Configure IP addresses on NetScaler Gateway
-
NSIP address. The management IP address for NetScaler Gateway that is used for all management-related access to the appliance. NetScaler Gateway also uses the NSIP address for authentication.
-
Default gateway. The router that forwards traffic from outside the secure network to NetScaler Gateway.
-
Subnet IP (SNIP) address. The IP address that represents the user device by communicating with a server on a secondary network.
How NetScaler Gateway uses IP addresses
-
Authentication. The IP address that NetScaler Gateway uses depends on the authentication server type.
-
LDAP/RADIUS/TACACS servers. If AAAD directly communicates with the authentication virtual server, then the NSIP address is used.
-
If a load balancer is used as proxy, then the load balancer uses the SNIP address for authentication. AAAD uses the NSIP address to communicate with the load balancer. The IP address that the NetScaler uses depends on the entity that is communicating with the authentication virtual server.
-
SAML/OAUTH/WEBAUTH servers: These servers communicate using the SNIP address.
-
-
File transfers from the home page. NetScaler Gateway uses the SNIP address.
-
DNS and WINS queries. NetScaler Gateway uses the SNIP address.
-
Network traffic to resources in the secure network. NetScaler Gateway uses the SNIP address or IP pooling, depending on the configuration on NetScaler Gateway.
-
ICA proxy setting. NetScaler Gateway uses the SNIP address.
Subnet IP addresses
To add a subnet IP address
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand System \ > Network, and then click IPs.
-
In the details pane, click Add.
-
In the Create IP dialog box, in IP Address, type the IP address.
-
In Netmask, type the subnet mask.
-
Under IP Type, select Subnet IP, click Close, and then click Create.
Configure IPv6 for user connections
-
Global Settings - Published Applications - ICA® Proxy
-
Global Authentication - RADIUS
-
Global Authentication - LDAP
-
Global Authentication - TACACS
-
Session Profile - Published Applications - ICA Proxy
-
NetScaler Gateway Virtual Servers
-
Create Authentication Server - RADIUS
-
Create Authentication Server - LDAP
-
Create Authentication Server - TACACS
-
Create Auditing Server
-
High Availability Setup
-
Bind / Unbind Route Monitors for High Availability
-
Virtual server (Load Balancing)
-
Citrix Virtual Apps and StoreFront. When you configure IPv6 for user connections and if there is a mapped IP address that uses IPv6, Citrix Virtual Apps and StoreFront servers can also use IPv6. StoreFront must be installed behind NetScaler Gateway. When users connect through NetScaler Gateway, the IPv6 address is translated to IPv4. When the connection returns, the IPv4 address is translated to IPv6.
-
Virtual servers. You can configure IPv6 for a virtual server when you run the NetScaler Gateway wizard. In the NetScaler Gateway wizard on the Virtual Servers page, click IPv6 and enter the IP address. You can only use configure an IPv6 address for a virtual server by using the NetScaler Gateway wizard.
-
Other. To configure IPv6 for ICA Proxy, authentication, auditing, and high availability, select the IPv6 check box in the dialog box and then type the IP address.