Configure client interception
Configure intranet applications for the Citrix Secure Access™ client
-
One IP address
-
A range of IP addresses
-
A host name
-
When Split Tunnel is ON,
-
Configure the intranet applications.
-
Assign intranet applications to every authentication, authorization, and auditing group.
-
-
When Split Tunnel is OFF,
-
All traffic intercepts through the VPN tunnel.
-
Intranet applications need not be configured.
-
-
When Split Tunnel is REVERSE,
-
Configure the intranet applications. The traffic that is not specified by the intranet applications pass through the VPN tunnel.
-
Assign the intranet applications to be excluded from the VPN to every authentication, authorization, and auditing group.
Important:Interception must be set to TRANSPARENT irrespective of the split tunnel configuration. -
-
When configuring an intranet application, you must select an interception mode that corresponds to the type of plug-in software used to make connections.
-
You cannot configure an intranet application for both proxy and transparent interception.
To create an intranet application for one IP address
-
On the Configuration tab, in the navigation pane, expand NetScaler Gateway Resources and then click Intranet Applications.
-
In the details pane, click Add.
-
In Name, type a name for the profile.
-
In the Create Intranet Application dialog box, select TRANSPARENT.
-
In Destination Type, select IP Address and Netmask.
-
In Protocol, select the protocol that applies to the network resource.
-
In IP Address, type the IP address.
-
In Netmask, type subnet mask, click Create and then click Close.
To configure an IP address range
-
On the Configuration tab, in the navigation pane, expand NetScaler Gateway Resources and then click Intranet Applications.
-
In the details pane, click Add.
-
In Name, type a name for the profile.
-
In Protocol, select the protocol that applies to the network resource.
-
In the Create Intranet Application dialog box, select TRANSPARENT.
-
In Destination Type, select IP Address Range.
-
In IP Start, type the starting IP address and in IP End, type the ending IP address, click Create and then click Close.
To create an intranet application for a host name
-
On the Configuration tab, in the navigation pane, expand NetScaler Gateway Resources and then click Intranet Applications.
-
In the details pane, click Add.
-
In Name, type a name for the profile.
-
In the Create Intranet Application dialog box, select TRANSPARENT.
-
In Destination Type, select hostname.
-
In Protocol, select ANY, click Create, and then click Close.
-
From release 13.0 build 36.27 and later, the Windows VPN plug-in supports host name (FQDN) based rules for split tunneling. You must upgrade both the NetScaler appliance and the Windows VPN plug-in to release 13.0 build 36.27 or later.
-
Wildcard host names are also supported. For example, if an intranet application with the host name “*.example.com” is configured,
a1.example.com,b2.example.com, and so on gets tunneled. -
Host name-based intranet application works only when you have split tunneling set to ON or REVERSE.
Exclude specific domain traffic from client interception
*.example.com, then Citrix Secure Access client intercepts all hostname-based application access that ends with example.com.
rdp.example.com and ftp.example.com, define these domains in the excluded parameter. Citrix Secure Access client bypasses the DNS call for these domains and sends it to the local DNS server instead of the remote DNS server. It does not intercept or tunnel traffic for these child domains.
-
For the Citrix Secure Access client for Windows, you can configure the exclusion of client interception only using registries in NetScaler® Gateway and using both registries and UI in Secure Private Access.
-
For the Citrix Secure Access client for macOS/iOS, you can configure the exclusion of client interception only using the Secure Private Access UI.
To configure exclusion of client interception using registries
-
Configure the
ExcludeDomainsFromRemoteDnsregistry on the end-user device to exclude DNS resolution from being performed by Citrix Secure Access client through a remote DNS server. For more information, see NetScaler Gateway Windows VPN client registry keys. -
Configure the
ExcludeDomainsFromTunnelregistry on the end-user device to exclude traffic from being tunneled by Citrix Secure Access client. For more information, see NetScaler Gateway Windows VPN client registry keys.