Secure Application Manager
secure application manager overview the secure application manager option provides secure, application level remote access to enterprise servers from client applications you may deploy two versions of the secure application manager windows version (psam) the windows version of the secure application manager is a windows based solution that enables you to secure traffic to individual client/server applications and application servers java version (jsam) the java version of the secure application manager provides support for static tcp port client/server applications, including enhanced support for citrix nfuse jsam also provides netbios support, which enables users to map drives to specified protected resources task summary configuring psam this section provides high level psam configuration steps these steps do not account for preliminary system configuration steps such as specifying the system's network identity or adding user ids to configure psam create resource profiles that enable access to client/server applications or destination networks, create supporting autopolicies as necessary, and assign the policies to user roles using settings in the users > resource profiles> sam pages of the admin console the following figure depicts configuring psam we recommend that you use resource profiles to configure psam (as described above) however, if you do not want to use resource profiles, you can configure psam using role and resource policy settings in the following pages of the admin console instead enable access to psam at the role level using settings in the users > user roles > role > general > overview page of the admin console specify which client/server applications and servers psam should intermediate using settings in the users > user roles > sam > applications page of the admin console specify which application servers' users can access through psam using settings in the users > resource policies > sam > access page of the admin console after enabling access to client/server applications and/or destination networks using psam resource profiles or roles and resource policies, you can modify general role and resource options in the following pages of the admin console (optional) configure role level options such as whether the system should automatically launch and upgrade psam using settings in the users > user roles > sam > options page of the admin console (optional) control ip based hostname matching at the resource level using settings in the users > resource policies > sam > options page of the admin console ensure that an appropriate version of psam is available to remote clients using settings in the maintenance > system > installers page of the admin console if you want to enable or disable client side logging for psam, configure the appropriate options through the system > configuration > security > client side logs tab of the admin console psam recommended operation ivanti recommends the following operation when using psam the isac client has a limit of 64 application sessions through a psam connection if this limit is exceeded, a log entry is displayed " maximum number of connection limit (64) reached for a user session , see kb https //hub ivanti com/s/article/kb44359?language=en us for information " psam supports client initiated udp and tcp traffic by process name, by destination hostname, or by destination address range\ port range except for passive ftp, psam only supports protocols that do not embed ip addresses in the header or payload w sam also supports unicast client initiated udp users must launch drive maps through psam in one of the following ways netuse at the command prompt, type net use \\\server\share /user\ username right click my computer > map network drive, or in windows explorer, go to tools > map network drive and select connect using a different username when using the psam access control list (acl), administrators should take extra precaution when granting access to hosts we recommend that administrators use the ip address instead of the hostname if the hostname is required for security purposes, administrators should try to include additional acls with the corresponding ip address or ip addresses for that hostname reverse dns lookups are not supported to run citrix nfuse through w sam, you must define a caching rule to cache launch asp files for example, configure the resource policy to server name 80,443/ launch asp and the caching option to cache (do not add/modify caching headers) when using psam on pocket pc, session roaming should be enabled when being used over gprs because the ip address of the phone may change when using psam on pocket pc, if you have multiple roles defined, select the merge settings for all assigned roles option under administrators > admin realms > realm > role mapping when using an external load balancer and accessing j sam or w sam persistence must be employed on the load balancer this persistence should be based on source ip or destination source, depending on the load balancer being used debugging psam issues you can use the secure application manager dialog box on an end user's system to view the psam status and a variety of details about the user's session for instance, the secure application manager dialog box displays the applications and servers that psam is configured to secure, event logs and winsock data for the user's session, and various system diagnostics and performance data this information can help you or a support representative debug any problems your users may encounter to access the secure application manager dialog box, users simply need to double click the psam icon on their windows task bars for more information about viewing information in the secure application manager dialog box, see the end user help system available from the help link in the end user console about psam resource profiles you can create two types of psam resource profiles psam application resource profiles these resource profiles configure psam to secure traffic to a client/server application when you create a psam application resource profile, the psam client intercepts requests from the specified client applications to servers in your internal network psam destination network resource profiles these resource profiles configure psam to secure traffic to a server when you create a psam destination network resource profile, the psam client intercepts requests from processes running on the client that are connecting to the specified internal hosts when creating psam resource profiles, note that the resource profiles do not contain bookmarks to access the applications and servers that psam intermediates, users must first launch psam and then launch the specified application or server using standard methods (such as the windows start menu or a desktop icon) when you enable jsam or psam through web rewriting autopolicies in the users > resource profiles > web applications/pages page of the admin console, the system automatically creates jsam or psam autopolicies for you you can only view these sam policies through the appropriate web resource profile not through the sam resource profile pages of the admin console creating psam client application resource profiles when you create a psam application resource profile, the psam client intercepts requests from the specified client applications to servers in your internal network to create a psam application resource profile in the admin console, choose users > resource profiles > sam > client applications the following figure depicts creating psam client application resource profiles click new profile from the type list, choose psam from the application list, select one of the following options custom when you select this option, you must manually enter your custom application's executable file name (such as telnet exe) additionally, you may specify this file's path and md5 hash of the executable file (although it is not required that you specify the exact path to the executable) if you enter an md5 hash value, psam verifies that the checksum value of the executable matches this value if the values do not match, psam notifies the user that the identity of the application could not be verified and does not forward connections from the application to the system lotus notes when you select this option, psam intermediates traffic from the lotus notes fat client application microsoft outlook when you select this option, psam intermediates traffic from the microsoft outlook application netbios file browsing when you select this option, psam intercepts netbios name lookups in the tdi drivers on port 137 citrix when you select this option, psam intermediates traffic from citrix applications you can only use psam to configure access to a standard application once per user role for example, you can enable one configuration of microsoft outlook and one configuration of lotus notes for the "users" role the system supports several mechanisms for intermediating traffic to the lotus notes, microsoft outlook, and citrix applications domain authentication select this option to allow integrated windows applications, such as file sharing, outlook, and so forth to authenticate to the domain controller