Always On
When to Use Always On
-
An employee starts the laptop outside the enterprise network and needs assistance to establish VPN connectivity.Solution: When the laptop is started outside the enterprise network, Always On seamlessly establishes a tunnel and provides VPN connectivity.
-
An employee using VPN connectivity moves into the enterprise network. The employee is switched to an enterprise network but remains connected to the VPN tunnel, which is not a desirable state.Solution: When the employee moves into the enterprise network, Always On tears down the VPN tunnel and seamlessly switches the employee to the enterprise network.
-
An employee moves outside the enterprise network and closes the laptop (not shut down). The employee needs assistance to establish VPN connectivity upon resuming work on the laptop.Solution: When the employee moves outside the enterprise network, Always On seamlessly establishes a tunnel and provides VPN connectivity.
-
An enterprise wants to regulate the network access provided to its users when they are not connected to a VPN tunnel.Solution: Depending on the configuration, Always On restricts access, allowing users to access only the gateway network.
Understanding the Always On Framework
Automatic reestablishment of a Tunnel
Supported user authentication methods for seamless tunnel establishment
-
User name + AD password: If the Windows user name and password are used for authentication, the Citrix Secure Access client seamlessly establishes the tunnel by using these credentials.
-
User certificate: If a user certificate is used for authentication and there is only one certificate on the client machine, Citrix Secure Access client seamlessly establishes a tunnel by using this certificate. If multiple client certificates are installed, the tunnel is established after the user has selected the preferred certificate. Citrix Secure Access client uses this preferred certificate for later tunnels.If the smart cards share a user certificate, autologon cannot be achieved if the certificates are dynamically installed in the store as compared to the certificates being present in the store.
-
User certificate and User name + AD password: This authentication method is the combination of previously described authentication methods.
Configuration requirements for Always On
-
User must not be able to end the process/service for specific configuration
-
User must not be able to uninstall the package for specific configuration
-
User must not be able to change specific registry entries
Considerations While Enabling the Always On feature
Configuring Always On
-
In the NetScaler GUI, navigate to Configuration > NetScaler Gateway > Policies > AlwaysON.
-
On the AlwaysON Profiles page, click Add.
-
On the Create AlwaysON Profile page, enter the following details:
-
Name – The name for your profile.
-
**Location Based VPN (client-side registry name: LocationDetection) – Select one of the following settings:
-
Remote to enable a client to detect whether it is in the enterprise network and establish the tunnel if not in the enterprise network. Remote is the default setting.
-
Everywhere to let a client skip the location detection and establish the tunnelregardless of the client's location
-
-
Client Control – Select one of the following settings:
-
Deny to prevent the user from logging off and connecting to another gateway. Deny is the default setting.
-
Allow to enable the user to log off and connect to another gateway.
-
-
Network Access On VPN Failure (client-side registry name: AlwaysOn) – Select one of the following settings:
-
Full Access to allow network traffic to flow to and from the client when the tunnel is not established. Full Access is the default setting.
-
Only To Gateway to prevent network traffic from flowing to or from the client when the tunnel is not established. However, the traffic to or from the Gateway IP address is allowed.Note: In Only To Gateway mode, only the virtual server, DNS, and DHCP traffic are unblocked. To unblock other websites, IP address ranges, or IP addresses, you must set the AlwaysOnAllowlist registry with a semicolon-separated list of FQDNs, IP address ranges, or IP addresses. For example, mycompany.com,mycdn.com,10.120.67.0-10.120.67.255,67.67.67.67
-
-
-
Click Create to finish creating your profile.
-
In the NetScaler interface, select Configuration > NetScaler Gateway > Global Settings.
-
On the Global Settings page, click the Change Global Settings link, and then select the Client Experience tab.
-
From the AlwaysON Profile Name drop-down menu, select the newly created profile, and click OK.
Note on IIPs
Behavior summary of different configurations for admin users and non-admin users
| networkAccessONVPNFailure | Client control | Non-admin user | Admin user |
|---|---|---|---|
fullaccess |
Allow | The tunnel gets established automatically. The user can log off and stay off the network. The user can also point to another NetScaler Gateway. | The tunnel gets established automatically. The user can log off and stay off the enterprise network. The user can also point to another NetScaler Gateway. |
fullaccess |
Deny | The tunnel gets establish automatically. The user cannot log off or point to another NetScaler Gateway. | The tunnel gets established automatically. The user can uninstall the Citrix Secure Access client or move to another NetScaler Gateway. |
| onlyToGateway | Allow | The tunnel gets established automatically. The user can log off (no network access). The user can also point to another NetScaler Gateway, in which case, the access is given only to the newly pointed NetScaler Gateway. | The tunnel gets established automatically. The user can uninstall the Citrix Secure Access client or move to another NetScaler Gateway. |
| onlyToGateway | Deny | The tunnel gets establish automatically. The user cannot log off or point to another NetScaler Gateway. | The tunnel gets established automatically. The user can uninstall the Citrix Secure Access client or move to another NetScaler Gateway. |
Allowing selected URLs when Always On is down
-
AlwaysOnAllowlist registry is supported from release 13.0 build 47.x and later.
-
AlwaysOnAllowlist registry location is Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Secure Access Client.
-
Wildcard URLs/FQDNs are not supported in the AlwaysOnAllowlist registry.
To set the AlwaysOnAllowlist registry