Integrate NetScaler Gateway with StoreFront or StoreFront Cloud for HDX routing only
Use cases
StoreFront
StoreFront Cloud
Prerequisites
-
A NetScaler Gateway instance reachable from the internet, with a valid SSL certificate available to bind to the virtual server.
-
A resource location added to Citrix Cloud with Cloud Connectors installed.
Configure NetScaler Gateway for HDX routing
1. Create a session profile and policy
-
Navigate to Configuration > NetScaler Gateway > Policies > Session.
-
In the Session Profiles tab, click Add.
-
Assign a name to the session profile.
-
In the Client Experience tab, set Session Time-out (mins) to Override Global and specify a value. This is an inactivity timeout: it is reset by network traffic and does not disconnect an active HDX connection, since ICA traffic keeps the session from going idle. It only ends the session if the connection is genuinely idle for the configured duration.
-
In the Security tab, enable Default Authorization Action and set it to ALLOW.
-
In the Published Applications tab, set ICA Proxy to ON.
-
Click Create.
-
In the Session Policies tab, click Add.
-
In Name, assign a name to the session policy.
-
In Profile, select the session profile that you created.
-
In Expression, enter
trueso that the policy applies to all connections to this virtual server. -
Click Create.
2. Create a NetScaler Gateway virtual server
-
Navigate to Configuration > NetScaler Gateway > Virtual Servers and click Add.
-
Assign a name and IP address, then click Continue.
-
In Basic Settings, clear Enable Authentication and select ICA Only.
-
Bind a certificate.
-
In the Certificate section, click No Server Certificate.
-
Under Select Server Certificate, choose the SSL certificate for the public FQDN of this virtual server, or click Add to install one if it is not already available.
-
Click Bind.
-
-
Click Continue.
-
Bind the policy.
-
In the Policies section, click +.
-
Leave Choose Policy as Session and Choose Type as Request and select Continue.
-
Under Policy Binding, click in Click to select.
-
Select the session policy that you created in the previous step and click Select.
-
Click Bind.
-
-
Add the STA servers.
-
In the Advanced Settings column, click Published Applications to add that section to the virtual server.
-
In the Published Applications section, click No STA Server.
-
Enter the address of a Cloud Connector in the resource location then click Bind.
-
Repeat for every Cloud Connector in the resource location.
-
-
Click Done.