
Before you deploy Azure Stack POC (Proof of Concept), make sure your computer meets the following requirements. These requirements apply to the Azure Stack POC only and might change for future releases.

If your server has note this memory available, you will not be able to pass prerequisites. I advise you to follow this good blog post to bypass this check.
For the architecture, the installer will deploy many VMs, and the final architecture will be the following:

You will have 9 VMs, which are the following:
VM Name
Resources
Services
ADVM
4 vCPU / 4096 GB RAM
AD / DNS / DHCP
ACSVM
4 vCPU / 8192 GB RAM
ACS Services
BGPVM
2 vCPU / 4096 GB RAM
BGP
MuxVM
2 vCPU / 4096 GB RAM
SLB Mux
NCVM
2 vCPU / 4096 GB RAM
Network Controller
NATVM
2 vCPU / 4096 GB RAM
NAT
xRPVM
8 vCPU / 8192 GB RAM
Compute RP / Network RP / Storage RP
SQLVM
4 vCPU / 4096 GB RAM
SQL
PortalVM
4 vCPU / 6144 GB RAM
Portal Services / ARM
ClientVM
2 vCPU / 4096 GB RAM
Client
Be sure to have a Global Admin account in an Azure AD directory and have changed his password:
On a server that has a minimum of 3 disques of 250GB minimum, download Azure Stack. When the download is finished, create a folder named AzureStack at the root of C:\ and extract downloaded files here. Execute Microsoft Azure Stack POC.exe:
When it’s done, do a copy of the VHDX WindowsServer2016Datacenter.vhdx and rename it to MicrosoftAzureStackPOCBoot.vhdx:
Now, mount the VHDX by double clicking on it and execute the following command:
bcdboot <your letter>:\Windows
Restart the server. The server will restart on the new VHDX. Do the based configuration and give a password:
When the host is restarted, give it an IP address that can access to Internet, it’s very important to deploy Azure Stack:
It’s now time to start the installation of Azure Stack. To do this, open a PowerShell window and move to the folder that contains the script DeployAzureStack.ps1. Here, execute the following command:
.\DeployAzureStack.ps1 -NATVMStaticIP 172.X.X.X/24 -NATVMStaticGateway 172.X.X.1 –Verbose
Here, I use 2 parameters named –NATVMStaticIP and –NATVMStaticGateway because I don’t have a DHCP server in my LAB. It’s very important that this network has an Internet access. The deployment starts, with the domain name azurestack.local. Some questions will be asked to you, that the admin password (1), the Azure AD account that you create previously (2), which Azure Directory you want to use (3) and if you want to install Azure Stack (which question
(4)). The installation is in progress:
This deployment will take approximatively 2 hours. When the installation is finished, you will have the following message:
Nouw, to connect to the administration interface of Azure Stack, go on the desktop of your server.Normally, you have a shortcut on the desktop to connect to the client VM. Connect to it:
Connect to the portal with using the shortcut located on the desktop, Microsoft Azure Stack POC Portal.url with the Global Admin of your Azure AD:
You have now access to the admin portal of Azure Stack:
Prerequisites
- All the tools are intended for the Microsoft Windows platform.
- Specific pre-requisites will vary from tool to tool. The included README contains links to the documentation (CTX article) for each tool where you can learn about tool-specific requirements.
- You will need Web access to lookup tool-specific Support documentation (CTX article) even though the tools are downloaded and saved in a local folder.
Installing Supportability Pack
1. Unzip the Supportability Pack into local folder of your choice.
2. Open the README.HTML file with any web browser and begin exploring the tools catalog.
3. You will need to one-time unzip/install of individual tools as needed prior to use. Each tool can be found in individual zip file located in the TOOLS subfolder.
How to Use the Supportability Pack
The pack can be extracted to local drive, portable drive, USB stick, etc. Once the SupportabilityPack.zip is extracted please open the README.html in any browser to begin exploring the catalog. You can review the entire set of tools or see a filtered list based on feature or component. All the listed tools are placed into the TOOLS subfolder and need to be unzipped individually as needed. The README.html also contain URL links to the Support documentation (CTX article) for each tool where you can learn more about them.
Security Permissions Required by Supportability Pack
You will need to appropriate privileges to download and unzip the Supportability Pack to a local folder. Please see documentation (CTX article) for each tool for any tool-specific Security permissions.
Data Modified by Supportability Pack
No data is modified when unzipping the Supportability Pack. Once unzipped the Supportability Pack will write a number of HTML documentation files along with a zip files of all the tools in the TOOLS folder. No other system changes are made.
Uninstalling Supportability Pack
The Supportability Pack can be removed by deleting the local folder where it was extracted. Additional steps may be necessary to uninstall some tools based on their specific requirements. Please refer to the relevant Support documentation (CTX article for the specific tool to learn more.
Tools Included
CDFMarker
CDFMonitor
CDFAnalyzer
CDFControl
Citrix Diagnostics Toolkit – 64bit Edition
Cpatch Tool
DSCheck Maintenance Assistant
Export-XenDesktop5Config
FarmTWIHelper
HDX 3D Pro Health Check Tool
HDXMonitor 3.x
IMA Helper
KeepMeLoggedIn
LBDiag – XenApp Load Balancing Diagnostic Tool
License Check Utility
LSQuery
MessageHistory
Policy Reporter – RSOP CtxCseUtil Tool
Port Check Utility
PortICA Log Enabler V3
CTX118837
Print Detective
Printing Tool
Profile Management Configuration Check Tool
PVSDataTools
Quick Launch
RDSWatcher
Receiver Diagnostics Tool
ReceiverCleanupTool
Repair Clipboard Chain
Scout
Session Management Tool
Session State Monitor Tool
StressPrinters
SysPool Tool
UPD Finder – CTXUPDINFO
UPS Print Driver Certification Tool
Web Interface Tracing
WindowHistory
WindowHistory64
XDDBDiag for XenDesktop
XDPing Tool
XenDesktop 5.0 Database Checker Script
XenDesktop Controller Service Log Enabler V3
XenDesktop Service Checker
XenDesktop Virtual Desktop Agent Troubleshooting Utility
Xnapshot
Many of the Web Interface customizations have equivalents in StoreFront by using JavaScript tweaks and Citrix published APIs.
The table contains an overview of the customizations and basic information about how to achieve them.
Folder locations
- For script customizations, append the examples to the script.js file found in
C:\inetpub\wwwroot\Citrix\StoreNameWeb\custom
- For style customization, append the example to the style.css file found in
C:\inetpub\wwwroot\Citrix\StoreNameWeb\custom
- For dynamic content, add the dynamic context to a text file in
C:\inetpub\wwwroot\Citrix\StoreNameWeb\customweb
- If you have a multiserver deployment, you can replicate any changes to other servers from the StoreFront administration console or by using PowerShell.
