Hardened Remote Access Infrastructure
Legacy VPNs grant excessive trust to user devices. Under the Zero Trust Security Model, access must be continuously authenticated and verified. This guide outlines configuring ZTNA on NetScaler Gateway.
1. nFactor Multi-Factor Authentication
Configure nFactor pipelines on NetScaler Gateway to run sequential authentication checks. Enforce Entra ID SAML authentication in the first factor, and run a secondary check for push notifications or security tokens.
2. Endpoint Posture Analysis (EPA)
Configure pre-authentication EPA policies on the gateway to scan user devices for compliant anti-virus software, enabled firewalls, and active registry checks before prompting for login.
3. Contextual Access Policies
Define dynamic session profiles that restrict file downloads, clipboard copying, and local drive mapping if users log in from personal devices or untrusted IP addresses.