContext-based application routing.
-
Discover domains or IP addresses accessed by end users: The Application Discovery feature helps an admin get visibility into the external and internal applications (HTTP/HTTPS and TCP/UDP apps) that are being accessed in an organization. This feature discovers and lists all the domains/IPs addresses, published or unpublished. Thus, admins can see what domains/IP addresses are getting accessed, by whom, and decide if they want to publish them as applications, providing access to those users. For details, see Discover domains or IP addresses accessed by end users.
-
Policy modeling tool: Admins can create multiple policies and assign these policies to multiple applications. As a result, it might become difficult for admins to understand the application access results for their end-users. That is, if the end-user is allowed or denied access based on the application and access policy configurations. The policy modeling tool (Access policies > Policy modeling) helps resolve these issues by giving the administrators full visibility into the expected application access result (allowed/allowed with restriction/denied). For details, see Policy modeling tool.
-
Configure Data Loss Prevention (DLP) policies: Access restrictions are configured in the Google Admin console for CEP. Access restrictions that were previously configured in the Secure Private Access console only apply to Citrix Enterprise Browser. When Google Chrome is the enterprise browser, access restrictions must be configured as policies and rules in the Google Admin console. For details, see Configure Data Loss Prevention (DLP) policies.
-
High availability deployments: You can configure high availability for Secure Private Access in just a few straightforward steps. For details, see High availability deployments.
-
Reset Secure Private Access configuration: If you have a Citrix Secure Private Access hybrid deployment with Citrix Enterprise Browser integration and you want to switch to Chrome Enterprise Premium, you can reset the Secure Private Access configuration. For details, see Reset Secure Private Access configuration.