when the client machine is part of a domain before using this option, you must specify domain controllers that are reachable through the system in the psam destination list so that ldap and kerberos traffic can be proxied and sent to the system configure a psam access control policy (acl) to allow access to all domain controllers enter a unique name and optionally a description for the resource profile the system displays this information in the client application sessions section of the end user home page in the autopolicy sam access control section, create a policy that allows or denies users access to the server that hosts the specified application the following figure depicts autopolicy sam access control if it is not already enabled, select the autopolicy sam access control check box in the resource field, specify the application server to which this policy applies you can specify the server as a hostname or an ip/netmask pair you may also include a port if you select domain authentication from the application list, enter your domain controller server addresses into the resource field you can add multiple domain controller servers if more than one is available when enabling auto policy for any client application for psam, avoid entering in the resource list since the access control policies are not restricted to that particular application this may result in other resources being accessed through client applications for which the access control policies are not defined from the action list, select allow to enable access to the specified server or deny to block access to the specified server click add click save and continue in the roles tab, select the roles to which the resource profile applies and click add the selected roles inherit the autopolicy created by the resource profile if it is not already enabled, the system also automatically enables the sam option in the users > user roles > select role > general > overview page of the admin console for all of the roles you select click save changes creating psam destination network resource profiles when you create a psam destination network resource profile, the psam client intercepts requests from processes running on the client to internal hosts when destinations (using either ip address or hostnames) are configured on the system, all dns and netbios names are resolved through the system to create a psam destination network resource profile in the admin console, choose users > resource profiles > sam > psam destinations click new profile enter a unique name and optionally a description for the resource profile in the psam destinations section, specify which servers you want to secure using psam and click add you can specify the servers as hostname or ip/netmask pairs you may also include a port select the create an access control policy allowing sam access to this server check box to enable access to the server specified in the previous step (enabled by default) click save and continue in the roles tab, select the roles to which the resource profile applies and click add the selected roles inherit the autopolicy created by the resource profile if it is not already enabled, the system also automatically enables the sam option in the users > user roles > role name > general > overview page of the admin console for all of the roles you select specifying applications and servers for psam to secure information in this section is provided for backwards compatibility we recommend that you secure traffic using psam resource profiles instead, since they provide a simpler, more unified configuration method use the applications tab to specify applications and servers for which psam secures traffic when psam downloads to a client pc, it contains the information you configure on the applications tab for the role after a user launches the secure application manager, psam intercepts requests from client applications to servers in your internal network and requests from processes running on the client to internal hosts you define these resources on the applications tab by configuring two lists psam supported applications list this list contains applications for which you want psam to secure client/server traffic between the client and the system psam allowed servers list this list contains hosts for which you want psam to secure client/server traffic between the client and the system to specify applications for which psam secures client/server traffic between the client and the system in the admin console, choose users > user roles >select role> sam > applications click add application enter the name of the application and, optionally, a description this information displays in the client application sessions section of the end user home page from the type list, choose one of the following options standard if you select this option, choose one the following applications from the application parameters section citrix when you select this option, psam intermediates traffic from citrix applications lotus notes when you select this option, psam intermediates traffic from the lotus notes fat client application microsoft outlook/exchange when you select this option, psam intermediates traffic from the microsoft outlook application netbios file browsing when you select this option, psam intercepts netbios name lookups in the tdi drivers on port 137 note that in order to access a share using psam with netbios, you need to explicitly specify the server's netbios name (alphanumeric string up to 15 characters) in two places on the add server page and in a sam resource policy (wildcards are currently not supported ) alternatively, you can enable the auto allow application servers option on the sam > options tab, and then the system automatically creates a sam resource policy that allows access to this server custom select this option to specify a custom client/server application then in the filename field, specify the name of the file's executable file optionally specify the file's path and md5 hash of the executable file if you enter an md5 hash value, psam verifies that the checksum value of the executable matches this value if the values do not match, psam notifies the user that the identity of the application could not be verified and does not forward connections from the application to the system click save change s or save + new configure a psam resource policy to specify to which enterprise resources (based on ip address/port combination) the system may send the application specifying servers for psam to secure to specify servers for which psam secures client/server traffic between the client and the system in the admin console, choose users > user roles > select role > sam > applications click add server enter the name of the server and, optionally, a description specify the server's hostname (the wild cards ' ' or '?' are accepted) or an ip/netmask pair specify multiple ports for a host as separate entries click save changes or save + new configure a psam resource policy to specify to which enterprise resources (based on ip address/port combination) the system may send a server request alternatively, you can enable the auto allow application servers option on the sam > options tab, and then the system automatically creates a sam resource policy that allows access to the specified server note that you need to enable this option before specifying the application or server; otherwise, you need to create a sam resource policy specifying applications that need to bypass psam the psam client comes pre configured with a list of "passthrough" applications bypass psam the psam client does not secure traffic for these applications in addition to bypassing these predefined applications, you may also specify additional applications that should bypass psam psam does not bypass applications on pocket ics and other handheld devices to specify applications for psam to secure in the admin console, choose users > user roles > select role > sam > applications click add bypass application the new bypass application page displays name the application and provide a description (optional) provide the file name (required) enter the absolute path to the application (optional) select save changes to add the bypass application to the list or save + new to save the bypass application and create another bypass application default bypass applications the psam client is preconfigured to bypass psam processing for the following applications apache exe apache licadmin exe vni exe lmgrd exe tnslsnr exe oracle exe agntsrvc exe onrsd exe pagntsrv exe encsvc exe agntsvc exe eisqlw\ exe sqlservr exe sqlmangr exe inetinfo exe xstart exe idsd exe dstermserv exe dscitrixproxy exe dsncservice exe dsnetworkconnect exe specifying role level psam options to specify psam options at the role level in the admin console, choose users > user roles > select role > sam > options if it is not already enabled, select the windows sam option at the top of the page under secure application manager options, configure the following options auto launch secure application manager if you enable this option, the system automatically launches the secure application manager when a user signs in if you do not select this option, users must