Skip to content

Client Settings

The Administrator can control various behaviour of the client through configuration settings on this page. These settings can be configured by navigating through Host Configuration | Client Settings. The settings are grouped under various heads and are described below for a better understanding.

Note

The client settings options are for all the clients logging in to the HySecure gateway and is not for a specific domain.

HySecure Client Settings

This block contains settings which are specific to the HySecure client functioning. This block is further grouped under various sub-blocks which are described hence.

HySecure Client Interface Settings

This sub-block would help in defining the settings primarily related to User login/logout, start/stop and messages related to HySecure Client.

# Client Setting Option Client Setting description Win Linux MAC Android iOS HyLite
1 Do not allow user to remember password on local device. On checking this option, the "Remember Password" option on the client login page will be greyed out and unchecked. As a result, the user will not have an option to save password, which is used to login to the Gateway, on the local device.
The "Remember Password" option can be enabled by unchecking this checkbox and allowing the user an option to save the password.
Y Y Y Y Y N
2 Do not allow user to remember username on local device. On checking this option, the "Remember Me" option on the client login page, will be greyed out and unchecked. As a result, the user will not have an option to save Username, which is used to login to the Gateway, on the local device.
The "Remember Me" option can be enabled by unchecking this checkbox and allowing the user an option to save the Username.
Y Y Y N N N
3 Enforce strong SSL Server Certificate check by HySecure Client. This option enforces the HySecure Server certificate verification while logging in from the client. On enabling it, if the client attempts a login and the server certificate is not valid, then s/he will get a message indicating the invalid server certificate and will ask the user whether s/he wants to continue or not. Accordingly it will be allowed to login.
This option is useful when the HySecure server is published using an IP only and the admin wants to avoid certificate error message on every client login.
Y N N N N N
4 Start HySecure Client on Windows / Linux logon. Check this option, if the HySecure client is expected to start automatically on Windows logon. As a result, the HySecure login page will open immediately after the user is logged onto Windows. Y N N N N N
5 Enable AutoLogin in HySecure Client. Check this option to enable auto-login of user, on the client launch.
Note: This option will be effective only if Username and Password are saved on the local device.
Y Y (Only without HyID) N N N N
6 Enable Always On in HySecure Client. Check this option to keep the HySecure client running even after the user logs out.
If the user intends to login after logging out, s/he can open the login page either by clicking on the pinned app OR by right clicking the client icon in the System tray and then clicking the "Login" option
This option is available to ensure that the user is never logged out due to inactivity.
Y Y N N N N
7 Use HySecure Client as service. Check this option to use the HySecure client as a Windows service.
Note: On checking this option, the user will not be able to logout and will always be connected to the HySecure server.
Login credentials are to be provided for the first time after launching the client. Post this, the client will run as a service
Y Y N N N N
8 Use Default browser for web application Check this option to use default browser while launching published Web applications.
If the option is not checked, Internet Explorer will be used to launch published Web applications.
Y Y Y N N N
Use Default Windows app for RDP app launch Y N/A N N N N
Enable client exit on logout Check this option to exit client automatically on user logout. Y N N N N N
10 Server Address label Enter the desired label name for HySecure Server IP address/hostname field on the client login page. In its absence, the default label is "HySecure Server". Y Y Y N N N
11 Specify password to stop HySecure Client in Service mode. Specify the password to stop the client, when it is running as a service. This password will be prompted for, when the user wants to stop the client.
Note: The client exit can be attempted by right clicking on the client icon in the system tray and clicking "Exit" button
Y N N N N N
12 Broadcast message warning. Specify a message here which gets displayed to the user along with "Ok" and "Cancel" buttons, on providing credentials to login to the Gateway and before s/he gets actually logged in to the Gateway.
If user clicks on OK then the login into HySecure Gateway will proceed with normal authentication process, and if the user clicks on cancel then user will get the login screen back.
The intent of this message is to primarily warn the user of any illegal and undesired login attempts.
Y Y Y N N N
13 Broadcast pre login message On entering the HySecure server address to which login is to be attempted, the realm is fetched which primarily involves details of all HySecure domains. At this point, the message configured in this field, gets displayed.
This message will be an informative message and hence is displayed with an "Ok" button only.
Y Y Y N N N
14 Broadcast post login message. When the user gets successfully logged into HySecure Gateway, the message configured in this field gets displayed in the left pane of the client application window. Y Y Y N N N
15 Disable HySecure system proxy update Check this option if the proxy settings on the user's local machine/browser are not expected to change, after a successful login to the Gateway. If a change is detected after login, then the proxy settings are disabled. Y N N N N N
16 Disable HySecure system proxy update message Configure this message which gets displayed when the Proxy settings are changed on the user's machine/browser, after login.
Note: This message is displayed only when the "Disable HySecure system proxy update" option is enabled
Y N N N N N
17 HySecure post login suffix message The message configured will get suffixed to the default message, on login failure. This message will help user take specific action on login failure Y N N N N N
18 HySecure custom device approval pending message Configure this message which gets displayed to the user when the manual approval is configured for Device ID policy and the user is trying to log in for the first time. Y Y Y N N N
19 HySecure custom device policy failed message Configure this message which gets displayed to the user when the user's login fails the Device ID policy. If nothing is configured, then the default message is displayed. Y Y Y N N N
20 HySecure custom device policy already pending message Configure this message which gets displayed when the user tries to log in but s/he has not been approved by the Security Officer / Administrator, as yet. Y Y Y N N N

