7.1

Table Of Contents
1
n
For the internal network (Internal Network Range), two authentication methods are congured for
the rule, Kerberos and password authentication as the fallback method. To access the apps portal
from an internal network, the service aempts to authenticate users with Kerberos authentication
rst, as it is the rst authentication method listed in the rule. If that fails, users are prompted to
enter their Active Directory password. Users log in using a browser and now have access to their
user portals for an eight-hour session.
n
For access from the external network (All Ranges), only one authentication method is congured,
RSA SecurID. To access the apps portal from an external network, users are required to log in with
SecurID. Users log in using a browser and now have access to their apps portals for a four-hour
session.
2 When a user aempts to access a resource, except for Web applications covered by a Web-application-
specic policy, the default portal access policy applies.
For example, the re-authentication time for such resources matches the re-authentication time of the
default access policy rule. If the time for a user who logs in to the apps portal is eight hours according
to the default access policy rule, when the user aempts to launch a resource during the session, the
application launches without requiring the user to re-authenticate.
Managing Web-Application-Specific Policies
When you add Web applications to the catalog, you can create Web-application-specic access policies. For
example, you can create an policy with rules for a Web application that species which IP addresses have
access to the application, using which authentication methods, and for how long until reauthentication is
required.
The following Web-application-specic policy provides an example of a policy you can create to control
access to specied Web applications.
Example 1 Strict Web-Application-Specific Policy
In this example, a new policy is created and applied to a sensitve Web application.
Configuring vRealize Automation
98 VMware, Inc.