Configure NetScaler Gateway to support HDX Insight
To configure NetScaler Gateway to support HDX Insight using GUI
-
This section is applicable to NetScaler Gateway versions 14.1-51.x and earlier.
-
Starting from NetScaler Gateway release 14.1 build 56.x, HDX Insight data is transmitted to Citrix Director without requiring AppFlow policy configuration. Administrators only need to enable the Network telemetry policy on Delivery Controller or Citrix Studio to transmit HDX Insight data to Citrix Director. For details about enabling the policy, see Create policies.
-
On the Configuration tab navigate to System> AppFlow®>Collectors, and click Add.

-
On the Create AppFlow Collector page, populate the following fields, and click Create.
-
Name: Name for the collector
-
IP address: IPv4 address of the collector
-
Port: Port on which the collector listens
-
Net Profile: Net profile to associate with the collector. The IP address defined in the profile is used as the source IP address for AppFlow traffic for this collector. If you do not set this parameter, the NetScaler IP (NSIP) address is used as the source IP address.
-
Transport: Transport type of collector.

-
-
Navigate to System > AppFlow > Actions, click Add.

-
On the Create AppFlow Action page, populate the following fields, and click Create.
-
AppFlow Action Name: Name for the action
-
Comment: Any comment about the action
-
Collector: Select the names of collectors to be associated with the AppFlow action.
-
Transaction Log: Transactions type to be logged.

-
-
Navigate to System> AppFlow>Policies, click Add.

-
On the Create AppFlow Policy page, populate the following fields, and click Create.
-
Name: Name for the policy.
-
Action: Name of the action to be associated with the policy.
-
UNDEF: Name of the AppFlow action to be associated with this policy when an undefined event occurs.
-
Expression: Expression or other value against which the traffic is evaluated. Must be a Boolean expression.
-
Comments: Any comments about this policy.

-
-
Navigate to NetScaler Gateway>Virtual Servers, select the virtual server, and click Edit.

-
Scroll down the VPN Virtual Server page and under the Policies section, click +.

-
On the Choose Type screen, in the Choose Policy drop-down menu, select AppFlow. In the Choose Type drop-down menu, choose Request or ICA® Request and click Continue.

-
Click the highlighted arrow under Select Policy.

-
Select the AppFlow policy and click Select.

-
Finally click Bind.

To configure NetScaler Gateway to support HDX Insight using CLI
-
This section is applicable to NetScaler Gateway versions 14.1-51.x and earlier.
-
Starting from NetScaler Gateway release 14.1 build 56.x, HDX Insight data is transmitted to Citrix Director without the following
appflow policyconfiguration. Administrators must enable the Network telemetry policy on Delivery Controller or Citrix Studio to transmit HDX Insight data to Citrix Director. For details about enabling the policy, see Create policies.
add appflow collector col3 -IPAddress<ip_mas>
add appflow action act1 <action_name>
add appflow policy <policy_name> true <action_name>
bind vpn Vserver <vserver_name> -pol <policy_name> - priority101 END -type <ICA_Request>
Enhanced HDX Insight transmission without NetScaler Gateway configuration dependency
To disable the HDX Insight transmission by using the GUI
-
Navigate to Settings > Change ICA Parameters.
-
On the Change ICA Parameters page, clear the HDX Insight data to director without HDXInsight configuration option.
-
Click OK.
To disable the HDX Insight transmission by using the CLI
set ica param -InsightOnlyToDirector DISABLED
Disable HDX Insight for non-NetScaler® AppFlow (NSAP) HDX session
set ica parameter HDXInsightNonNSAP (YES | NO )
HDX Insight support with Secure HDX
Key benefits
-
Network latency for HDX Insight can be monitored in Director.
-
Data security is strengthened through a secure TLS/DTLS connection between NetScaler Gateway and the VDA.
System requirements
-
Citrix Workspace™ app for Windows - version 2503 and later.
-
VDA for Windows - version 2503 and later.
-
VDA for Linux - version 2507 and later
-
Director - version 2503 and later.
Limitations
-
HDX Multi-stream ICA (MSI) connections
-
IPv6 protocol
-
Transparent mode and LAN proxy mode topologies
-
SOCKS protocol
Configure DTLS 1.2 by using the GUI
-
Navigate to NetScaler Gateway -> Global Settings -> Change Global Settings.
-
On the Global NetScaler Gateway Settings page, select ENABLED in Backend DTLS 1.2 and click OK.
Configure DTLS 1.2 by using the CLI
set vpn parameter -backenddtls12 ENABLED
-
set vpn parameter -backenddtls12 DISABLED
-
unset vpn parameter -backendDtls12