Our environment needs to DENY access from any Mobile device and any MAC/iOS devices, but allow Linux and Windows

I have the Linux and Windows+EPA scan Piece in place

but am having an issue with the policy language for Denying the MAC / iOS and Mobile devices (android and windows Phones)


where to place them in the Authentication process to get them to deny these devices. 


this is the language i have in the script. 



HTTP.REQ.HEADER("User-Agent").CONTAINS("CitrixReceiver").NOT && HTTP.REQ.HEADER("User-Agent").CONTAINS("Android").Not || HTTP.REQ.HEADER("User-Agent").CONTAINS("CitrixReceiver").NOT && HTTP.REQ.HEADER("User-Agent").CONTAINS("iOS").Not || HTTP.REQ.HEADER("User-Agent").CONTAINS("CitrixReceiver").NOT && HTTP.REQ.HEADER("User-Agent").CONTAINS("WindowsPhone").Not