Note: Web Interface enabled individual users to customize various settings. Currently, StoreFront 3.0 does not have this ability, and while it is possible to add more extensive customization to support it, that is not the focus of this article.
Web Interface Feature
StoreFront Equivalent
Customization with the Management Console
- Layout-low graphics
- Layout-full graphics
- Allow users to choose
Not applicable. StoreFront auto detects and adjusts the UI to device screen.
- Enable search
- Disable search
- Search is enabled by default.
- Disable. To hide the search boxes on the desktop/web UI, add the following style to style.css:
.search-container {
display: none;
}
To hide the search boxes on the phone UI, add:
#searchBtnPhone {
display: none;
}
Enable refresh
Enabled by default (browser refresh).
Enable return to last folder
Not enabled by default.
Enable Return to last folder – To remember the current folder, and return to it on load, add the following to script.js
CTXS.Extensions.afterDisplayHomeScreen = function ()
{
// check if view was saved last time
CTXS.ExtensionAPI.localStorageGetItem("view",
function (view) {
if (view) {
// if view was saved, change to it
CTXS.ExtensionAPI.changeView(view);
}
if (view == "store") {
// if view is store, see if folder was saved
CTXS.ExtensionAPI.localStorageGetItem("folder",
function(folder) {
if (folder != "") {
// if folder was saved, change to it
CTXS.ExtensionAPI.navigateToFolder(folder);
}
}
);
}
// set up monitoring of folder
CTXS.Extensions.onFolderChange = function(folder) {
CTXS.ExtensionAPI.localStorageSetItem("folder",
folder);
};
// set up monitoring of view
CTXS.Extensions.onViewChange = function(newview) {
// don’t retain search or appinfo views
// instead, remember parent view.
if ((newview != "appinfo") &&
(newview != "search")) {
CTXS.ExtensionAPI.localStorageSetItem(
"view", newview);
}
};
});
};
Enable hints
Citrix Receiver makes very limited use of tool tips, as it is targeting touch and non-touch devices. You can add tool tips by custom script.
- Icon view
- Tree view
- Details view
- List view
- Group view
- Set Default view
- (Low graphics) Icon view
- (Low graphics) List view
(Low graphics) Default view
Citrix Receiver has a different UI so these choices do not apply. You can use scripts to disable the Citrix Receiver views or add custom views. You can also specify this by configuration.
The web.config file in the web site directory enables and disables different views and sets the default.
Search for:
<uiViews showDesktopsView="true" showAppsView="true" defaultView="auto" />
Also, search for:
enableAppsFolderView="true"
Note that the Favorite view displays only if subscription is enabled for the store (see the StoreFront administration console).
- Single tab UI
- Tabbed UI
- App tab
- Desktop tab
- Content tab
- (Tab order)
The Citrix Receiver UI is tabbed by default, with apps and content in one tab and desktops in the other. There is also an optional Favorite tab.
- Header logo
- Text color
- Header background color
- Header background image
Equivalents for colors and logos using the StoreFront administration console. Click Customize Website Appearance in the StoreFront administration console’s Actions pane and make your customizations on the screen that displays.
You can set the header to a background image using a style customization. For example
.theme-header-bgcolor {
background-image: url(‘spirals.png’);
}
- Pre-logon welcome message
(Pre-locale)- Title
- Text
- Button label
By default, there is no separate pre-logon screen.
This example script adds a click-through message box:
var doneClickThrough = false;
// Before web login
CTXS.Extensions.beforeLogon = function (callback) {
doneClickThrough = true;
CTXS.ExtensionAPI.showMessage({
messageTitle: "Welcome!",
messageText: "Only for WWCo Employees",
okButtonText: "Accept",
okAction: callback
});
};
// Before main screen (for native clients)
CTXS.Extensions.beforeDisplayHomeScreen
= function (callback) {
if (!doneClickThrough) {
CTXS.ExtensionAPI.showMessage({
messageTitle: "Welcome!",
messageText: "Only for WWCo Employees",
okButtonText: "Accept",
okAction: callback
});
} else {
callback();
}
};
- Logon screen title
- Logon screen message
- Logon screen system message
There are four areas for customization on the logon screen(s). Top and bottom of screen (header and footer) and top and bottom of the logon box itself.
.customAuthHeader,
.customAuthFooter
.customAuthTop,
.customAuthBottom {
text-align: center;
color: white;
font-size: 16px;
}
Example script (static content)
$(‘.customAuthHeader’).html("Welcome to ACME");
Example script (dynamic content)
function setDynamicContent(txtFile, element) {
CTXS.ExtensionAPI.proxyRequest({
url: "customweb/"+txtFile,
success: function(txt) {$(element).html(txt);}});
}
setDynamicContent("Message.txt", ".customAuthTop");
Note: Do not explicitly include dynamic content in the script, or put it in the custom directory, as changes made here force all clients to reload the UI. Put dynamic content in the customweb directory.
- Application screen welcome message
- Application screen system message
See the examples for CustomAuth welcome screen above.
See examples for dynamic content above. Use ‘#customTop’ rather than ‘.customAuthTop’ to place content on the home screen.
Footer text (all screens)
Example script:
#customBottom {
text-align: center;
color: white;
font-size: 16px;
}
Example static content using a script:
$(‘#customBottom’).html("Welcome to ACME");
Features with no direct equivalent
- Logon screen without headers
- Logon screen with headers
(including messages)
There is no direct equivalent in StoreFront. However, you can create custom headers. See “Logon Screen Title” above.
User settings
By default, there are no user settings. You can add menus and buttons from JavaScript.
Workspace control
Equivalent functionality for administrator settings. The extension APIs allow significant additional flexibility.
Deep Customizations (code)
ICA File generation hooks and other call-routing customizations.
Equivalent or better APIs.
http://www.citrix.com/go/citrix-developer/storefront-receiver-developer-community/store-customization-sdk.html
Authentication customizations
Equivalent or better APIs.
JSP/ASP source access
There are no equivalent APIs on StoreFront, as the UI is not rendered in the same way. There are many JavaScript APIs to enable customization of the UI.
Objective
This article describes how to customize a different logon page for each VPN virtual server hosted on NetScaler Gateway, and how to configure the NetScaler appliance to redirect users to the customized page based on the Fully Qualified Domain Name (FQDN).
Prerequisites
The NetScaler Gateway must be licensed for the Responder Feature to address this scenario. To ensure that the NetScaler Gateway appliance is licensed for the Responder feature, complete one of the following tasks:
-
From the GUI, expand the System node and click Licenses.
In the Licenses page, verify if the Responder feature is enabled, as shown in the following screen shot:
-
Run the following command from the Command Line Interface:
