Responder action and policy examples
Responder actions and policies are powerful and complex, but you can get started with relatively simple applications.
Example: Blocking Access from Specified IPs
The following procedures block access to your protected website(s) for clients originating from the CIDR 222.222.0.0/16. The responder sends an error message stating that the client is not authorized to access the requested URL.
To block access by using the NetScaler command line:
At the command prompt, type the following commands to block access:
-
add responder action act_unauthorized respond with "HTTP/1.1 403 Forbidden\r\n\r\n" + "Client: " + CLIENT.IP.SRC + " is not authorized to access URL:" + "HTTP.REQ.URL.HTTP_URL_SAFE"'
-
add responder policy pol_un "CLIENT.IP.SRC.IN_SUBNET (222.222.0.0/16)" act_unauthorized
-
bind responder global pol_un 10
To block access by using the GUI:
-
In the navigation pane, expand Responder, and then click Actions.
-
In the details pane, click Add.
-
In the Create Responder Action dialog box, do the following:
-
In the Name text box, type act_unauthorized.
-
Under Type, select Respond with.
-
In the Target text area, type the following string: "HTTP/1.1 403 Forbidden\r\n\r\n" + "Client: " + CLIENT.IP.SRC + " is not authorized to access URL:" + HTTP.REQ.URL.HTTP_URL_SAFE
-
Click Create, and then click Close. The responder action you configured, named act_unauthorized, now appears in the Responder Actions page.
-
-
In the navigation pane, click Policies.
-
In the details pane, click Add.
-
In the Create Responder Policy dialog box, do the following:
-
In the Name text box, type pol_unauthorized.
-
Under Action, select act_unauthorized.
-
In the Expression window, type the following rule: CLIENT.IP.SRC.IN_SUBNET(222.222.0.0/16)
-
Click Create, then click Close. The responder policy you configured, named pol_unauthorized, now appears in the Responder Policies page.
-
-
Globally bind your new policy, pol_unauthorized, as described in Binding a Responder Policy.
Example: Redirecting a client to a new URL
The following procedures redirect clients who access your protected website(s) from within the CIDR 222.222.0.0/16 to a specified URL.
To redirect clients by using the NetScaler command line:
At the command prompt, type the following commands to redirect clients and verify the configuration:
add responder action act_redirect redirect "\"<http://www.example.com/404.html>\""
show responder action act_redirect
add responder policy pol_redirect "CLIENT.IP.SRC.IN_SUBNET(222.222.0.0/16)" act_redirect
show responder policy pol_redirect
bind responder global pol_redirect 10
Example:
add responder action act_redirect redirect "\"<http://www.example.com/404.html>\""
add responder policy pol_redirect "CLIENT.IP.SRC.IN_SUBNET(222.222.0.0/16)" act_redirect
To redirect clients by using the GUI:
-
Navigate to AppExpert > Responder > Actions.
-
In the details pane, click Add.
-
In the Create Responder Action dialog box, do the following:
-
In the Name text box, type act_redirect.
-
Under Type, select Redirect.
-
In the Target text area, type the following string:
"http://www.example.com/404.html" -
Click Create, then click Close. The responder action you configured, named act_redirect, now appears in the Responder Actions page.
-
-
In the navigation pane, click Policies.
-
In the details pane, click Add.
-
In the Create Responder Policy dialog box, do the following:
-
In the Name text box, type pol_redirect.
-
Under Action, select act_redirect.
-
In the Expression window, type the following rule: CLIENT.IP.SRC.IN_SUBNET(222.222.0.0/16)
-
Click Create, then click Close. The responder policy you configured, named pol_redirect, now appears in the Responder Policies page.
-
-
Globally bind your new policy, pol_redirect, as described in Binding a Responder Policy.