Gateway pre-installation checklist
User devices
-
Ensure that user devices meet the installation prerequisites described in Citrix Secure Access System Requirements
-
Identify the mobile devices with which users connect. Note: If users connect with an iOS device, you must enable Secure Browse in a session profile.
NetScaler Gateway basic network connectivity
-
Identify and write down the NetScaler Gateway host name. Note: This is not the fully qualified domain name (FQDN). The FQDN is contained in the signed server certificate that is bound to the virtual server.
-
Obtain Universal licenses from the Citrix Website
-
Generate a Certificate Signing Request (CSR) and send to a Certificate Authority (CA). Enter the date that you send the CSR to the Certificate Authority.
-
Write down the system IP address and subnet mask.
-
Write down the subnet IP address and subnet mask.
-
Write down the administrator password. The default password that comes with NetScaler Gateway is
nsroot. -
Write down the port number on which NetScaler Gateway listens for secure user connections. The default is TCP port 443. This port must be open on the firewall between the unsecured network (Internet) and the DMZ.
-
Write down the default gateway IP address.
-
Write down the DNS server IP address and port number. The default port number is 53. In addition, if you are adding the DNS server directly, you must also configure ICMP (ping) on the appliance.
-
Write down the first virtual server IP address and host name.
-
Write down the second virtual server IP address and host name (if applicable).
-
Write down the WINS server IP address (if applicable).
Internal networks accessible through NetScaler Gateway
-
Write down the internal networks that users can access through NetScaler Gateway. Example: 10.10.0.0/24
-
Enter all internal networks and network segments that users need access to when they connect through NetScaler Gateway by using the Citrix Secure Access client.
High availability
-
Write down the NetScaler Gateway software version number.
-
The version number must be the same on both NetScaler Gateway appliances.
-
Write down the administrator password (
nsroot). The password must be the same on both appliances. -
Write down the primary NetScaler Gateway IP address and ID. The maximum ID number is 64.
-
Write down the secondary NetScaler Gateway IP address and ID.
-
Obtain and install the Universal license on both appliances.
-
Install the same Universal license on both appliances.
-
Write down the RPC node password.
Authentication and Authorization
LDAP authentication
-
Write down the LDAP server IP address and port.If you allow unsecure connections to the LDAP server, the default port is 389. If you encrypt connections to the LDAP server with SSL, the default port is 636.
-
Write down the security type.You can configure security with or without encryption.
-
Write down the administrator bind DN.If your LDAP server requires authentication, enter the administrator DN that NetScaler Gateway must use to authenticate when making queries to the LDAP directory. An example is cn=administrator,cn=Users,dc=ace, dc=com.
-
Write down the administrator password.The password is associated with the administrator bind DN.
-
Write down the Base DN.DN (or directory level) under which users are located; for example, ou=users,dc=ace,dc=com.
-
Write down the server logon name attribute.Enter the LDAP directory person object attribute that specifies a user’s logon name. The default is sAMAccountName. If you are not using Active Directory, the common values for this setting are cn or uid. For more information about LDAP directory settings, see Configuring LDAP Authentication
-
Write down the group attribute. Enter the LDAP directory person object attribute that specifies the groups to which a user belongs. The default is memberOf. This attribute enables NetScaler Gateway to identify the directory groups to which a user belongs.
-
Write down the subattribute name.
SAML Authentication
-
Obtain and install on NetScaler Gateway a secure IdP certificate.
-
Write down the redirect URL.
-
Write down the user field.
-
Write down the signing certificate name.
-
Write down the SAML issuer name.
-
Write down the default authentication group.
Opening ports through the firewalls (single-hop DMZ)
On the firewall between the unsecured network and the DMZ
-
Open a TCP/SSL port (default 443) on the firewall between the Internet and NetScaler Gateway. User devices connect to NetScaler Gateway on this port.
On the firewall between the secured network
-
Open one or more appropriate ports on the firewall between the DMZ and the secured network. NetScaler Gateway connects to one or more authentication servers or to computers running Citrix Virtual Apps and Desktops in the secured network on these ports.
-
Write down the authentication ports.Open only the port appropriate for your NetScaler Gateway configuration.
-
For LDAP connections, the default is TCP port 389.
-
For a RADIUS connection, the default is UDP port 1812. Write down the Citrix Virtual Apps and Desktops ports.
-
-
If you are using NetScaler Gateway with Citrix Virtual Apps and Desktops, open TCP port 1494. If you enable session reliability, open TCP port 2598 instead of 1494. Citrix recommends keeping both of these ports open.
Citrix Virtual Desktops™, Citrix Virtual Apps, or StoreFront
-
Write down the FQDN or IP address of the server running StoreFront.
Citrix Endpoint Management™
-
Write down the FQDN or IP address of Endpoint Management.
-
Identify web, SaaS, and mobile iOS or Android applications users can access.
Double-Hop DMZ deployment with Citrix Virtual Apps™
NetScaler Gateway in the first DMZ
-
Complete the items in the NetScaler Gateway Basic Network Connectivity section of this checklist for this NetScaler Gateway.When completing those items, Interface 0 connects this NetScaler Gateway to the Internet and Interface 1 connects this NetScaler Gateway to NetScaler Gateway in the second DMZ.
-
Configure the second DMZ appliance information on the primary appliance.To configure NetScaler Gateway as the first hop in the double-hop DMZ, you must specify the host name or IP address of NetScaler Gateway in the second DMZ on the appliance in the first DMZ. After specifying when the NetScaler Gateway proxy is configured on the appliance in the first hop, bind it to NetScaler Gateway globally or to a virtual server.
-
Write down the connection protocol and port between appliances.To configure NetScaler Gateway as the first hop in the double DMZ, you must specify the connection protocol and the port on which NetScaler Gateway in the second DMZ listens for connections. The connection protocol and port is SOCKS with SSL (default port 443). The protocol and port must be open through the firewall that separates the first DMZ and the second DMZ.
NetScaler Gateway in the second DMZ
-
Complete the tasks in the NetScaler Gateway Basic Network Connectivity section of this checklist for this NetScaler Gateway.When completing those items, Interface 0 connects this NetScaler Gateway to NetScaler Gateway in the first DMZ. Interface 1 connects this NetScaler Gateway to the secured network.