manually start the secure application manager from the client applications sessions section of the end user home page although you configure the secure application manager to automatically launch when users sign into the device, users can override this setting through the preferences > applications page of the end user console if you or the end user disables psam from automatically launching, users need to manually start the secure application manager by clicking its link on the home page auto allow application servers if you enable this option, the system automatically creates a sam resource policy that allows access to the server specified in the psam application and server lists you may not see the auto allow option if you are using a new installation or if an administrator hides the option under windows sam options, configure the following options auto uninstall secure application manager select this option to automatically uninstall the secure application manager after users sign off prompt for username and password for intranet sites select this option to require users to enter their sign in credentials before connecting to sites on your internal network this option changes internet explorer's intranet zone setting so that internet explorer prompts the user for network sign in credentials whenever the user wants to access an intranet site auto upgrade secure application manager select this option to automatically download the secure application manager to a client machine when the version of secure application manager on the system is newer than the version installed on the client if you select this option, note the following the user must have administrator privileges in order for the system to automatically install secure application manager on the client if a user uninstalls secure application manager and then signs in to the system for which the auto upgrade secure application manager option is not enabled, the user no longer has access to secure application manager resolve only hostnames with domain suffixes in the device dns domains if this option is configured, psam filters dns requests (fqdns) and sends to the system only those dns requests that have a domain suffix in the list of dns domains configured on the network overview page this option is limited to resolution of fqdns only no filtering is applied to short names and netbios requests session start script and session end script if you want to run a batch, application, or win32 service file when the psam session starts or ends, enter the name and path for the file for example, if you want to terminate an application and then restart it, you may use pskill exe (a third party utility that terminates processes on local or remote systems) if you enable the session start script option or session end script option, note the following you must either install the specified file on your end user's computers or specify a path on an accessible network directory to ensure that the system can locate a file on different platforms, you can use windows variables, such as in a path such as %windir%\system32\log the file must invoke the psam launcher using the appropriate command line options click save changes specifying application servers that users can access information in this section is provided for backwards compatibility we recommend that you secure traffic using psam resource profiles instead, since they provide a simpler, more unified configuration method when you enable the secure application manager access feature for a role, you need to create resource policies that specify which application servers a user may access these policies apply to both the java version and windows version of the secure application manager (jsam and psam, respectively) when a user makes a request to an application server, the system evaluates the sam resource policies if the system matches a user's request to a resource listed in a sam policy, the system performs the action specified for the resource when writing a sam resource policy, you need to supply key information resources a resource policy must specify one or more resources to which the policy applies when writing a sam policy, you need to specify application servers to which a user may connect roles a resource policy must specify the roles to which it applies when a user makes a request, the system determines what policies apply to the role and then evaluates those policies that correspond to the request sam resource policies apply to users' requests made through either version, jsam or psam actions a secure application manager resource policy either allows or denies access to an application server you can create resource policies through the standard interface (as described in this section) or through resource profiles (recommended method) the engine that evaluates resource policies requires that the resources listed in a policy's resources list follow a canonical format to write a secure application manager resource policy in the admin console, choose users > resource policies > sam > access on the secure application manager policies page, click new policy enter a name to label this policy (required) and a description of the policy (optional) in the resources section, specify the application servers to which this policy applies in the roles section, specify policy applies to all roles choose this option to apply this policy to all users policy applies to selected roles choose this option to apply this policy only to users who are mapped to roles in the selected roles list make sure to add roles to this list from the available roles list policy applies to all roles other than those selected below choose this option to apply this policy to all users except for those who map to the roles in the selected roles list make sure to add roles to this list from the available roles list in the action section, specify allow socket access choose this option to grant access to the application servers specified in the resources list deny socket access choose this option to deny access to the application servers specified in the resources list use detailed rules choose this option to specify one or more detailed rules for this policy click save changes on the secure application manager policies page, order the policies according to how you want to evaluate them keep in mind that once the system matches the resource requested by the user to a resource in a policy's (or a detailed rule's) resource list, it performs the specified action and stops processing policies detailed rule after saving secure application manager resource policy you get a link to see and modify the detailed rule, do the following to modify rule on detailed rules page in the action section, specify allow socket access choose this option to grant access to the application servers specified in the resources list deny socket access choose this option to deny access to the application servers specified in the resources list allow socket access via proxy server this option configures proxy server details for selected psam resources or destinations, and maps these settings to specific user roles the proxy server facilitates only tcp traffic; udp traffic will bypass the proxy in the resources section, specify the application servers to which this policy applies under conditions, expand and select the prebuilt conditions list , your conditions , logical operators , variables , and click insert expression to add the string to the conditions box click save changes specifying resource level psam options use the options tab to specify the sam resource option to match ip addresses to hostnames specified as resources in your sam resource policies when you enable this option, the system looks up ip addresses corresponding to each hostname specified in a sam resource policy when a user tries to access a server by specifying an ip address rather than the hostname, the system compares the ip to its cached list of ip addresses to determine if a hostname matches an ip if there is a match, then the system accepts the match as a policy match and applies the action specified for the resource policy when you enable this option, the system compiles a list of hostnames specified in the resources field of each sam resource policy the system then applies the option to this comprehensive list of hostnames this option does not apply to hostnames that include wildcards and parameters to specify the sam resource option in the admin console, choose users > resource policies > sam > options select ip based matching for hostname based policy resources this option looks up the ip address corresponding to each hostname specified in a secure application manager resource policy when a user tries to access a server by specifying an ip address rather than the hostname, the system compares the ip to its cached list of ip addresses to determine if a hostname matches an ip if there is a match, then the system accepts the match as a policy match and applies the action specified for the resource policy click save changes proxy servers for psam connection ics now supports proxy server for connections to psam destination (tcp only) via proxy servers administrators can modify existing policies to route