Advance Settings

This sub-section lists the advanced settings related to the client interface

# Advanced Setting Option Description Win Linux MAC Android iOS HyLite
1 Additional HTTP Headers to Communication with HySecure gateway
( HTTP HEADER , separated by \r\n )
This configuration is needed in a special case where the HySecure Gateway is behind a firewall and the firewall expects some header key-value pairs as part of App Hello, to allow connections to the Gateway.
The expected header key-value pair is configured in the form header_key: header_value. Multiple such key-value pairs can be entered and separated by \r\n.
Y N N N N N
2 Allow access from current session This option caters to a Windows specific use case where a user accesses a published application after login to the Gateway. On switching to another user on the same machine without logging out, the session would remain open and the application can be accessed if the url is known.
Select this option, if the above case is to be avoided.
Y N N N N N
3 Deny access to the process
( Entries must be 'comma' separated. Example : teams.exe,iexplore.exe )
Configure the list of applications which are not expected to be executed after logging in to HySecure Gateway. The applications exe names need to be entered in a comma separated manner.
This option is primarily used for the case where a published application is not expected to be launched OR accessed through another application on the local system.
Y N N N N N
4 UPN support user name in client Check this option if the User Principal Name (upn) is to be entered by the user for logging in.
Note: The AD needs to be configured with upn as the User Search Attribute. By default, it is samAccountName.
Y Y Y Y Y Y
5 Application access time interval
(Enter numbers to set time in minutes )
TBD Y N N N N N
6 Enable login name as domain\username. Use domain name from login name. User able to login with domain\username in username field. Domain name is HySecure Server name. Y N N N N N
7 Use client side host file for name resolution. When user logged into HySecure Client, it will give automatically client application entry in user's machine host file. And on logout it will automatically remove client application entry. Y N N N N N
8 Disable HySecure login when the user is working through an Internet proxy server When proxy is set on user's machine and user tries to login then it wont be able to login. If unchecked, user able to login into HySecure Client. Y N N N N N
9 Map shared folders as local drives on user machine Check this option if the published path (as part of a FileShare type of application) is to be mapped to a local drive on the user machine Y N N N N N
10 Uninstall LSP on logout LSP will uninstall on client logout. Y N N/A N N N
11 Uninstall NSP on logout NSP will uninstall on client logout. Y N N/A N N N
12 Enable collection of device fingerprint details from user device. Check this option if the device details (fingerprint) are to be shared with the Gateway. This is mandatory if Device ID Access Control Policy is configured. Otherwise the Device ID policy does not get applied. Y Y Y Y Y Y
13 Detect real WAN IP address of the user if the user is working through an Internet proxy server When proxy is set on user's machine and user logged into HySecure Client, then will give WAN IP of machine in active user. If unchecked, it will give proxy server IP as WAN IP in active user. Y N N N N N
14 Specify comma separated list of alternate HySecure gateways that HySecure client can connect to. Admin have to give gateway list. When user tries to login and found gateway unreachable then with the list it will tries to connect. Y N N N N N
15 Force the client to randomly choose an alternate gateway from the list. When user tries to login and found gateway unreachable then it will randomly choose gateway which is running. Y N N N N N
16 Keep Alive Interval for TCP from client to gateway(in milliseconds) Configure the time interval at which Keep Alive messages will need to be sent to the Gateway to keep the connection with the Gateway alive. Y N N N N N
17 Keep Alive Time for TCP from client to gateway(in milliseconds) TBD Y N N N N N
18 User Idle Timeout Configure this option to "Enable" the User Idle timeout configured as part of the Global Settings. In this case, the client would send a logout on the idle timeout.
Configure this option to "Disable" if the user idle timeout logic is to be followed at the HySecure Gateway
Configure this option to "Not Set" (TBD)
Y N N N N N
19 Specify comma separated list of process to allow internet if internet is blocked. (like TeamViewer.exe, AA_v3.exe) When internet block policy is enabled and some specific process should run, while user logged into HySecure Client. List of process is given by admin. Y N N N N N
20 HySecure Linux Client Download URL. To download Linux Client, URL is specified.
This is applicable for web portal only
N N N N N N/A
21 HySecure Mac Client Download URL. To download MAC Client, URL is specified.
This is applicable for web portal only
N N N N N N/A