>show license
Background
There are situations where more than one VPN virtual servers are hosted on the NetScaler Gateway appliance. You might want to customize a different logon page for each VPN virtual server.
The following VPN virtual servers are hosted on the NetScaler Gateway appliance.
VPN virtual server "example.com" is configured for Lightweight Directory Access Protocol (LDAP) authentication.
The logon page is displayed as shown in the following screen shot:
When VPN virtual server "example.org" is configured for RADIUS and LDAP authentications, the logon page is displayed as shown in the following screen shot:
You must change the passcode field to password on the VPN virtual "server example.com".
However, if the logon page is customized, it affects the VPN virtual server "example.org". It is recommended to keep the logon page unchanged, otherwise it appears as shown in the following screen shot:
Instructions
To customize a different logon page for each VPN virtual server hosted on the NetScaler Gateway appliance and to configure the NetScaler appliance to redirect users to the customized page based on the FQDN, complete the following procedure:
-
To enable the Responder feature on the NetScaler appliance, complete one of the following tasks:
From the Command Line interface, run the following command:
>enable feature ResponderOR
From the GUI, navigate to System > Settings. In Modes and Features, select Configure Advanced features (ensure that you select the Responder feature), click OK, and then click Close.
-
You can have multiple index.html and login.js files, because you can rename them.
-
Retain the default index.html and login.js files for VPN virtual server "example.org".
-
Create index_modified.html and login_modified.js files for the VPN virtual server "example.com".
-
Modify the line 7 of index_modified.html to refer to the new login_modified.js file as shown in the following screen shot:
-
-
Customize the logon page for each VPN virtual server (example.com and example.org) by referring to the following articles:
-
For Access Gateway Enterprise Edition/NetScaler software release 8.1 to 9.1: CTX118305 – Customizing Access Gateway Enterprise Edition Logon Page
-
For Access Gateway Enterprise Edition/NetScaler software release 9.2: CTX126206 – How to Customize the Logon Page of a Access Gateway Enterprise Edition Release 9.2 Appliance
-
-
To configure a Responder Action where you redirect users accessing https://example.com to the modified index.html file, complete one of the following tasks:
From the command line interface run:
>add responder action redirect_remotesite redirect "\"https://example.com/vpn/index_modified.html\""OR
From the GUI:
-
Select Responder > Actions > Add.
-
Enter a name for the action.
-
Select Redirect under Type*.
-
Enter the target URL as "https://example.com/vpn/index_modified.html".
Note: Ensure that you include the quotes.
-
-
To configure a Responder Policy to define the condition that redirects users, complete one of the following tasks:
Note: Ensure you include the URL condition, otherwise you might experience issues such as loops.From the command line interface, run the following command:
>add responder policy redirect_remotesite_policy "HTTP.REQ.HOSTNAME.EQ(\"example.com\") && HTTP.REQ.URL.CONTAINS(\"index.html\")" redirect_remotesite_actionOR
From the GUI, complete the following procedure:
-
Select Responder > Policies > Add.
-
Enter a name for the policy.
-
In the Action field, select the action you defined previously.
-
In the Expression field, enter the following expression:
HTTP.REQ.HOSTNAME.EQ("example.com") && HTTP.REQ.URL.CONTAINS("index.html")
-
-
To bind the Policy Globally, complete one of the following tasks.
From the command line interface, run the following command:
>bind responder global redirect_remotesite_policy 1 END -type REQ_DEFAULTOR
From the GUI, complete the following procedure:
-
Go to Responder > Policies > Click Policy Manager.
-
Select Default Global > Insert Policy and select the Responder Policy you created.
-
Double-click the Priority field to define the Priority.
-
Click Apply Changes.
-
Click Close.
-
Users accessing https://example.org are redirected to https://example.org/vpn/index.html.
-
Users accessing https://example.com are redirected to https://example.com/vpn/index_modified.html.
-
-
To make the changes persistent after you restart the appliance, complete the following tasks:
-
Decide the name of the new folder to hold the NetScaler Gateway virtual server customized files.
For example, the folder name is customizations in the /var directory: -
Using a text editor, create the text file named rc.netscaler with the following single line of content:
#cp -R /var/customizations/* /netscaler/ns_gui/Note: Make sure there are no blank lines after this line.
-
-
Connect to the appliance using a secure copy utility like WinSCP, and copy all the folders from directory /netscaler/ns_gui to directory /var/customizations.
-
Using WinSCP, copy the rc.netscaler file to the /nsconfig folder of the appliance.
-
Restart the appliance.
By default this will be located at “C:\inetpub\wwwroot\Citrix\<StoreName>Web\contrib”. If you have not created any customizations, select everything in the file and replace with the following:
(function ($) {
$.localization.customStringBundle('en', {
YouAreLoggedOff: 'You have logged off successfully. <br>'
+'You are being redirected to <Enter your web page here or delete this line>'
+''
+'window.location.replace("http://www.czerno.com");'
+''
});
})(jQuery);
“Activate” Option in Web Page – Disable
From Citrix Discussions: to disable the “activate…”; function for Citrix receiver for windows that is visible when a user clicks their username in the upper right hand corner of Receiver for Web:
- Browse to C:\inetpub\wwwroot\Citrix\”NameoftheStoreWeb”\
- Open config
- Locate the following line.
<receiverConfiguration enabled=”true” downloadURL=”ServiceRecord/GetDocument/receiverconfig.cr” /> - Change the true to false
Citrix CTX139762 How to Configure StoreFront to Start Published Desktops in Full Screen Mode: This article describes how to configure StoreFront to start published desktops in Full Screen Mode.
- Open the file C:\inetpub\wwwroot\Citrix\Store\App_Data\default.ica on the StoreFront server(s) with notepad (as Administrator)
- Add the line:
[Application] DesktopViewer-ForceFullScreenStartup=On
- In older versions of StoreFront, it should be true instead of On.
- Save the file
- Open the command prompt (cmd) and run iisreset.
By default, if only a single desktop is published to the user, Receiver for Web will auto-launch it. You can change this behavior by editing the Receiver for Web site configuration file or by using the GUI Assistant:
- On the StoreFront server, use a text editor to open the web.config file for the Receiver for Web site, which is typically located in the C:\inetpub\wwwroot\Citrix\storenameWeb\ directory, where storename is the name specified for the store when it was created.
- Search for autoLaunchDesktop near line 58.