traffic through proxy servers, enhancing both security and scalability to specify the sam resource option in the admin console, choose users > resource policies > sam > proxy servers enter host address and port number click add to use the proxy servers and allow web traffic to bypass direction connection within your sam policy, you now have an additional option under actions docid\ iixfpddqb3weawsarzoal to allow socket access via the proxy server select resource policy > sam policy > (policy name) , and in the options tab, select "allow socket access via proxy server " you may also set proxy server usage within detailed rules docid\ iixfpddqb3weawsarzoal for more granular control select resource policy > sam policy > (policy name) > detailed rules , and select " allow socket access via proxy server " jsam overview the java version of the secure application manager provides support for static tcp port client/server applications, including enhanced support for citrix nfuse jsam also provides netbios support, which enables users to map drives to specified protected resources jsam works well in many network configurations but does not support dynamic port tcp based client/server applications, server initiated connections, or udp traffic regedit exe is required for some jsam functionality if regedit exe is disabled, automatic host mapping and the netbios applications will not work properly for information about the operating systems, web browsers, and jvms on which supports jsam, see the supported platforms guide https //www ivanti com/support/product documentation#97 task summary configuring jsam this topic provides high level jsam configuration steps these steps do not account for preliminary system configuration steps such as specifying the system's network identity or adding user ids to configure jsam create resource profiles that enable access to client/server applications, create supporting autopolicies as necessary, and assign the policies to user roles using settings in the users > resource profiles> sam pages of the admin console we recommend that you use resource profiles to configure jsam (as described above) however, if you do not want to use resource profiles, you can configure jsam using role and resource policy settings in the following pages of the admin console instead enable access to jsam at the role level using settings in the users > user roles > select role > general > overview page of the admin console specify which client/server applications jsam should intermediate using settings in the users > user roles > sam > applications page of the admin console specify which application servers' users can access through jsam using settings in the users > resource policies > sam > access page of the admin console after enabling access to client/server applications using jsam resource profiles or roles and resource policies, you can modify general role and resource options in the following pages of the admin console (optional) configure role level options such as whether the system should automatically launch jsam using settings in the users > user roles > sam > options page of the admin console (optional) control ip based hostname matching at the resource level using settings in the users > resource policies > sam > access page of the admin console if you want to enable or disable client side logging for jsam, configure the appropriate options through the system > configuration > security > client side logs tab of the admin console if you have multiple internal domains, such as company a com and company b com, add dns domains to the system using settings in the system > network > overview page of the admin console so that names such as app1 company a com and app2 company b com resolve correctly if a remote user's pc is set up to use a web proxy in internet explorer, configure the client machine to bypass the proxy server when the user launches applications that need to connect to the secure application manager enable jsam to associate ip loopback addresses with application servers on specific ports either by enabling jsam to edit the hosts file on your users' systems or by creating an external dns to route client application traffic to the jsam applet using jsam for client/server communications jsam provides secure port forwarding by directing client application traffic to the jsam applet running on a client machine to the client application running on the local machine, jsam appears as the application server to the application server in your network, the system appears as the client application the below figure illustrates the interaction between a client application and its server via ivanti connect secure (this figure assumes that the user specified a localhost ip address as the server in the client application ) the user starts a client application listed in the client application sessions section of the end user home page the application resolves the remote server to localhost the client application connects to jsam running on the user's machine and starts sending requests jsam encapsulates and forwards all client requests to the system over ssl the system unencapsulates the client data and forwards it to the specified application server the application server responds with data to the system the system encapsulates and forwards the response from the application server to jsam over ssl jsam unencapsulates the application server data and forwards it to the client application a status indicator on the jsam window shows the current state of jsam if green, jsam is working correctly if red, jsam is unable to send/receive requests to/from the system the jsam window updates the status indicator only when traffic is passed through jsam if no traffic is passed through jsam, the status indicator remains in its current state for example, if there is a network outage or if the user's session times out, the status indicator remains green even though it cannot send/receive requests to/from the system note the following if a remote user's pc is set up to use a web proxy in internet explorer, you must configure the client machine to bypass the proxy server when the user launches applications that need to connect to the secure application manager jsam allocates 20 30 mb of ram when running (the exact amount of memory depends on the java virtual machine (jvm) used) and, if caching is enabled, may leave a jar file on the client machine for more information about files left by jsam on client machines, see the client side changes guide on the support center users may experience problems waiting for the secure application manager to fully load if they enable pop up blockers through their web browsers this problem occurs because a pop up window alerting users to accept the secure application manager plug in may appear in the background (behind the web browser window) where users cannot see it when launching applications through jsam, supports configuration of 1200 unique ip/port combinations on windows and mac and 800 unique ip/port combinations on linux note that this limit is based on ip/port combinations, not applications (which may listen on more than one ip address and port) ivanti determined these numbers by testing on windows machines using default jre memory settings assigning ip loopback addresses to servers for jsam to function, it must listen on loopback addresses for client requests to network application servers the system assigns these unique ip loopback address to each application server that you specify for a given port for example, if you specify app1 mycompany com, app2 mycompany com app3 mycompany com, for a single port, the system assigns a unique ip loopback address to each application 127 0 1 10, 127 0 1 11, 127 0 1 12, when the system installs jsam on a user's machine, jsam listens on the loopback addresses (on the corresponding client port specified for the application server) for client requests to network application servers you can configure the system to dynamically assign these loopback addresses, or you can configure static loopback addresses yourself through the admin console you must enable these associations between ip loopback addresses and applications servers on a specific port in one of two ways allow the system to edit the hosts file on the client system with ip loopback assignments the system makes a copy of the current hosts file and then creates a new hosts file with the ip loopback assignments when the user ends the session, the system deletes the new hosts file and restores the original hosts file if the client system shuts down unexpectedly, the hosts file still points the client to loopback addresses for outside connections settings in the hosts file are returned to their original state when the client system reboots users must have the proper privileges on their machines in order for the system to edit the hosts file create an external dns to route client application traffic to the jsam applet using static loopback addresses using an external dns server with dynamic loopback addresses requires an administrator to update the dns settings each time the jsam application configuration changes on the other hand, configuring an external dns server using static loopback addresses