Profile Settings

# Profile Settings Option Description Win Linux MAC Android iOS HyLite
1 Enable Network Profile Detection. Check this option if the network profile of the connecting user as being "Office Profile" or "Roaming Profile" needs to be detected for controlling access to printing, USB, clipboard etc. Y N N N N N
2 Network Profile Detection Interval(In Seconds). Time interval of network profile detection. Usually we give 120 seconds. Y N N N N N
3 Specify comma or "-" separated list or subnet of Local Network IP Address to allow connection. Specify comma or '-' separated list of IP/subnet of local network for which the Internet Block Policy (EPS) will get bypassed Y N N N N N
4 Specify comma or "-" separated list or subnet of IP Address of websites to allow internet if internet is blocked. Specify comma or '-' separated list of IP/subnet of websites for which the Internet Block Policy will get bypassed Y N N N N N

Office Profile

Thee settings are not relevant for HyLite

# Office Profile Option Description Win Linux MAC Android iOS
1 Office Profile: Enable above local lan ip address bypass. Check this option if the list of IP addresses/subnet as indicated in the Profile setting Specify comma or "-" separated list or subnet of Local Network IP Address to allow connection. should bypass the Internet Block Policy
This will be effective for the user whose profile is detected as an Office Profile.
Y N N N N
2 Office Profile: Enable above internet ip address bypass. Check this option if the list of IP addresses/subnet as indicated in the Profile setting Specify comma or "-" separated list or subnet of IP Address of websites to allow internet if internet is blocked. should bypass the Internet Block Policy
This will be effective for the user whose profile is detected as an Office Profile.
Y N N N N
3 Office Profile: Block printing. Check this option if printing is to be blocked for the user after s/he logs in to the Gateway.
This option is effective for the user whose profile is detected as an Office Profile.
Y N N N N
4 Office Profile: Block USB. Check this option if USB detection is to be blocked for the user after s/he logs in to the Gateway.
This option is effective for the user whose profile is detected as an Office Profile.
Note: If USB is detected before login into HySecure Gateway, then it will automatically get disabled when user logs in.
Y N N N N
5 Office Profile: Block clipboard. Check this option if Copy/Paste/PrintScreen is to be blocked for the user after s/he logs in to the Gateway.
This option is effective for the user whose profile is detected as an Office Profile.
Y N N N N

