This message was deleted.
# citrix-netscaler
s
This message was deleted.
j
are you using adapative auth ?
k
EPA on NetScaler Gateway? ... one of the key things to decide is that if the EPA is ran pre-logon or post logon... I like the nFactor with this since you're able to do all sorts of things with it. I wouldn't say there's a best practice else than what are your requirements and then you need to meet them.
m
I need to determine trust level of the endpoint. So is it a corporate endpoint ? Is AV/sec tools are ut to dates? ...
@Jonathan Pitre It's an on-prem NS with AAA vservice with standard MFA AD+Radius factors.
j
Adaptive Auth can take care of that now, EPA is kinda legacy, if you are licensed to use Adaptive Auth, I would look into that instead of investing time and money into a dead technology. https://docs.citrix.com/en-us/citrix-daas/manage-deployment/adaptive-access/adaptive-authentication-service.html Sadly, I don't think it can be enabled for On-Prem deployments 😞
💯 1
c
Adaptive auth is a pair of ADCs that Citrix hosts for you - the EPA bits are all the same as on-prem. I assume that will eventually change but that's likely down the road a while.