provides administrators with the highest degree of configuration control for example, consider the following ip loopback assignments app1 mycompany com 127 0 1 10 app2 mycompany com 127 0 1 11 app3 mycompany com 127 0 1 12 if you configure an external dns server using dynamic loopback address assignments and you delete the first application server, the address assignments change app2 mycompany com 127 0 1 10 app3 mycompany com 127 0 1 11 with static ip loopback addresses in an external dns, deleting the first application server does not affect the ip loopback assignments for the remaining application servers app2 mycompany com 127 0 1 11 app3 mycompany com 127 0 1 12 you can assign static ip loopback addresses when creating a jsam custom resource profile through the users > resource profiles > sam > client applications page of the admin console or when enabling jsam applications through the users > user roles > select role > sam > applications page of the admin console if you assign a static ip loopback address while creating a new application, the system checks the address for conflicts against other configured applications in the same role if another application uses the same address, the system displays an error message prompting you to enter a different ip address static ip loopback addresses apply only to application servers configured by an administrator the system assigns dynamic ip loopback addresses for user defined application servers if the administrator does not assign an ip loopback address to an application server, the system assigns a dynamic address ip loopback address considerations when merging roles ip loopback address considerations when merging roles if two or more roles map to the same application and each mapping contains a different static ip loopback address, all of the static ip loopback addresses remain unchanged if two or more roles map to the same application and only one role uses a static ip loopback address, jsam uses only the static ip loopback address and binds to only one statically defined socket on the client if two or more roles map to the same application using dynamic ip loopback addresses, only one dynamic ip loopback address is used the application listener binds to only one dynamically assigned socket on the client if you use the same hostname in multiple roles, either use the same static ip loopback address, or dynamic addresses for all the applications if you use different hostnames associated with the same loopback address and port combination, jsam cannot distinguish between the two different hosts at the back end and, hence, cannot accurately direct ip traffic bound for those hosts resolving hostnames to localhost for jsam to successfully intermediate traffic, a client application on the user's machine needs to resolve the application server to the client localhost this process enables jsam to capture and securely port forward the data intended for the application server via ivanti connect secure jsam can perform automatic host mapping, in which it edits the client's hosts file, to map application servers to localhost (you can enable automatic host mapping through the users > user roles > select role > sam > options page of the admin console ) in order for jsam to edit a user's hosts file, the user must have the appropriate authority on the client machine windows users using the fat file system may belong to any user group for exchange mapi support, however, users must have at least power user privileges on their machines windows users using the ntfs file system must have administrator privileges on their machines linux (redhat) users must launch the browser that will launch jsam as root macintosh users must supply the administrator password when prompted by jsam if users do not have the appropriate privileges on their machines, jsam cannot automatically edit the hosts file, preventing hostname resolution to localhost alternatives for users who do not have the appropriate privileges are you configure your external dns server to resolve application servers to localhost if you configure your external dns server to use a localhost address instead of the application server hostname, remote users need to configure the order in which their machine searches dns servers to start with the corporate dns you relax the permissions on the etc directory and the etc\hosts file to enable jsam to make the necessary modifications users configure a client application to use the localhost address assigned by the system where they typically specify the application server hostname in the client application configuring a pc that connects through a proxy web server if a remote user's pc is set up to use a web proxy in internet explorer, you must configure the client machine to bypass the proxy server and contact the secure application manager instead to configure a pc that connects to the system through a web proxy in internet explorer from the internet explorer tools menu, choose internet options on the connections tab, click the lan settings button under proxy server, click the advanced button under exceptions, enter the addresses for which you do not want to use a proxy server enter all addresses (hostnames and localhost) that the client application uses when connecting through the secure application manager for example if your application server is app1 company com, enter the following exceptions app1;app1 company com;127 0 0 1 ivanti connect secure clients parse internet explorer's static proxy exception list we support most exceptions that internet explorer supports with the following limitations for ip address exception, we support n , n n , n n n for example, 10 , 10 10 , 10 10 10 , or 10 10 10 10 we do not support 10 or 10 10 even though internet explorer may support them for string expression, we support specific strings such as my company net,or a wild card at front of the string, for example, my company net or company net we do not support company , company , company com, net, com and so forth determining the assigned loopback address users cannot modify the corporate dns server for applications they add for port forwarding if you allow users to specify applications for jsam to proxy, users need to configure a client application to use the localhost address assigned by the system where they typically enter the server hostname the details pane of the jsam browser window displays the loopback ip address assigned by the system along with the port specified by the user to determine what ip address the system assigns to an application specified through the client applications page, a user must restart the secure application manager after adding the application the loopback address assigned to the application appears on the details pane of the secure application manager browser window in the client application, the user needs to enter the system assigned loopback address as the application server for example, if a user wants to access a telnet server behind your corporate firewall, the user needs to follow these steps in the client application sessions section of the end user home page, click the item properties icon, then click add application on the add application page, specify the server's fully qualified domain name or ip address in the remote server field, such as terminalserver ivanti com the port on which jsam should listen for client traffic to the server in the client port field, such as 3389 the port on which the remote server should listen for traffic from the client application (jsam) in the server port field, such as 3389 click add to save the information close the secure application manager browser window in the client application sessions section of the end user home page, click start to restart the secure application manager in the secure application manager browser window, click details on the details tab, look at which loopback address is assigned to the remote server, such as 127 0 1 18 in the client application, such as remote desktop connection, specify the loopback address in the configuration field for the server this field appears in different places for different applications users may enter this information through a setup wizard or other configuration dialog configuring external dns servers and user machines client applications must resolve server hostnames to jsam, which proxies data between a client and a server on windows pcs, server hostnames are stored in the hosts file to intercept data using jsam, the server names in the hosts file need to resolve to the local machine (localhost) so that the system can intermediate the traffic the recommended process for mapping application servers to a user's local pc is to enable the automatic host mapping option, which enables the system to automatically modify the pc hosts file to point application servers to the localhost for secure port forwarding for the system to perform automatic host mapping, however, pc users must have the proper privileges on their machines if your pc users do not have these privileges, you must ensure that your internal application server names resolve externally to a pc's localhost by adding entries to your external internet facing dns server such as 127 0 0 1 app1 company a com 127 0 0 1 