Roaming Profile

These settings are not relevant for HyLite

# Roaming Profile Option Description Win Linux MAC Android iOS
1 Roaming Profile: Enable above local lan ip address bypass. Check this option if the list of IP addresses/subnet as indicated in the Profile setting Specify comma or "-" separated list or subnet of Local Network IP Address to allow connection. should bypass the Internet Block Policy
This will be effective for the user whose profile is detected as a Roaming Profile.
Y N N N N
2 Roaming Profile: Enable above internet ip address bypass. Check this option if the list of IP addresses/subnet as indicated in the Profile setting Specify comma or "-" separated list or subnet of IP Address of websites to allow internet if internet is blocked. should bypass the Internet Block Policy
This will be effective for the user whose profile is detected as a Roaming Profile.
Y N N N N
3 Roaming Profile: Block printing. Check this option if printing is to be blocked for the user after s/he logs in to the Gateway.
This option is effective for the user whose profile is detected as a Roaming Profile.
Y N N N N
4 Roaming Profile: Block USB. Check this option if USB detection is to be blocked for the user after s/he logs in to the Gateway.
This option is effective for the user whose profile is detected as a Roaming Profile.
Note: If USB is detected before login into HySecure Gateway, then it will automatically get disabled when user logs in.
Y N N N N
5 Roaming Profile: Block clipboard. Check this option if Copy/Paste/PrintScreen is to be blocked for the user after s/he logs in to the Gateway.
This option is effective for the user whose profile is detected as a Roaming Profile.
Y N N N N

Upgrade Settings

These settings are not relevant for HyLite

# Upgrade Settings Option Description Win Linux MAC Android iOS
1 Enable HySecure Client upgrade notification to users. Check this option if a notification needs to be given to the user to upgrade the client application, with an option to proceed further or cancel for the time being. Y Y N N N
2 Forcefully update HySecure client if the user's client version is equal to or below this version (format a.b.c.d, like 3.7.1.5). To forcefully update all the HySecure client enter "*" and leave blank to disable forcefully update. Specify the HySecure client version which is uploaded on the HySecure Gateway. If the client version is lower than the specified version, then the client application will get upgraded with the version on the HySecure Gateway.
If all the clients are to be upgraded forcefully, enter "*" in this field.
Keep the field empty if forceful upgrade is to be disabled.
Y Y (But with other method) N N N

HyWorks Client Settings

Note

All the settings indicated below are for Windows HyWorks client only.

# HyWorks Client Settings Option Description
1 Hyworks Client Version Specify the version of HyWorks Client which can be downloaded from the Gateway
2 Enable Hyworks client download (If unchecked, HyWorks On-Demand Client will be downloaded) Check this option to enable download of HyWorks client.
If unchecked, it will download on-demand client.
3 Enable Hyworks Client Upgrade. Check this option to enable HyWorks client upgrade from the Gateway
4 Enable Hyworks Client Force Upgrade. Check this option to forcefully upgrade HyWorks Client if the version is lower than Client version set in "Hyworks Client Version" settings.
5 Enable SEP installation with HyWorks Client. Check this option to Enable installation of SEP module while downloading and installing HyWorks Client.
Note: SEP is used for redirection.
6 Enable Eltima installation with HyWorks Client. Check this option to Enable installation of Eltima module while downloading and installing HyWorks Client.
Note: Eltima is used for redirection
7 Enable Hyworks exit with HySecure Logout. Check this option for the HyWorks client to logout and exit when the user logs out from HySecure Gateway using the HySecure client.
8 Disable HyWorks desktop shortcut. Check this option to avoid creation of HyWorks Desktop shortcuts, when user logs in into HySecure Gateway
9 Enable HySecure logout on Hyworks license error. Check this option to automatically log out the user from HySecure, if there is an error related to HyWorks license. For e.g. the HyWorks license gets expired.
10 Enable full width (Double-byte) characters check in username and password. Check this option to allow double-byte characters in username and password while launching HyWorks applications.
11 Pre Launch HyWorks Client Set the value to:
Enable: If the HyWorks client need to be launched along with the HySecure client
Disable: If the HyWorks client should be explicitly launched
Not Set:
12 Allow SSO on HyWorks Applications
13 HyLite Keep Alive Time Interval (in minutes, this setting is applicable for HyWorks only, Maximum 60 minutes are allowed) When user logged into HyLite portal then it will check the reachability of HyWorks application at the specified interval
14 Hyworks Client Installer Download URL. URL to download HyWorks Admin Client.
15 Hyworks On-Demand Client Installer Download URL. URL to download HyWorks On-demand Client.

