Create virtual servers
-
Certificates
-
Authentication
-
Policies
-
Bookmarks
-
Address pools (also known as IP pools or intranet IPs)
-
Double-hop DMZ deployment with NetScaler Gateway
-
Secure Ticket Authority
-
SmartAccess ICA® Proxy Session Transfer
-
From the virtual servers node. This node is on the navigation pane in the configuration utility. You can add, edit, and remove virtual servers by using the configuration utility.
-
With the Quick Configuration wizard. If you deploy Citrix Endpoint Management™ or StoreFront in your environment, you can use the Quick Configuration wizard to create the virtual server and all the policies needed for your deployment.
To create virtual servers
To create a virtual server by using the GUI
-
Navigate to NetScaler Gateway > Virtual Servers.
-
In the details pane, click Add.
-
Configure the settings as per your requirement.
-
Click Create and then click Close.
To create a virtual server by using the CLI
add vpn vserver <name> <serviceType> [<IPAddress> [<port>]
add vpn vserver gatewayserver SSL 1.1.1.1 443
Points to note when binding a net profile to the VPN virtual server
-
When you bind a net profile to a NetScaler Gateway virtual server, it selects a specific SNIP for the virtual server to use when sending traffic to back-end servers.
-
In the absence of net profile binding, if there are multiple SNIPs, NetScaler Gateway uses the round robin method to select the SNIP to be used.
-
Net profile does not work for dynamically generated services (STA, SF monitor). For STA and other dynamically generated services, you can bind the net profile to those monitors directly and those monitors are used at that point. However, if you have multiple gateways on the same appliance, all gateways use the same net profile for the configured monitors.
Current users and total connected users on the virtual server
-
Consider that an ICA connection is established but no corresponding authentication, authorization, and auditing session are established. In this scenario, a user launches an application or a desktop and closes the browser, continues to work on the launched app or desktop. The authentication, authorization, and auditing session times out but the connection is still active. The total number of connected users can be used to identify the users that are still connected.
-
In HDX™ optimal routing, authentication gateway and ICA gateway can be on different appliances. The total connected users in this case can be used to identify the number of connected users on the ICA gateway.
-
Current users exceed total connected users when there are active sessions (not yet timed out) but there are no active connections on these sessions. For example, a user launched an application or a desktop and closed it immediately but did not log out from the authentication, authorization, and auditing session.
-
Total connected users exceed current users if authentication, authorization, and auditing sessions timeout but ICA connections are still active.
-
In a pure VPN setup (no ICA is involved), the number of current users and total connected users are equal.
Configure connection types on the virtual server
-
Connections with Citrix Workspace app only to Citrix Virtual Apps and Desktops without SmartAccess, endpoint analysis, or network layer tunneling features.
-
Connections with the Citrix Secure Access™ client and SmartAccess, which allow the use of SmartAccess, endpoint analysis, and network layer tunneling functions.
-
Connections with Secure Hub that establishes a Micro VPN connection from mobile devices to NetScaler Gateway.
-
Parallel connections made over the ICA session protocol by a user from multiple devices. The connections are migrated to a single session to prevent the use of multiple Universal licenses.
To configure Basic or SmartAccess connections on a virtual server
-
Navigate to NetScaler Gateway and then click Virtual Servers.
-
In the details pane, click Add.
-
In Name, type a name for the virtual server.
-
In IP Address and Port, type the IP address and port number for the virtual server.
-
Do one of the following:
-
To allow ICA connections only, click Basic Mode.
-
To allow user logon with Secure Hub, the Citrix Secure Access client, and SmartAccess, click SmartAccess Mode.
-
To allow SmartAccess to manage ICA Proxy sessions for multiple user connections, click ICA Proxy Session Migration.
-
-
Configure the other settings for the virtual server, click Create, and then click Close.
Configure a listen policy for wildcard virtual servers
| Parameter | Description |
|---|---|
| Name | The name of the virtual server. The name is required and you cannot change it after you create the virtual server. The name cannot exceed 127 characters and the first character must be a number or letter. You can also use the following characters: at symbol (@), underscore (_), dash (-), period (.), colon (:), pound sign (#), and a space. |
| IP | The IP address of the virtual server. For a wildcard virtual server bound to the VLAN, the value is always *. |
| Type | The behavior of the service. Your choices are HTTP, SSL, FTP, TCP, SSL_TCP, UDP, SSL_BRIDGE, NNTP, DNS, ANY, SIP-UDP, DNS-TCP, and RTSP. |
| Port | The port on which the virtual server listens for user connections. The port number must be between 0 and 65535. For the wildcard virtual server bound to a VLAN, the value is usually *. |
| Listen Priority | The priority that is assigned to the listen policy. Priority is evaluated in reverse order; the lower the number, the higher the priority assigned to the listen policy. |
| Listen Policy Rule | The policy rule is used to identify the VLAN to which the virtual server must listen. The rule is: CLIENT.VLAN.ID.EQ (<ipaddressat>) For <ipaddressat>, substitute the ID number assigned to the VLAN. |
To create a wildcard virtual server with a listen policy
-
In the navigation pane, expand NetScaler Gateway and then click Virtual Servers.
-
In the details pane, click Add.
-
In Name, type a name for the virtual server.
-
In Protocol, select the protocol.
-
In IP Address, type the IP address for the virtual server.
-
In Port, type the port for the virtual server.
-
On the Advanced tab, under Listen Policy, in Listen Priority, type the priority for the listen policy.
-
Next to Listen Policy Rule, click Configure.
-
In the Create Expression dialog box, click Add, configure the expression, and then click OK.
-
Click Create and then click Close.