Configuring IF-MAP Session Import Policy on the Secure Access Device (NSM Procedure)
The session-export policies that you create allow IF-MAP data that represents a session to be stored on the IF-MAP server. Session-import policies specify how the Secure Access device derives a set of roles and a username from the IF-MAP data in the IF-MAP server. Session-import policies establish rules for importing user sessions from a different Infranet Controller or SA appliance. Import policies allow you to match authenticated users with corresponding roles on the target device. For example, you might configure an import policy to specify that when IF-MAP data for a session includes the “Contractor” capability, the imported session should have the “limited” role. Session-import policies allow the device to properly assign roles based on information that the IF-MAP server provides.
To configure a session-import policy:
- In the NSM navigation tree, select Device Manager > Devices. Click the Device Tree tab, and then double-click the Secure Access device for which you want to configure a session-import policy.
- Click the Configuration tab. In the configuration tree, select System > IF–MAP Federation > Session-Import Policies.
- Add or modify settings as specified in Table 1.
- Click one:
- OK—Saves the changes.
- Cancel—Cancels the modifications.
Table 1: IF–MAP Session-Import Policy Configuration Details