DNS Setting

# DNS Setting Option Description Win Linux MAC Android iOS HyLite
1 Enforce DNS server name resolution Set the following option as per the need:
Enable: Selecting this value will force the use of DNS server of Gateway, for name resolution.
Disable: Selecting this value will disable the use of DNS server for name resolution
Not Set: Selecting this value will have the name resolution mechanism same as the one which is selected in the Preferences section of the client
Y N N N N N
2 Enter DNS NetBios list
( Entries must be 'semicolon' separated. Example : organization.com; somecompany.edu )
Specify the NetBIOS names list which should be resolved through the client system's WINS server Y N N N N N
3 Enter DNS list to bypass
( Entries must be 'comma' separated. Example : organization.com, somecompany.edu )
Enter the 'comma' separated domain list which need to be resolved by the local system's DNS server and not the Gateway's DNS server Y N N N N N
4 Enter DNS list to allow
( Entries must be 'comma' separated. Example : organization.com, somecompany.edu )
Enter the 'comma' separated list of domain names which should be resolved. Enter '*' to allow name resolution for all domains Y N N N N N
5 Enter DNS list to block
( Entries must be 'comma' separated. Example : organization.com, somecompany.edu )
Enter 'comma' separated list of domain names which should not be resolved for name Y N N N N N
6 Enter domain redirect suffix list
( Entries must be 'comma' separated. Example : organization.com, somecompany.edu )
Y N N N N N
7 Enter DNS list to redirect
( Entries must be 'comma' separated.. Example : organization.com, somecompany.edu )
Y N N N N N
8 Enter domain name suffix list All name resolution will be requested with each of the entries in the list. E.g. if list contains microsoft.com and accops.com then the name is resolved for name.microsoft.com and then name.accops.com Y N N Y Y N

Hybrid Mode Setting

Note

The Hybrid mode settings are applicable only for the Web Portal i.e. HyLite and no other client type.

Client Setting Option Client Setting description
1 Enable Hybrid mode. If checked, user is able to login into Hybrid mode. Hybrid mode, when user is able to login through web portal and if client is not installed on user's machine then it will download client.
2 Enable admin client as default client for Portal HyBrid Mode (If unchecked, On-Demand client will be default client) If this option is checked, then on user logon into web portal and with no HySecure Client installed on the user machine, the admin client will get installed.
If it is unchecked then it will install on demand client.
3 Time Interval for Portal Status Check (in seconds, this setting is applicable for hybrid mode only, Maximum 3600 seconds are allowed) When user is logged into the Gateway through hybrid mode, it will keep on checking the status whether the portal is running or not with the specified time interval. If portal gets closed then client will automatically exit. By Default, status check time interval is 20 sec.
4 Time Interval for Client Status Check (in seconds, this setting is applicable for hybrid mode only, Maximum 3600 seconds are allowed) When user is logged into the Gateway through hybrid mode, it will keep on checking the status whether the client is running or not with the specified time interval. By Default, status check time interval is 60 sec.

Remote Meeting Setting

Note

These settings are applicable for Windows clients only

# Remote Meeting Setting Option Description
1 Allow remote support to SO user only Set the following values as per the desired behaviour:
Enable: If only SO users are expected to give support
Disable: If any user can give or take support as per the published application of type Remote Meeting
2 Specify users for remote support
( Entries must be 'comma' separated. Example : jsons,taylors )
Specify the 'comma' separated list of users who can give remote meeting support
3 File transfer between remote users Mark the option as "Enable" if file transfer is to be supported between the users who are part of the remote meeting. Otherwise, set the option to "Disable"
4 Use remote cursor Mark the option as "Enable" if the remote user's cursor need to be used which sharing the screen. Otherwise, set the option to "Disable"