- Change the value of the autoLaunchDesktopattribute to false to prevent Receiver for Web from automatically starting and accessing a desktop when a user logs on to the site and only a single desktop is available for that user.
Note: The Receiver Self-Service interface does not auto-launch desktops.
NetScaler Gateway Universal Licenses
For basic ICA Proxy connectivity to XenApp/XenDesktop, you don’t need to install any NetScaler Gateway licenses on the NetScaler appliance. However, if you need SmartAccess features (e.g. EPA scans) or VPN then you must install NetScaler Gateway Universal licenses. These licenses are included with some editions of XenApp, XenDesktop, XenMobile, and the Platinum version of NetScaler.
When you create a NetScaler Gateway Virtual Server, the ICA Only setting determines if you need NetScaler Gateway Universal licenses or not. If the Virtual Server is set to ICA Only then you don’t need licenses. But if ICA Only is set to false then you need a NetScaler Gateway Universal license for every user that connects to this NetScaler Gateway Virtual Server. Enabling ICA Only disables all SmartAccess, SmartControl, and VPN features. 
After NetScaler Gateway Universal licenses are installed on the appliance, they won’t necessarily be available for usage until you make a configuration change as detailed below:
- On the left, expand System and click Licenses. On the right, in the Maximum NetScaler Gateway Users Allowed field is the number of licensed users for NetScaler Gateway Virtual Servers that are not set to ICA Only.

