Before Getting Started
-
Citrix Endpoint Management™
-
Citrix Virtual Apps™
-
Citrix Virtual Desktops™
-
StoreFront™
-
Citrix SD-WAN™
-
Identify resources. List the network resources for which you want to provide access, such as Web, SaaS, mobile or published applications, virtual desktops, services, and data that you defined in your risk analysis.
-
Develop access scenarios. Create access scenarios that describe how users access network resources. An access scenario is defined by the virtual server used to access the network, endpoint analysis scan results, authentication type, or a combination thereof. You can also define how users log on to the network.
-
Identify client software. You can provide full VPN access with the Citrix Secure Access client, requiring users to log on with Citrix Workspace app, Secure Hub, or by using clientless access. You can also restrict email access to Outlook Web App or WorxMail. These access scenarios also determine the actions users can perform when they gain access. For example, you can specify whether users can modify documents by using a published application or by connecting to a file share.
-
Associate policies with users, groups, or virtual servers. The policies you create on NetScaler Gateway enforce when the individual or set of users meets specified conditions. You determine the conditions based on the access scenarios that you create. You then create policies that extend the security of your network by controlling the resources users can access and the actions users can perform on those resources. You associate the policies with appropriate users, groups, virtual servers, or globally.
-
Planning for Security includes information about authentication and certificates.
-
Prerequisites that define network hardware and software you might need.
-
The Pre-Installation Checklist that you can use to write down your settings before you configure NetScaler Gateway.
Prerequisites for installing NetScaler Gateway
-
NetScaler Gateway is physically installed in your network and has access to the network. NetScaler Gateway is deployed in the DMZ or internal network behind a firewall. You can also configure NetScaler Gateway in a double-hop DMZ and configure connections to a server farm. Citrix recommends deploying the appliance in the DMZ.
-
You configure NetScaler Gateway with a default gateway or with static routes to the internal network so users can access resources in the network. NetScaler Gateway is configured to use static routes by default.
-
The external servers used for authentication and authorization are configured and running. For more information, see Authentication and Authorization.
-
The network has a domain name server (DNS) or Windows Internet Naming Service (WINS) server for name resolution to provide correct NetScaler Gateway user functionality.
-
You downloaded the Universal licenses for user connections with the Citrix Secure Access client from the Citrix website and the licenses are ready to be installed on NetScaler Gateway.
-
NetScaler Gateway has a certificate that is signed by a trusted Certificate Authority (CA). For more information, see Installing and Managing Certificates.
Planning for security
Configure secure certificate management
Authentication support
-
LDAP
-
RADIUS
-
TACACS+
-
Client certificate with auditing and smart card support
-
RSA with RADIUS configuration
-
SAML authentication