DLP Settings

These settings are not applicable for HyLite

# Client Setting Option Client Setting description Win Linux MAC Android iOS
1 User list to bypass secure desktop
( Entries must be 'comma' separated. Example : jasons,taylors )
Specify the 'comma' separated list of users for whom the DLP settings/checks need to be bypassed Y N N N N
2 Application list to bypass secure desktop
( Entries must be 'comma' separated. Example : notepad.exe, teams.exe )
Specify the 'comma' separated list of applications for which DLP settings/checks need to be bypassed Y N N N N
3 Enable screen shot block Check this option if screen shot needs to be blocked on user login to HySecure Y N N N N
4 Screenshot Unblock Check this option if Screen shot needs to be unblocked on HySecure logout Y N N N N
5 Application list to bypass screenshot block
( Entries must be 'comma' separated. Example : notepad.exe,teams.exe )
Specify the 'comma' separated list of applications for which the Screen shot block configuration needs to be bypassed Y N N N N
6 Block internet post log-out from HySecure(Only for Nano OS.) This option is for Nano OS only. On checking this option, internet is blocked even after logout from the HySecure Gateway N Nano OS only N N N
7 Enable clipboard control. Check this option if subsequent clipboard control configuration needs to be set Y N N N N
7.1 Block clipboard for all applications including printscreen. Check this radio button if copy/paste as well as print screen is to be blocked for all users, while they are logged in to HySecure. Y N N N N
7.2 Block clipboard for selective applications.
Specify comma separated list of applications. (like notepad.exe,mstsc.exe)
Specify the 'comma' separated list of applications for which copy/paste as well as print screen needs to be blocked, while they are logged in to HySecure. Y N N N N
8 Specify domain name for endpoint detection. User machine should be in domain which is specified by admin to login into HySecure Client. Y N N N N
9 Specify specific file path for endpoint detection. Y N N N N
10 Enable antivirus check for endpoint detection. To login into HySecure, Antivirus should be installed on user's machine. Y N N N N
11 Enable clipboard in Android Web Apps N N N Y N

HyId Desktp Config

# HyId Desktop Config Option Description HyLite
1 Default Policy Behaviour
2 User Policy Behaviour

RDP Setting

# Client Setting Option Client Setting description Win Linux MAC Android iOS HyLite
1 Use RDP Clipboard Y Y Y N N N
2 Use Default Windows app for RDP app launch When user is logged into HySecure and tries to launch RDP application then RDP will open through default windows module. If unchecked, it will use EDC launcher to open RDP. Y Y Y N N N
3 Enable RDP virtual channel for advanced RDP functions. When user is logged into HySecure, WTS value is set in registry and SSO enabler will work. Y Y Y N N N
4 Add additional information for RDP
(Eg: valid username, domain name, etc. , separated by \r\n )
Additional RDP settings can be provided here which will get appended to the default settings used. Multiple RDP settings can be provided by separating them with "\r\n" characters
E.g: Additionaclipboard:i:0\r\nPrintScreen:i:1
Additionally it can also be used to define additional parameters related to either camera re-direction or audio redirection etc.
Y Y Y N N N

Web Portal Logon mode selection

Note

These settings are applicable for HyLite only

# Web Portal Logon Mode Selection Option Description
1 Restrict Web Login and allow mobile registration.
2 Enable RMS mode. If checked, user is able to login into RMS mode. RMS mode, when user logged into Hylite, it will automatically connect to HyWorks and shows assigned dedicated/shared reservation VDI.
3 Primary RMS IP
4 Secondary RMS IP
5 Enable HyLite mode. If checked, user able to login into HyLite mode. Hylite mode, when user is able to login through web portal and tries to access application.
6 Select Default logon mode. From the above mode, any one of the mode is checked then it will set to default.

Upload Client with URLs

These settings are applicable only for Windows Client

# Upload Client With URLs Option Description
1 Allow upgrade with absolute url
2 Windows client upgrade with absolute URL
3 Windows client upgrade with absolute URL(non-admin)

Upload Clients

These settings are applicable only for Windows Client

# Upload Clients Option Description
1 Select client setup type which you want to upload Admin have to select the client type i.e. on-demand or admin client, HyWorks or HySecure Client.
2 HySecure/HyWorks Windows Client Version(Current version is 5.1.6.3 ) Version of the client which admin want to upload is specified in this field.
3 Choose client setup file Client setup file is selected from this field.
(Admin can check file is present in /home/fes/public/VPNClientSetup.exe)