- On the left, under NetScaler Gateway, click Global Settings.

- In the right column of the right pane, click Change authentication AAA settings.

- Change the Maximum Number of Users to your licensed limit. This field has a default value of 5 and administrators frequently forget to change it thus only allowing 5 users to connect.

- If desired, check the box for Enable Enhanced Authentication Feedback. Click OK.
set aaa parameter -enableEnhancedAuthFeedback YES -maxAAAUsers 200
- Then edit the NetScaler Gateway Virtual Server.

- In the Basic Settings section, click the pencil icon near the top right.

- Click More.

- In the Max Users field, either enter 0 (for unlimited/maximum) or enter a number that is equal to or less than the number of licensed users. Click OK.

set vpn vserver gateway.corp.com -maxAAAUsers 0
Create Gateway Virtual Server
- Create a certificate for the NetScaler Gateway Virtual Server. The certificate must match the name users will use to access the Gateway. For email discovery in Citrix Receiver, the certificate must have subject alternative names (SAN) for discoverReceiver.email.suffix (use your email suffix domain name). If you have multiple email domains then you’ll need a SAN for each one.


- On the left, right-click NetScaler Gateway and click Enable Feature.

- On the left, expand NetScaler Gateway and click Virtual Servers.

- On the right, click Add.

- Name it gateway.corp.com or similar.
- Enter a new VIP that will be exposed to the Internet. Note: new to NetScaler 11.0 is the ability to set it to Non Addressable, which means you can place it behind a Content Switching Virtual Server.
- Click More.

- In the Max Users field enter 0.
- In the Max Login Attempts field, enter your desired number. Then enter a timeout in the Failed Login Timeout field.

- Check the box next to ICA Only. This option disables SmartAccess and VPN features but does not require any additional licenses.
- Check the box next to DTLS and click OK. DTLS enables UDP Audio and Framehawk.

- In the Certificates section, click where it says No Server Certificate.

- Click the arrow next to Click to select.

- Select a previously created certificate that matches the NetScaler Gateway DNS name and click Select.

- Click Bind.

- If you see a warning about No usable ciphers, click OK.

- Click Continue.

- In the Authentication section, click the plus icon in the top right.

- Select LDAP, select Primary and click Continue.

- If you used the authentication dashboard to create the LDAP server then you probably haven’t create the corresponding policy yet. Click the plus icon to create a new policy.

- Use the Server drop-down to select the previously created LDAP server.
- Give the policy a name. It can match the LDAP Server name.
- In the Expression box, enter ns_true or select it from the Saved Policy Expressions drop-down. Click Create.

- Click Bind.

- Or for two-factor authentication, you will need to bind two policies to Primary and two polices to Secondary:
- Primary = LDAP for Browsers (User-Agent does not contain CitrixReceiver)
- Primary = RADIUS for Receiver Self-Service (User-Agent contains CitrixReceiver)
- Secondary = RADIUS for Browsers (User-Agent does not contain CitrixReceiver)
- Secondary = LDAP for Receiver Self-Service (User-Agent contains CitrixReceiver)

- Click Continue.

- Scroll down to the Profiles section and click the pencil icon.

- In the TCP Profile drop-down select nstcp_default_XA_XD_profile and click OK.

- In the Policies section, click the plus icon near the top right.

- Select Session, select Request and click Continue.

- Click the arrow next to Click to select.

- Select one of the Receiver session policies and click Select. It doesn’t matter which order you bind them.

- There’s no need to change the priority number. Click Bind.

- Repeat these steps to bind the second policy. In the Policies section, click the plus icon near the top right.

- Select Session, select Request and click Continue.

- Click Add Binding.

- Click the arrow next to Click to select.

- Select the other Receiver session policy and click Select.

- There’s no need to change the priority number. Click Bind.

- The two policies are mutually exclusive so there’s no need to adjust priority. Click Close.

- On the right, in the Advanced Settings section, click Published Applications.

- Click where it says No STA Server.

- Add a Controller in the https://<Controller_FQDN> or http://<Controller_FQDN> format, depending on if SSL is enabled on the XenApp Controller or not. This must be a FQDN or IP address. Short names don’t work.
- For the Address Type, select IPV4. Click Bind.

- To bind another Secure Ticket Authority server, on the left, in the Published Applications section, click where it says 1 STA Server.

- Click Add Binding. Enter the URL for the second controller.

- The State is probably down. Click Close.

- In the Published Applications section, click STA Server.