app2 company b com if the client application uses an unqualified name for the application server, users need to specify dns suffixes so that the pc can attach the suffix and contact your external dns server for name resolution to configure a user pc with dns suffixes (windows 2000) from the windows start menu, choose settings > network and dial up connections > local area connection and then choose properties select internet protocol (tcp/ip) and then click properties click advanced and then click the dns tab click append these dns suffixes and then click add add your enterprise's internal domains as additional dns suffixes standard application support citrix web interface for metaframe (nfuse classic) remote users can use the citrix web interface for metaframe server to access a variety of applications via ivanti connect secure this process does not require any alterations to the user permissions on the client after a user browses to a citrix web interface for metaframe server and selects an application, the server sends an ica file to the client when the system rewrites the ica file, it replaces hostnames and ip addresses with pre provisioned loopback ip addresses the ica client then sends application requests to one of the loopback ip addresses the secure application manager encapsulates the data and sends it to the system the system unencapsulates the data and sends it to the appropriate metaframe server using port 1494 or 2598 (depending on the client) note the following the system supports several mechanisms for intermediating traffic between a citrix server and client, including the terminal services, jsam, psam, and vpn tunneling features jsam does not automatically launch when embedded applications are set to "auto" in the citrix web interface for metaframe console in these cases, we recommend that you configure jsam to automatically launch after the user signs into the device otherwise, end users must manually launch jsam before using citrix web interface for metaframe if a user attempts to use the server discovery feature and then attempts to use application discovery, the application discovery process fails to resolve this particular situation, shut down and restart citrix program neighborhood the system serves as an alternative to deploying the citrix secure gateway (csg) to use the applet mode of the java client, make sure to enable java applet support on the users > user roles > role name > web > options page of the admin console if you set the network protocol setting in the citrix program neighborhood client to tcp/ip, the system does not support the application through jsam since the tcp/ip setting produces udp traffic enabling citrix published applications on the citrix native client when enabling citrix published applications on the citrix native client through the system, you must complete the following steps specify custom application on jsam to port forward configure the citrix metaframe server for published applications configure the citrix client for published applications note the following these instructions assume that you are not using the citrix web interface for citrix presentation server (formerly known as nfuse server) these instructions do not cover how to configure the standard citrix application option (for standard citrix application instructions, use settings in the users > resource profiles > web > web applications/pages page of the admin console ) you can enable both the standard citrix application and the custom citrix application these settings do not impact each other the system supports several mechanisms for intermediating traffic between a citrix server and client, including the terminal services, jsam, psam, and vpn tunneling features specifying custom applications on jsam to port forward when configuring jsam to work with published applications, you must open two port ports 80 and 1494 each opened port creates a connection through jsam to the citrix metaframe server to specify published applications for jsam to port forward add a custom application through jsam when adding the custom application, keep the following settings in mind server name for published applications, you must enter the metaframe server's fully qualified dns name, not its ip address server port for published applications, enter 80 and 1494 (create one entry for port 80 and another for port 1494 ) if you have multiple metaframe servers, you must configure all of them on the same ports client port for published applications, enter 80 and 1494 (create one entry for port 80 and another for port 1494 ) if you have multiple internal domains, such as company a com and company b com, add dns domains to the system using settings in the system > network > overview page of the admin console so that names such as app1 company a com and app2 company b com resolve correctly if a remote user's pc is set up to use a web proxy in internet explorer, configure the client machine to bypass the proxy server when the user launches applications that need to connect to the secure application manager enable jsam to associate ip loopback addresses with application servers on specific ports either by enabling jsam to edit the hosts file on your users' systems or by creating an external dns to route client application traffic to the jsam applet configuring the citrix metaframe server for published applications when enabling citrix published applications through the system, you must enable the xml service dns address resolution on the metaframe server the following instructions describe how to do this on metaframe xp to configure the citrix metaframe server to work with the system open the citrix management console right click on the name of your server farm and click properties select the metaframe settings tab select the enable xml service dns address resolution check box click ok configuring the citrix client for published applications when enabling citrix published applications through the system, you must create an ica connection on each citrix client using the instructions that follow to configure the citrix client to work with the system open the citrix program neighborhood and choose the add ica connection option in the add new ica connection wizard, select the connection type that your computer uses to communicate in the next screen enter a description of the new ica connection select tcp/ip + http as the network protocol select published application click server location, and then deselect the use default check box click add in the locate server or published application dialog box confirm that http/https is selected from the network protocol list enter the metaframe server dns in the add server location address dialog box enter 80 in the port field click ok in the add server location address dialog box and the locate server or published application dialog box select an application from the published application list enter information in the remaining wizard screens as prompted enabling citrix secure gateways when enabling citrix secure gateways (csgs) through the system, you must disable citrix nfuse as a standard application through the users > resource profiles > web > web applications/pages page of the admin console you cannot enable the citrix nfuse standard application and citrix secure gateways (csgs) custom applications through jsam on the same device the system supports several mechanisms for intermediating traffic between a citrix server and client, including the terminal services, jsam, psam, and vpn tunneling features specify applications for jsam to port forward by adding a custom application through jsam when adding the custom application, keep the following settings in mind server name for csgs, you must enter the citrix secure gateway server's fully qualified dns name, not its ip address server port for csgs, enter 443 if you have multiple citrix secure gateway servers, you must configure all of them on the same port client port for csgs, enter 443 (create one entry for port 80 and another for port 443 ) if you have multiple internal domains, such as company a com and company b com, add dns domains to the system using settings in the system > network > overview page of the admin console so that names such as app1 company a com and app2 company b com resolve correctly if a remote user's pc is set up to use a web proxy in internet explorer, configure the client machine to bypass the proxy server when the user launches applications that need to connect to the secure application manager enable jsam to associate ip loopback addresses with application servers on specific ports either by enabling jsam to edit the hosts file on your users' systems or by creating an external dns to route client application traffic to the jsam applet setup your citrix secure gateway and confirm that it works on your desktop add a bookmark to the end users' home page that points to the list of citrix secure gateway servers and use the selective rewrite feature to turn off rewriting for the url or, if you do not want to create a bookmark through the system, simply instruct users to access the url using their web browser's address bar instead of the system address bar creating a jsam application resource profile jsam resource