1Y0-231 · Question #108
How can a Citrix Administrator configure session policies for authentication, authorization, and auditing traffic management (AAA-TM) sessions if the authentication virtual server is specified in a…
The correct answer is A. Bind the AAA-TM session policies to the AAA virtual server. When a dedicated AAA virtual server is specified in a Citrix Gateway configuration, AAA-TM session policies must be bound directly to that AAA virtual server - because that is the entity actually processing the authentication, authorization, and auditing traffic. The AAA…
Question
How can a Citrix Administrator configure session policies for authentication, authorization, and auditing traffic management (AAA-TM) sessions if the authentication virtual server is specified in a Citrix Gateway setup?
Options
- ABind the AAA-TM session policies to the AAA virtual server.
- BBind the AAA-TM session policies to the AAA virtual server.
- CDefine session policies only for the Citrix Gateway virtual server.
- DBind AAA-TM session policies as default global.
How the community answered
(20 responses)- A80% (16)
- B5% (1)
- C5% (1)
- D10% (2)
Explanation
When a dedicated AAA virtual server is specified in a Citrix Gateway configuration, AAA-TM session policies must be bound directly to that AAA virtual server - because that is the entity actually processing the authentication, authorization, and auditing traffic. The AAA virtual server becomes the policy decision point for those sessions, so any session policies governing that traffic must be attached there to take effect.
Why the distractors are wrong:
- B is identical to A (a duplicate in the question - likely a typo intended to be a different option).
- C is wrong because the Gateway virtual server handles VPN/gateway traffic, not AAA-TM sessions; binding session policies only there would leave AAA-TM sessions ungoverned when a separate AAA vserver is in use.
- D is wrong because binding globally applies policies indiscriminately across all sessions, which is imprecise, can cause unintended side effects, and does not target the AAA virtual server specifically as required by this architecture.
Memory tip: Follow the traffic - wherever authentication is processed, that's where the session policies must live. AAA vserver = AAA policies.
Topics
Community Discussion
No community discussion yet for this question.