- Now they should be up and there should be a unique Auth ID for each server. Click OK.

add vpn vserver gateway.corp.com SSL 10.2.2.200 443 -icaOnly ON -dtls ON -tcpProfileName nstcp_default_XA_XD_profile bind vpn vserver gateway.corp.com -policy "Receiver Self-Service" -priority 100 bind vpn vserver gateway.corp.com -policy "Receiver for Web" -priority 110 bind vpn vserver gateway.corp.com -policy Corp-Gateway -priority 100 bind vpn vserver gateway.corp.com -staServer "http://xdc01.corp.local" bind vpn vserver gateway.corp.com -staServer "http://xdc02.corp.local" bind vpn vserver gateway.corp.com -portaltheme X1
- Perform other normal SSL configuration including: disable SSLv3, bind a Modern Cipher Group, and enable Strict Transport Security.
bind ssl vserver MyvServer -certkeyName MyCert set ssl vserver MyvServer -ssl3 DISABLED -tls11 ENABLED -tls12 ENABLED unbind ssl vserver MyvServer -cipherName ALL bind ssl vserver MyvServer -cipherName Modern bind ssl vserver MyvServer -eccCurveName ALL bind vpn vserver MyvServer -policy insert_STS_header -priority 100 -gotoPriorityExpression END -type RESPONSE
Verify SSL Settings
After you’ve created the Gateway Virtual Server, run the following tests:
- Citrix CTX200890 – Error: “1110” When Launching Desktop and “SSL Error” While Launching an Application Through NetScaler Gateway: You can use OpenSSL to verify the certificate. Run the command:
openssl s_client -connect gateway.corp.com:443.Replace the FQDN with your FQDN. OpenSSL is installed on the NetScaler or you can download and install it on any machine. - Go to https://www.digicert.com/help/ to verify the certificate chain.

- Go to https://www.ssllabs.com/ssltest/ and check the security settings of the website. Citrix Blogs – Scoring an A+ at SSLlabs.com with Citrix NetScaler

Gateway Portal Theme
Citrix Blog Post Branding your Deployment Part 2: Matching NetScaler to StoreFront explains NetScaler Gateway Portal Themes, how to edit the Portal Theme CSS, and warns about GUI changes overwriting CSS file changes.
If you want the logon page for NetScaler Gateway to look more like StoreFront 3.0, NetScaler 11.0 build 62 and newer have a built-in X1 theme:
- Go to NetScaler Gateway > Virtual Servers and edit an existing Virtual Server.


- On the right, in the Advanced Settings section, click Portal Themes.

- On the left, click where it says No Portal Theme.

- Click to select.

- Select the built-in X1 theme and click Select.

- Click Bind.

- Click Done.

bind vpn vserver gateway.corp.com -portaltheme X1
- When you access the NetScaler Gateway login page you’ll see the theme.

You can also create your own theme by starting from one of the built-in themes:
- Go to NetScaler Gateway > Portal Themes.

- On the right, click Add.

- Give it a name and select X1 as the Template Theme.
- In the Look and Feel section there are two sub-sections: one for Home Page and one for Other Pages. In each of these sections is an Attribute Legend link that shows you what you can edit.
- The Home Page is for Unified Gateway (aka VPN Clientless Access).


- If you want to modify the logon page, use the Other Pages sub-section.


- Make changes as desired and click OK.

- In the Locale section, select a language and click OK.

- On the right, in the Advanced Settings section, click Login Page.

- Make changes as desired (e.g. Password Field Titles) and click OK.

- At the top of the screen, click the link to Click to bind and view configured theme.

- Select a Gateway Virtual Server and click Preview.

- The logon page is displayed.

- You could go to /var/netscaler/logon/themes/StoreFront3/css and make more changes to custom.css but this file gets overwritten any time you make a change in the Portal Themes section of the NetScaler GUI.

Jason Samuel – How to fix Green Bubble theme after upgrading to NetScaler 11 Unified Gateway details the following:
- Change the NetScaler Unified Gateway logo to match the older Citrix Receiver logo.

- Restore the older favicon.

- And other observations regarding the Green Bubbles theme in NetScaler 11.0
SSL Redirect – Down vServer Method
This procedure details the Down vServer method of performing an SSL redirect. An alternative is to use the Responder method.
- On the left, expand Traffic Management, expand Load Balancing, and click Virtual Servers.
- On the right, click Add.

- Give it a name of Gateway-HTTP-SSLRedirect or similar.
- Set the IP Address so it matches the VIP of the NetScaler Gateway vServer. Click OK.

- Do not select any services. This redirect only works if the vServer is Down. Click Continue.

- On the right, in the Advanced Settings column, click Protection.

- Enter https://gateway.corp.com or similar into the Redirect URL Click Save.

- Then click Done.

add lb vserver gateway.corp.com-HTTP-SSLRedirect HTTP 10.2.2.200 80 -redirectURL "https://gateway.corp.com"
- All SSL Redirect Virtual Servers are supposed to be Down. They don’t work if they are not down. By contrast, the Responder method uses redirect Virtual Servers that are Up.

Public DNS SRV Records
For email-based discovery, add a SRV record to each public email suffix DNS zone. Here are sample instructions for a Windows DNS server:
- In Server Manager, click Tools > DNS Manager
- In the left pane of DNS Manager, select your DNS domain in the forward or reverse lookup zones. Right-click the domain and select Other New Records.

- In the Resource Record Type dialog box, select Service Location (SRV) and then click Create Record.