profiles configure jsam to secure traffic to a client/server application when you create a jsam application resource profile, the jsam client tunnels network traffic generated by the specified client applications to servers in your internal network when creating jsam resource profiles, note that the resource profiles do not contain bookmarks therefore, end users will not see a link for the configured application in the end user interface to access the applications and servers that jsam intermediates, users must first launch jsam and then launch the specified application using standard methods (such as the windows start menu or a desktop icon) also note that when you enable jsam or psam through rewriting autopolicies for web resource profiles, the system automatically creates jsam or psam autopolicies for you you can only view these sam policies through the appropriate web resource profile not through the sam resource profile pages of the admin console to create a jsam application resource profile in the admin console, choose users > resource profiles > sam > client applications click new profile from the type list, choose jsam from the application list, select one of the following options custom select this option to intermediate traffic to a custom application then in the server name field, enter the name or ip address of the remote server if you are using automatic host mapping, enter the server as it is known to the application if you enter an ip address, note that end users must connect to jsam using that ip address in order to connect to the specified server in the server port field, enter the port on which the remote server listens for client connections for example, to forward telnet traffic from a remote machine, specify port 23 for both the client port (on which jsam listens) and the server port (on which the telnet server listens) to disable the registry change made by jsam and restore the original copy of the etc/hosts file, users must uninstall the jsam client using settings in the preferences > applications page of the end user console to re enable the change, they need to reboot you can also use the restore system settings script however, the restore system settings script cannot restore the hosts file successfully if you log in as a different user from the one that originally launched jsam in the client loopback ip field, provide a static loopback address if you do not provide a static ip loopback address, the system assigns an ip loopback address dynamically when configuring an external dns, do not use ip loopback addresses in the 127 0 2 x range because the system reserves ip loopback addresses in that range for use with citrix nfuse if you want to modify a static loopback address for a jsam application server configured on multiple ports, you must delete all applications referring to this application server and re enter these applications with the new static loopback address in the client port field, enter the port on which jsam should listen for client application connections typically, the local port value is the same value as the server port; the local port value usually only differs for linux or macintosh non root users who want to add applications for port forwarding that use ports under 1024 you may configure more than one application on a single port, such as app1 mycompany com, app2 mycompany com, app3 mycompany com either you assign a static loopback address or the system assigns a dynamic loopback address (127 0 1 10, 127 0 1 11, 127 0 1 12) to each application jsam then listens on these multiple loopback addresses on the specified port for example, when there is traffic on 127 0 1 12 on the specified port, the system forwards the traffic to the app3 mycompany com destination host click add select the allow jsam to dynamically select an available port if the specified client port is in use check box if jsam is listening for multiple hosts on the same port and you want jsam to select an available port when the client port you specify is taken the client application must allow you to specify the port number for the connection in order to use this option select the create an access control policy allowing sam access to these servers check box to enable access to the list of servers specified in the server column (enabled by default) netbios file browsing select this option to tunnel netbios traffic through jsam then enter the fully qualified hostname for your application servers in the servers field you must enter the full name of the servers in this field since the system creates direct one to one mappings between the servers you enter here and ip addresses in the etc/hosts file for more information about registry changes made by jsam, see the client side changes guide on the support center if you want to enable drive mapping on a windows client machine, use the standard netbios file browsing option when you do, jsam automatically modifies the registry to disable port 445 on windows machines, which forces windows to use port 137, 138, or 139 for drive mapping windows users need to reboot one time to enable the registry change to take effect select the create an access control policy allowing sam access to this server check box to enable access to the server specified in the previous step (enabled by default) you can only use jsam to configure netbios file browsing once per user role the system does not support netbios file browsing through svw, since netbios requires hklm registry key changes enter a unique name and optionally a description for the resource profile the system displays this information in the client application sessions section of the end user home page click save and continue in the roles tab, select the roles to which the resource profile applies and click add the selected roles inherit the autopolicy created by the resource profile if it is not already enabled, the system also automatically enables the sam option in the users > user roles > role name > general > overview page of the admin console for all of the roles you select click save changes specifying applications for jsam to secure information in this section is provided for backwards compatibility we recommend that you secure traffic using jsam resource profiles instead, since they provide a simpler, more unified configuration method to specify applications for jsam to secure in the admin console, choose users > user roles > select role > sam > applications select add application enter the name of the application and, optionally, a description this information displays in the client application sessions section of the end user home page choose either standard application select citrix nfuse, or netbios file browsing the system does not support the standard jsam applications outlook and netbios file browsing through svw, since these applications require registry key changes however, the system does support the citrix and lotus notes jsam standard applications through svw custom application in the server name field, enter the dns name of the server or the server ip address if entering the dns name, enter name of the remote server as it is known to the application if you are using automatic host mapping enter the server name in the server port field, enter the port on which the remote server listens for client connections for example, to forward telnet traffic from a remote machine, specify port 23 for both the client port (on which jsam listens) and the server port (on which the telnet server listens) to disable the registry change made by jsam and restore the original copy of the etc/hosts file, users must uninstall the jsam client using settings in the preferences > applications page of the end user console to re enable the change, they need to reboot you can also use the restore system settings script however, the restore system settings script cannot restore the hosts file successfully if you log in as a different user from the one that originally launched jsam in the client loopback ip field, provide a static loopback address if you do not provide a static ip loopback address, the system assigns an ip loopback address dynamically when configuring an external dns, do not use ip loopback addresses in the 127 0 2 x range because the system reserves ip loopback addresses in that range for use with citrix nfuse if you want to modify a static loopback address for a jsam application server configured on multiple ports, you must delete all applications referring to this application server and re enter these applications with the new static loopback address in the client port field, enter the port on which jsam should listen for client application connections typically, the local port value is the same value as the server port; the local port value usually only differs for linux or macintosh non root users who want to add applications for port forwarding that use ports under 1024 you may configure more than one application on a single port, such as app1 mycompany com, app2 mycompany com, app3 mycompany com either you assign a static loopback address or the system assigns a dynamic loopback address (127 0 1 10, 127 0 1 11, 127 0 1 12) to each application jsam then listens on these multiple loopback addresses on the specified