This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Monitor and troubleshoot network policies
Every network policy behavior feeds the Audit dashboard, which is your primary tool for understanding and fixing policy effects.
- Monitored traffic generates log events for all outgoing connections.
- Restricted traffic logs every blocked request, so you can see exactly which destination was denied.
- Inspected traffic reports inspected TCP content and dropped UDP traffic.
Find the traffic logs
Network events appear in the Audit dashboard for the project, in the Live system event log.
- Open Audit for the project. You need the Security permission set to Access or Manage.
- Find the network events, for example DNS requests showing the domain a workspace tried to reach.
- Select Filter to narrow the log by event type, severity, workspace, user, or date, or use the search bar to find a specific destination.
- Expand a row to see the event’s full details, including the description of what triggered it.
Use a monitor policy to build an allow list
A monitor-only policy is the recommended way to discover what a workspace needs before you lock it down.
- Apply the Monitor Traffic (default) policy, or any policy with restriction turned off, to the workspace.
- Use the workspace normally so its tools generate their usual network calls.
- In the audit log, review the network events to see which domains and IP addresses the workspace actually reached.
- Create a restrict policy and add those destinations to the allow list. See Build the allow list.
- Switch the workspace to the restrict policy. Any destination you missed now appears as a blocked request in the same audit log, so you can refine the allow list and repeat.
Tip:
Attached resources, such as repositories, SSH services, and HTTP services, are always reachable under a restrict policy. You do not need to add them to the allow list.
Common issues
An application cannot reach a service it needs
The destination is probably missing from the allow list. Check the Audit dashboard for the blocked request, then add the domain or IP address to the policy. If the service uses subdomains, turn on Include subdomains.
A tool that uses UDP stops working after a policy is applied
Any attached network policy — monitor, restrict, or inspect — drops non-DNS UDP traffic by design. DNS still works, but other UDP-based protocols do not. If a workload depends on UDP, it cannot run in a workspace that has a network policy attached.
See What happens when a policy is attached.
A workspace ignores the policy you selected
A parent scope is probably enforcing a different policy, or the policy was applied automatically from project settings. Check the network policy overview to see which scope enforces the inherited policy. Only security officers, organization owners, and project owners can change a workspace’s policy.
Related information
Share
Share
This Preview product documentation is Citrix Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Citrix Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Citrix product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.