Full VPN setup on NetScaler Gateway
Prerequisites
-
Install an SSL certificate and bind it to the VPN virtual server.
-
NetScaler documentation - Binding the Certificate-Key Pair to the SSL-Based Virtual Server.
-
Create an authentication profile for NetScaler Gateway.
-
For additional information, refer to NetScaler documentation - Configuring External User Authentication.
-
For additional information, refer to Checklist - Use AD FS to implement and manage single sign-on.
-
-
Download VPN Client.
-
Create a session policy allowing full VPN connections.
-
Split tunneling
-
IP addresses for users, including address pools (intranet IPs)
-
Connections through a proxy server
-
Defining the domains to which users are allowed access
-
Time-out settings
-
Single sign-on
-
User software that connects through NetScaler Gateway
-
Access for mobile devices
Configure a full VPN setup on a NetScaler Gateway appliance
-
Navigate to Traffic Management > DNS.
-
Select the Name Servers node, as shown in the following screenshot. Ensure that the DNS name server is listed. If it is not available, add a DNS Name Server.

-
Expand NetScaler Gateway > Policies.
-
Select the Session node.
-
In the NetScaler Gateway Session Policies and Profiles page, click the Profiles tab click Add. For each component you configure in the Configure NetScaler Gateway Session Profile dialog box, ensure that you select the Override Global option for the respective component.
-
Click the Client Experience tab.
-
Type the intranet portal URL in the Home Page field if you would like to present any URL when the user logs into the VPN. If the home page parameter is set to "nohomepage.html," the home page is not displayed. When the plug-in starts, a browser instance starts and gets killed automatically.
-
Ensure to select the desired setting from the Split Tunnel list.
-
Select OFF from the Clientless Access list if you want FullVPN.
-
Ensure that Windows/Mac OS X is selected from the plug-in Type list.
-
Select the Single Sign-on to Web Applications option if desired.
-
Ensure that the Client Cleanup Prompt option is selected if necessary, as shown in the following screenshot:

-
Click the Security tab.
-
Ensure that ALLOW is selected from the Default Authorization Action list.

-
Click the Published Applications tab.
-
Ensure that OFF is selected from the ICA® Proxy list under the Published Applications option.

-
Click Create.
-
Click Close.
-
Click the Policies tab of the NetScaler Gateway Session Policies and Profiles page in the virtual server or activate the Session Policies at the GROUP/USER Level as required.
-
Create a session policy with a required expression or true, as shown in the following screenshot:

-
Bind the Session policy to the VPN virtual server. For details, see Bind session policies.If Split Tunnel was configured to ON, you must configure the Intranet Applications you would like the users to access when connected to the VPN. For details on Intranet Applications, see Configure intranet applications for the Citrix Secure Access client.
-
Go to NetScaler Gateway > Resources > Intranet Applications.
-
Create an Intranet Application. Select Transparent for FullVPN with Windows client. Select the protocol that you would like to allow (TCP, UDP, or ANY), destination type (IP address and mask, IP address range, or host name).

-
If necessary, set a new policy for VPN on iOS and Android using the following expression:
HTTP.REQ.HEADER("User-Agent").CONTAINS("CitrixVPN")&&HTTP.REQ.HEADER("User-Agent").CONTAINS("NSGiOSplugin")&&HTTP.REQ.HEADER("User-Agent").CONTAINS("Android") -
Bind the Intranet Applications created at the USER/GROUP/VSERVER level as required.
-
nsapimgr -y -s vpn_http_port80=0
/nsconfig/rc.netscaler.
Configure split tunneling
-
Navigate to Configuration > NetScaler Gateway > Policies > Session.
-
In the details pane, on the Profiles tab, select a profile and then click Edit.
-
On the Client Experience tab, next to Split Tunnel, select Global Override, select an option, and then click OK.Configuring Split Tunneling and AuthorizationWhen planning your NetScaler Gateway deployment, it is important to consider split tunneling and the default authorization action and authorization policies.For example, you have an authorization policy that allows access to a network resource. You have split tunneling set to ON and you do not configure intranet applications to send network traffic through NetScaler Gateway. When NetScaler Gateway has this type of configuration, access to the resource is allowed, but users cannot access the resource.

-
You have split tunneling set to ON.
-
Intranet applications are configured to route network traffic through NetScaler Gateway
-
Navigate to Configuration > NetScaler Gateway > Resources > Intranet Applications.
-
In the details pane, click Add.
-
Complete the parameters for allowing network access, click Create, and then click Close.
Split tunneling options
Split tunnel OFF
Split tunnel ON
Reverse split tunnel
Points to note
-
Number of IP address-based rules is limited to 1024.
-
Supported with both DNE and WFP drivers.
-
The number of host names that can be accessed during a VPN session is restricted by the number of usable IP addresses specified in the FQDN spoofing range. This is because every host name takes up one IP address from the FQDN spoofing range. Once the IP range is exhausted, the least recently assigned IP address is reused for the next new host name.
-
DNS suffixes must be configured.Note:For Windows clients, host name-based reverse split-tunneling is supported only with the WFP driver. Enable the WFP driver mode by setting "EnableWFP" registry value to
1. For more information, see Windows Citrix Secure Access client using Windows Filtering Platform.
-
Supported only with the WFP driver. All the other guidelines mentioned in IP-based reverse split-tunneling and host name-based reverse split-tunneling are applicable.
Configure name service resolution
-
Configure a DNS or WINS server
-
Set the priority of the DNS lookup
-
Set the number of times to retry the connection to the server.
-
In the configuration utility, configuration tab > NetScaler Gateway > Policies > Session.
-
In the details pane, on the Profiles tab, select a profile and then click Open.
-
On the Network Configuration tab, do one of the following:
-
To configure a DNS server, next to DNS Virtual Server, click Override Global, select the server, and then click OK.
-
To configure a WINS server, next to WINS Server IP, click Override Global, type the IP address and then click OK.
-