- In the New Resource Record dialog box, click in the Service box and enter the host value _citrixreceiver.
- Click in the Protocol box and enter the value _tcp.
- In the Port number box, enter 443.
- In the Host offering this service box, specify the fully qualified domain name (FQDN) for your NetScaler Gateway Virtual Server in the form servername.domain (e.g. gateway.company.com)

Block Citrix VPN for iOS
Andrew Morgan Blocking the new Citrix VPN iOS connection to Netscaler gateway and Citrix CTX201129 Configuration for Controlled Access to Different VPN Plugin Through NetScaler Gateway for XenMobile Deployments: do one or both of the following:
- Create an AppExpert > Responder > Policy with Action = DROP and Expression =
REQ.HEADER("User-Agent").CONTAINS("CitrixReceiver/NSGiOSplugin"). Either bind the Responder Policy Globally or bind it to the Gateway vServers.
- In your Gateway Session Policies, do not set the Plugin type to Windows/Mac OS X.

View ICA Sessions
To view active ICA sessions, click the NetScaler Gateway node on the left and then click ICA Connections on the right.

show vpn icaconnection
Customize Logon Page
Logon Page Labels
When two factor authentication is configured on NetScaler Gateway, the user is prompted for User name, Password, and Password 2.

The Password field labels can be changed to something more descriptive, such as Active Directory or RSA:

To change the labels, edit a Portal Theme:
- Go to NetScaler Gateway > Portal Themes and edit an existing theme. You can’t edit the built-in themes so you’ll have to create one if you haven’t already.

- On the right, in the Advanced Settings column, click Login Page.

- In the Login Page section, change the two Password fields to your desired text.
- Click OK.

- In the Portal Theme section you can Click to bind and view configured theme to Preview your changes.

- On Platinum Edition appliances, you might have to invalidate the loginstaticobjects Content Group (Optimization > Integrated Caching > Content Groups) before the changes appear. This seems to be true even if Integrated Caching is disabled.

Logon Security Message (Disclaimer, EULA)
You can force users to agree to a EULA before they are allowed to login.

Clicking the Terms & Conditions link allows the user to view the EULA text that you have entered.

Do the following to configure the EULA:
- Go to NetScaler Gateway > Resources > EULA.

- On the right, click Add.

- Give the EULA a name and enter some text. You can even enter HTML code. See the example posted by Chris Doran at Citrix Discussions.

- Click Create.

- Edit a Gateway Virtual Server.

- On the right, in the Advanced Settings column click EULA.

- Click where it says No EULA.

- Click the arrow next to Click to select.

- Select the EULA and click Select.

- Click Bind.

Logon Page Links
Citrix CTX202444 How to Customize NetScaler Gateway 11 logon Page with Links shows how to add links to the NetScaler Gateway 11 logon page.
- In WinSCP, go to /netscaler/ns_gui/vpn/js and edit the file gateway_login_form_view.js.

- Scroll down to line 40 and insert the code copied from the article. Feel free to change the link.

- Scroll down to line 140 and insert the line form.append(link_container);
- Since this is an if block, insert the line in both the if section and the else section (line 148). Both should be after the append field_login line and before the append(form) line.

- Save the file and verify your results.

- If you reboot your appliance then your changes will be lost. To preserve your changes after a reboot, copy the modified file to /var.


- Then edit /nsconfig/rc.netscaler and add a cp line to copy the modified file from /var to /netscaler/ns_gui/vpn/js. This is the same procedure as older NetScaler firmware. Feel free to reboot your appliance to confirm that the changes are still applied.


UDP Audio Through Gateway
From John Crawford at Citrix Discussions and Marius Sandbu Enabling Citrix Receiver audio over Netscaler Gateway with DTLS
Note: If you have NetScaler 11 build 62 or newer then enabling DTLS on the Gateway also enables Framehawk. See VDA > Framehawk for Framehawk configuration.
Requirements for UDP Audio:
- Citrix Receiver 4.2 or newer
- NetScaler Gateway 10.5.e (enhancement build) or NetScaler 11
- UDP 443 allowed to NetScaler Gateway Virtual Server
- UDP 16500-16509 allowed from NetScaler SNIP to VDAs
To enable UDP Audio through Gateway, make changes on both the NetScaler Gateway Virtual Server and in Receiver:
- Edit the NetScaler Gateway Virtual Server. In the Basic Settings section click the edit (pencil) icon.

- Click More.

- Enable the DTLS option and click OK.

- After enabling DTLS, it probably won’t work until you unbind the Gateway certificate and rebind it.

- Copy the receiver.admx (and .adml) policy template into PolicyDefinitions if you haven’t already.
- Edit a GPO that applies to Receiver machines. You can also edit the local GPO on a Receiver machine.
- Go to Computer Configuration > Policies > Administrative Templates > Citrix Components > Citrix Receiver.
- Edit the setting Client audio settings.

- Enable the setting.
- Set audio quality as desired. Higher quality = higher bandwidth.
- Check to Enable Real-Time Transport.
- Check to Allow Real-Time Transport through Gateway. Click OK.

Next step
Configure StoreFront to use NetScaler Gateway
Unified Gateway
Unified Gateway FAQ at docs.citrix.com
The Unified Gateway wizard in NetScaler 11 relies on Clientless Access and the built-in portal. See Jens Trendelkamp NetScaler Gateway Single Sign-On to Storefront in Clientless Access Mode to learn how to enable iFrame in StoreFront so it can be embedded in the Clientless Access portal.