port for example, when there is traffic on 127 0 1 12 on the specified port, the system forwards the traffic to the app3 mycompany com destination host select the allow secure application manager to dynamically select an available port check box if jsam is listening for multiple hosts on the same port and you want jsam to select an available port when the client port you specify is taken the client application must allow you to specify the port number for the connection in order to use this option click add if a remote user's pc is set up to use a web proxy in internet explorer, configure the client machine to bypass the proxy server when the user launches applications that need to connect to the secure application manager add dns domains to the system if you have multiple internal domains, such as company a com and company b com, so that names such as app1 company a com and app2 company b com resolve correctly in the admin console, choose system > network > overview under dns name resolution, add a comma separated list of domains in the to dns domains field click save changes specifying role level jsam options to specify jsam options at the role level in the admin console, choose users > user roles > select role > sam > options under secure application manager options, select the options to enable for users auto launch secure application manager select this option to automatically launches the secure application manager when a user signs in if you do not select this option, users must manually start the secure application manager from the client applications sessions section of the end user home page although you configure the secure application manager to automatically launch when users sign into the system, users can override this setting through the preferences > applications page of the end user console if disabled from automatically launching, users need to manually start the secure application manager by clicking its link on the home page auto uninstall secure application manager select this option to automatically uninstall the secure application manager after users sign off auto allow application servers select this option to automatically creates a sam resource policy that allows access to the server specified in the psam application and server lists and the jsam application list you may not see the auto allow option if you are using a new installation or if an administrator hides the option under java sam options, select the options to enable for users user can add applications if enabled, users can add applications for users to add applications, they need to know the application server dns name and client/server ports when you enable this option, users can set up port forwarding to any host or port in your enterprise before providing users with the ability to add applications, please verify that this feature is consistent with your security practices if a user adds an application, the application remains available to the user even if you later change disable the feature automatic host mapping if enabled, the secure application manager edits the windows pc hosts file and replaces entries of windows application servers with localhost these entries are changed back to the original data when a user closes the secure application manager for the java version of the secure application manager to work, the client application needs to connect to the local pc on which the secure application manager is running as the application server the recommended process for mapping application servers to a user's local pc is to enable automatic host mapping, which enables the system to automatically modify the pc's hosts file to point application servers to the pc's localhost for secure port forwarding alternatively, you can configure your external dns server skip web proxy registry check if enabled, jsam does not check a user's registry for a web proxy some users do not have permissions to look at their registries, so if jsam tries to look at their registries, then users see an error that they do not have permission this option ensures that users do not see this message auto close jsam window on sign out if enabled, jsam automatically closes when a user signs out of the device by clicking sign out in the browser window jsam continues to run if the user simply closes the browser window click save changes automatically launching jsam use the launch jsam tab to write a web resource policy that specifies a url for which the system automatically launches jsam on the client the system launches jsam in two scenarios when a user enters the url in the address field of the home page when a user clicks a web bookmark (configured by an administrator) on the home page to the url this feature is useful if you enable applications that require jsam but don't want to require users to run jsam unnecessarily this feature requires, however, that users access the url through the home page if users enter the url in a browser address field, the system does not serve the request the system provides tight integration with citrix if you specify citrix as a standard jsam application, the system automatically launches jsam when a user selects an ica file even if the url is not configured as a resource policy to write a launch jsam resource policy in the admin console, choose users > resource policies > web if your administrator view is not already configured to show launch jsam policies, make the following modifications click the customize button in the upper right corner of the page select the launch jsam check box click ok select the launch jsam tab on the jsam autolaunch policies page, click new policy enter a name to label this policy (required) and a description of the policy (optional) in the resources section, specify the urls to which this policy applies the resource policies configured for the jsam auto launch policy must be a specific url and not include wildcards the url should specify the entry point of the web application for which jsam tunneling is needed in the roles section, specify policy applies to all roles choose this option to apply this policy to all users policy applies to selected roles choose this option to apply this policy only to users who are mapped to roles in the selected roles list make sure to add roles to this list from the available roles list policy applies to all roles other than those selected below choose this option to apply this policy to all users except for those who map to the roles in the selected roles list make sure to add roles to this list from the available roles list in the action section, specify launch jsam for this url the system downloads the java secure application manager to the client and then serves the requested url jsam launches automatically for the specified url only if a user enters the url or selects a bookmark to the url on the home page (browsing > bookmarks) the bookmasrk does not launch the application that is configured through jsam, but launches jsam itself don't launch jsam for this url the system does not download the java secure application manager to the client for the requested url this option is useful if you want to temporarily disable jsam auto launching for the specified urls use detailed rules to specify one or more detailed rules for this policy click save changes specifying application servers that users can access information in this topic is provided for backwards compatibility we recommend that you secure traffic using jsam resource profiles instead, since they provide a simpler, more unified configuration method refer to the specifying application servers that users can access section in psam for more details specifying resource level jsam options use the options tab to specify the sam resource option to match ip addresses to hostnames specified as resources in your sam resource policies when you enable this option, the system looks up ip addresses corresponding to each hostname specified in a sam resource policy when a user tries to access a server by specifying an ip address rather than the hostname, the system compares the ip to its cached list of ip addresses to determine if a hostname matches an ip if there is a match, then the system accepts the match as a policy match and applies the action specified for the resource policy when you enable this option, the system compiles a list of hostnames specified in the resources field of each sam resource policy the system then applies the option to this comprehensive list of hostnames this option does not apply to hostnames that include wildcards and parameters to specify the sam resource option in the admin console, choose users > resource policies > sam > options select ip based matching for hostname based policy resources when you select this option, the system looks up the ip address corresponding to each hostname specified in a secure application manager resource policy when a user tries to access a server by specifying an ip address rather than the hostname, the system compares the ip to its cached list of ip addresses to determine if a hostname matches an ip if there is a match, then the system accepts the match as a policy match and applies the action specified for the resource policy click save changes
