Citrix Secure Private Access™ Hybrid Deployment

Configure session policies

You can use a session policy to allow users to directly access back-end applications by bypassing NetScaler Gateway tunneling.

  1. Navigate to Policies > Session Policies and click Create Session Policy.

    Session policies

  2. Enter a name and a description of the policy.
  3. Select the users and conditions to which you want to apply these settings.

    You can apply the condition to all users or to a subset of users.

    For example, you can define the Network Location condition to enable dynamic routing for the entire session. This ensures that direct routing is enabled only when users are inside the company’s corporate network.

    When you add additional conditions based on a context, an AND operation is applied on the conditions, and the policy is evaluated only if both the users and the optional contextual-based conditions are met.

  4. Select Direct routing to send user traffic directly to the back-end applications without NetScaler Gateway tunneling.
  5. Select Enable policy after creation. If you do not select this option, the policy is only created and not enforced on the applications.

    Alternatively, you can also enable the policy from the Session Policies page by using the toggle switch in the Status column.

  6. Click Save.

Note:

Network location changes trigger session policy refreshes and this might impact the end clients as follows:

  • Citrix Secure Access client: Policy refreshes might alter routing configurations and hence impact application access.
  • Chrome Secure Browse extension: Policy refreshes occur every 30 minutes. Users must restart the browser or wait for the refresh to access applications.
Configure session policies

In this article