Unified Gateway means Content Switching for NetScaler Gateway. There are two methods of Content Switching:
- Create a Content Switching Virtual Server that has a Content Switching policy that directs requests to a NetScaler Gateway
- Create a NetScaler Gateway Virtual Server that has Content Switching policies that direct requests to Load Balancing Virtual Servers.
In either case you can only have one Gateway Virtual Server in the Content Switching configuration.
Content Switching vServer with Gateway as Target
- When creating a Gateway Virtual Server, you can change the IP Address Type to Non Addressable. This means you can only access the Gateway through a Content Switching Virtual Server.

- On the left, go to Traffic management > Content Switching > Policies.

- On the right click Add.

- Give the policy a name.
- Click the plus icon next to the Action field.

- Give the Action a name.
- Change the selection to NetScaler Gateway Virtual Server.
- Click the arrow to select a Gateway Virtual Server and click Create.

- Back in the policy screen, enter an expression. There are several options for selecting traffic that should be directed to the Gateway:
- Hostname
- The built-in is_vpn_url expression
- Any path that starts with /Citrix/.
http.REQ.HOSTNAME.SET_TEXT_MODE(IGNORECASE).EQ("mygateway.corp.com") && (is_vpn_url || http.REQ.URL.PATH.SET_TEXT_MODE(IGNORECASE).STARTSWITH("/Citrix/")) - Click Create when done.

- Add or Edit a Content Switching Virtual Server.

- Click where it says No Content Switching Policy Bound.

- Click the arrow to select a Content Switching policy and click Bind.

Gateway vServer with Load Balancing vServer as Target
Another option is to bind Content Switching policies to a Gateway Virtual Server:
- On the left, go to Traffic Management > NetScaler Gateway > Policies > Content Switching.

- On the right, click Add to create a Content Switching Policy with an Action that points to a Load Balancing Virtual Server.

- On the left, go to NetScaler Gateway > Virtual Servers.

- On the right, edit an existing NetScaler Gateway Virtual Server.

- On the right in the Advanced Settings section, click Content Switching Policies.

- Click where it says No Content Switching Policies.

- Select a Content Switching policy that sends traffic to a Load Balancing Virtual Server and click Bind.

- Repeat for additional Content Switching policies that redirect to Load Balancing Virtual Servers. You cannot bind Content Switching policies that redirect to NetScaler Gateway Virtual Servers.
SNI: What is it and what can it do for you?
Citrix NetScaler gives you the ability to leverage multiple SSL certificates on one Virtual Server by using a great feature that has been available since version 9.2. This feature is known as SNI.
So, what is SNI?
SNI is also known as Server Name Indication, and is an extension to the TLS networking protocol. It works by way of the Client (in most cases browsers), indicating the hostname it is attempting to connect to at the beginning of the SSL handshaking process.
When the Client begins the SSL handshake process with its Hello and requested Server Name extension, the NetScaler will match the server name through the SNI certificates bound to the requested Virtual Server. If no match is found, the NetScaler then returns an unrecognized name message and will reset the connection.
If the Client begins the SSL handshake process with its Hello and NO requested Server Name extension, the default certificate bound to the Virtual Server is returned.
What can it do for you?
The value-add to this great feature allows Cloud Networking Administrators to leverage only one IP Address and use multiple SSL certificates for their load-balanced backend servers.

Here is how to apply SNI SSL certificates to your virtual server:
Scenario:
Content Switching Virtual Server (more on Content Switching: http://bit.ly/1T73M3i)
- Content switching is leveraged to identify content on the HTTP header (host), and direct it to the correct backend server.

3 Back-end Web Servers – Blue Apache Web Server, Green Apache Web Server, Red Apache Web Server.
Each of the backend web servers is NON-Addressable. They are only accessible when referenced within the NetScaler.

In this case, each of the NON-Addressable virtual servers are attached to a content switching action.
Step by Step Guidance:
NOTE: Guide assumes that the following has been completed.
- All SSL certificates have been validated, and installed on the NetScaler.
- All backend virtual servers have been configured on the NetScaler (Non-Addressable).
Step 1: Add the Content Switching Virtual Server.


Step 2: Add the relevant policies to the content switching virtual server.



Step 3: Click the edit (pencil) button of the SSL Parameters advanced setting. Next, click the check box next to the SNI Enable feature and click OK.


Step 4: Add the Certificates Advanced Setting, and click the No Server Certificate box to add the certificates used for each back end server.


Step 5: Click the > symbol, and check the Server Certificate for SNI check box to add each of the SSL certificates. Repeat these steps as needed for all other SSL certificates.

How to test:
NOTE: A DNS records have been created for each of the backend web servers with the same IP address as they are uniquely identified via the layer7 HTTP header.
IE: blue.training.lab = 10.10.10.10 red.training.lab = 10.10.10.10 green.training.lab = 10.10.10.10
Using content switching and the SNI Server Name Extension, the Citrix NetScaler is able to deter where to forward the client request to.
Example of the client connecting to the Blue web server to the same IP address using a unique SSL certificate and SNI Server Name extension:


Example of the client connecting to the Green web server to the same IP address using a unique SSL certificate and SNI Server Name extension:


Example of the client connecting to the Red web server to the same IP address using a unique SSL certificate and SNI Server Name extension:


