XenApp 6 - Policy to control access to published apps over VPN

Looking for advice on best practices on setting up a policy to control users access to published apps based on some criteria when connecting to VPN.  We use Cisco ASA as VPN endpoint and do not have citrix access gateway.   Using XenApp 6 with citrix receiver v3.0.

Ex.  User has access to 5 published apps when logging into receiver locally on LAN.  But when using receiver on IPad (with same credentials), he only has access to 3 of the published apps.
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Sekar ChinnakannuStaff EngineerCommented:
you dont have policy to control the published applications in vpn. you can configure same in application properties.
Use a Load Evaluator criteria for the IP address, and specifically block the VPN subnet.  

If you choose the Load Evaluator route, be aware that it may not work the way you'd expect.  I'm not quite sure why, but you can't just designate specific IPs to allow.  The allow field doesn't work--trust me, I experienced much frustration to learn this the hard way because the admin interface would certainly lead you to believe you'd configured it correctly with "allow" settings.  You will attempt to save the configuration, and it appears to save but won't save at all.  No error messages, it just doesn't save.  Arghh!

So, you must specifically designate the deny IP ranges.  You'll want to designate ranges with the specific allow as gaps IPs in between.  Backwards, I know, but hopefully this tip will save you several hours.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.