Configure SmartControl
| Attribute | Description |
|---|---|
| ConnectClientDrives | Specifies the default connection to the client drives when the user logs on. |
| ConnectClientLPTPorts | Specifies the automatic connection of LPT ports from the client when the user logs on. LPT ports are the Local Printer Ports. |
| ClientAudioRedirection | Specifies the applications hosted on the server to transmit audio through a sound device installed on the client computer. |
| ClientClipboardRedirection | Specifies and configures clipboard access on the client device and maps the clipboard on the server. |
| ClientCOMPortRedirection | Specifies the COM port redirection to and from the client. COM ports are the COMmunication ports. COM ports are serial ports. |
| ClientDriveRedirection | Specifies the drive redirection to and from the client. |
| Multistream | Specifies the multistream feature for specified users. |
| ClientUSBDeviceRedirection | Specifies the redirection of USB devices to and from the client (workstation hosts only). |
Localremotedata |
Specifies the HTML5 file upload download capability for the Citrix Workspace app. |
| ClientPrinterRedirection | Specifies the client printers to be mapped to a server when a user logs on to a session. |
| ClientTWAINDeviceRedirection | Allows default access or disables TWAIN devices, such as digital cameras or scanners, on the client device from published image processing applications. |
| WIARedirection | Allows default access or disables WIA scanner redirection. |
| DragAndDrop | Allows default access or disables drag and drop between client and remote applications and desktops. |
| SmartCardRedirection | Allow default access or disable smart card redirection. Smart card virtual channel is always allowed in CVAD. |
| FIDO2Redirection | Allows default access or disable FIDO2 redirection. |
ICA® Policies and Profiles
ICA access profile
-
ClientTWAINDeviceRedirection
-
WIARedirection
-
DragAndDrop
-
SmartCardRedirection
-
FIDO2Redirection
Configure an ICA access profile by using the GUI
-
Navigate to NetScaler Gateway > Policies > NetScaler Gateway ICA Policies and Profiles > Access Profiles and click Add. The Create ICA Access Profile page appears.
-
Provide a name for the ICA access profile, configure the following parameters, and click Create.
-
Connect Client LPT Ports: Allow or block the automatic connection of Line Print Terminal (LPT) ports from the client when the user logs on.
-
Client Audio Redirection: Allow or block applications hosted on a server to play sounds through a sound device installed on the client computer. This setting also allows or blocks users from recording audio inputs.
-
Local Remote Data Sharing: Allow or block file or data sharing through the Citrix Workspace™ app for HTML5.
-
Client Clipboard Redirection: Allow or block the clipboard on the client device to be mapped to the clipboard on the server.
-
Client COM Port Redirection: Allow or block the Communication (COM) port redirection to and from the client.
-
Client Drive Redirection: Allow or block the drive redirection to and from the client.
-
Client Printer Redirection: Allow or block printers to be mapped to a server when a user logs on to a session.
-
Multistream: Allow or block the multi-stream feature for the specified users.
-
Client USB Drive Redirection: Allow or block the redirection of USB devices to and from the client.
-
Client TWAIN Device Redirection: Allow or block TWAIN devices, such as digital cameras or scanners, on the client device from the published image processing applications.
-
WIA Redirection: Allow or block the Windows Image Acquisition (WIA) scanner redirection.
-
Drag and Drop: Allow or block the drag and drop action between client and remote applications and desktops.
-
Smart Card Redirection: Allow or block the smart card redirection. Smart card virtual channel is always allowed in Citrix Virtual Apps and Desktops.
-
FIDO2 Redirection: Allow or block Fast Identity Online 2 (FIDO 2) redirections.
-
Configure an ICA access profile by using the CLI
add ica accessprofile <name> [-ConnectClientLPTPorts ( DEFAULT | DISABLED )] [-ClientAudioRedirection ( DEFAULT | DISABLED )][-LocalRemoteDataSharing ( DEFAULT | DISABLED )][-ClientClipboardRedirection ( DEFAULT | DISABLED )][-ClientCOMPortRedirection ( DEFAULT | DISABLED )][-ClientDriveRedirection ( DEFAULT | DISABLED )][-ClientPrinterRedirection ( DEFAULT | DISABLED )] [-Multistream (DEFAULT | DISABLED )][-ClientUSBDriveRedirection ( DEFAULT | DISABLED)] [-ClientTWAINDeviceRedirection ( DEFAULT | DISABLED )][-WIARedirection ( DEFAULT | DISABLED )] [-DragAndDrop ( DEFAULT | DISABLED )] [-SmartCardRedirection ( DEFAULT | DISABLED )]
[-FIDO2Redirection ( DEFAULT | DISABLED )]
ICA latency profile
Configure an ICA latency profile by using the GUI
-
Navigate to NetScaler Gateway > Policies > NetScaler Gateway ICA Policies and Profiles > ICA Latency Profiles.
-
Update the required fields and click Create.
Configure an ICA latency profile by using the CLI
add ica latencyprofile [-l7LatencyMonitoring ( ENABLED | DISABLED )] [-l7LatencyThresholdFactor ] [-l7LatencyWaitTime ] [-l7LatencyNotifyInterval ] [-l7LatencyMaxNotifyCount ]
ICA action
Configure an ICA action by using the GUI
-
Go to NetScaler Gateway > Policies and then click ICA.
-
In the ICA Actions tab, click Add. The Create ICA Action page appears.
-
In the Name field, specify a name for the ICA policy.
-
Next to the ICA Access Profile field, do one of the following:
-
Click the > icon to select an existing ICA access profile.
-
Click Add to create an ICA access profile.
-
-
Create an ICA latency profile to associate it to the ICA action.
-
Click Create.
ICA policy
Configure an ICA policy by using the GUI
-
Navigate to NetScaler Gateway > Policies and click ICA.
-
In the ICA Policies section, click Add. The Create ICA Policy page appears.
-
In the Name field, specify a name for the ICA policy.
-
Next to the Action field, do one of the following:
-
Click the > icon to select an existing action.
-
Click Add to create an action.
-
-
Add an expression.
-
Create a log action.
-
Configure the remaining parameters as required and click OK.
Configure an ICA policy by using the CLI
add ica policy smartaccess_policy -rule TRUE -action smartaccess_action
Bind the ICA policy to a bind point by using the GUI
-
Navigate to NetScaler Gateway > Policies > NetScaler Gateway > ICA Policies and Profiles > ICA Policies. Click Policy Manager.
-
Select the bind point and the virtual server, and click Continue.
-
In the Policy Binding section, select the ICA policy that you need to associate to a bind point.
-
Click Bind and then click Done.
Bind the ICA policy to a VPN virtual server by using the CLI
bind vpn vserver vpnvserver -policy smartaccess_policy -type ICA_REQUEST -priority 10
Configure an ICA action by using the CLI
add ica action smartaccess_action -accessProfileName smartaccess_profile
SmartControl support with Secure HDX™
System requirements
-
Citrix Workspace app for Windows - version 2503 and later.
-
VDA for Windows - version 2503 and later.
-
VDA for Linux - version 2507 and later
Key enhancement
-
Data security: Secure end-to-end connection between NetScaler Gateway and VDA over TLS.
Limitations
-
EDT connections
-
HDX Multi-stream ICA (MSI) connections
-
IPv6 protocol
-
Transparent mode and LAN proxy mode topologies
-
SOCKS protocol