NetScaler is the industry’s leading web and application delivery controller that maximizes the performance and availability of all applications and data, and also provide secure remote access to any application from any device type. NetScaler products are easily selected by determining the edition providing functional needs and the appropriate physical or virtual appliance platform to fulfill performance needs.

Share tech news, updates, or what's on your mind.

Sign up to Post

I have two domains with trust between them. VDIs/HSDs are in one domain and users are in another domain. When I do LDAP configuration to which domain my Citrix NetScaler should be pointing to? What is the best practice?
Citrix XenAppXenDesktop 7.15 LTSR
Windows 2016 HSD
Windows 10 VDI
Citrix NetScalser 12.x VPX

I have  Citrix version 6.0 with NetScaler (5500). How can I connect directly to a Citrix server without pass by NetScaler?

We have 3 published virtual Desktop icons when logging into Citrix NetScaler Gateway.  

1 - Published Virtual Desktop icon = Windows 2012 R2 Server
2 - Published Virtual Desktop icon = Windows 10 Pro. Desktop
3 - Published Virtual Desktop icon = Windows 7 Pro. Desktop

I have a problem that is Laptop specific where when I try to launch the 201 R2 icon from the NetScaler portal (version 12.0) the Citrix ica session opens and then freezes after a couple of seconds and then the session disappears/closes before I see the desktop screen.  Usually the 2012 R2 icon is the only one that UI use; but, I have not used it in a while and now it is just not opening for me.

The other 2 icons are opening up just fine on the same laptop.  If I use other computers or laptops the same 2012 R2 icon comes up and works well.  And if I login as a different user on my 'rouge' laptop (test user) I have the same problem; hence it appears that the proble is specific to the laptop.  What can I do to have the 2012 R2 icon work on my laptop?

The Citrix .ica session launches then it closes after a couple of seconds.  I have seen that before and the fix was to uninstall receiver and to re-install it but that did not work in this case.  Equally important, this problem happens when logged in to the NetScaler Gateway while using different internet browsers (Chrome, internet explorer, Edge); but, it is laptop specific.
We are moving to Netscaler 11.1 using StoreFront 3.15 with a backend of XenApp 6.5.

Trying to find the best way/documentation to understand the best way to follow a session.  It used to be use the Secure Gateway logs and the STA logs.  But with the new flow, having a hard time finding logs to follow a session from end to end.  Or, is this type of logging not on by default and needs to be enabled.  Any help is appreciated.

It will help once I get logging into Splunk for the NetScaler and StoreFront, but as noted until I know what logs are useful and how to get them there, this isn't going to help me.

Once we get this working, will need to complete our new XenApp 7.15 and provision endpoints there from NetScaler and Storefront, so really would like to get a handle on the flow now.

Thanks in advance.
On a Netscaler MPX v11.x is it possible to see the bandwidth being used by a particular VIP?
How about for a particular SNIP?
We have newly deployed Xenapp 7.15 LTSR CU3 on Windows 2016 OS. While launching published applications through Storefront from Win 2016 VDA, our session stuck on Windows Sign in prompt. We are not getting user id & password option. We do have RDS security policy is in place “Always prompt for password upon connection”.
But while launching published desktops, we are getting prompt to enter userid & password options. Does anyone has seen this issue?
We are using NetScaler VPX.
We identified the Issue: We do have RDS security policy is in place “Always prompt for password upon connection”.
If we disabled this policy, issues has been resolved.
But as per security team, this policy is must.
Do we have any Citrix article where it confirmed that, this policy has to disable?
We are planning a VDI solution using Citrix Xendesktop. As part of the VDI solution we have an internal Netscaler VPX to load balance the Citrix Storefront servers. As part of the deployment we also have two exchange servers and I am looking for a load balancing solution for the Exchange servers also. my question is if I can use the same Netscaler Appliance that I wil be using for Citrix Storefront servers to load balance exchange servers as well. I may have to create an additional Virtual server on VPX and does that impact any licenses for the Netscaler or can I use it without any additional cost.
we are planning to deploy a VDI solution using the Citrix xendesktop and Xenapp. we have purchased a Netscaler VPX to load balance the storefront server. we will have two storefront servers load balanced by the netscaler VPX. since it a small environment for 300 clients we are planning to install the storefront and the delivery controllers on the same machines. now my question is can I load even the delivery controllers that the storefront server uses by the same netscaler vpx.

I want to create two VIP on the netscaler VPX. one to load balance storefront servers that users use. the second VIP that Storefront used to load balance the Delivery controllers that are installed on the same servers.

Shall we use or any free Domain names for Testing Purpose? Shall we get public SSL certs for those domains?
I would like to test Citrix NetScaler Gateway URL with FAS and SSO in Citrix & Azure Cloud. For this I need one Domain name with public SSL Certificates.
Please suggest any Free Domain names which can used for 10 to 30 days over internet with above features.
we have 1 internal ADFS Server on our primary data center and secondary ADFS in our secondary data center, and traffic is redirected from office 365 to our internal ADFS Server through netscaler which is acting as reverse proxy.

In order to protect our internal ADFS server from any any outside sporadic attack, we need to set up external proxy adfs server

can you define the steps needed to streamline traffic from external ADFS Proxy server to our internal ADFS Server.

regarding setting up relying party trust etc.
We currently have a few Netscaler MPX 9700 FIPS devices with HA Configured nodes running version

We need to apply a company WildCard certificate generated from a 3rd party (GeoTrust) for use with the Managment Console (GUI) as well as be available for the defined sites/endpoints on the system that will be used with StoreFront.

Since this is a FIPS Device, I am finding a bit confusing to determine the best approach to initially install and update these certificates on a Netscaler FIPS Appliance.

Any direction is appreciated.

Thanks in advance.
Hello.  We have a discrepency on the order of steps we need to enable FIPS in a HA setup for Netscaler MPX9700.  These are running version 11.1.

From the Articles, such as and, it reads as though you start with the HSM/FIPS module and then the HA portion of the GUI.  We are planning to use a WildCard for the certificate on the FIPS module and the URL's provided to users.

However; from research a co-worker insists that the HA portion through the GUI needs to be setup first, and then do the HSM/FIPS portion.

Any clarification from experience is appreciated.
Good day. I have removed one Xenapp delivery controller and made another primary. I have changed the storefront and studio to point to the new one. I have updated the STA in netscaler. I can connect to citrix resources internally fine but externally i now get the following error: Connection to the server "x.x.x.x:1494" was interrupted. Please check your network connection and try again.

I am newbie to Citrix Netscaler. ;)

I have create a loadbalancer to some https servers. I works as expected.

Is it possible to use content switching on the VIP (of the loadbalancer i just created)? -> VIP ->
https://* -> VIP -> (to one of the https servers)

Thanks in advance.

Hello.  Trying to do some customization's to Citrix StoreFront 3.15.  I have found numerous articles that have helped, but getting stuck on the following two items.

#1 - Is there a way to move the Description next to the icon instead of below?  (I've attached a screen shot of what I see and would like to do)

#2 - Trying to set a footer on all pages as we front end Citrix Storefront with Netscaler (MPX9700) running version 11.  I have found an article to add the following in the custom\style.css, but doesn't seem to be working.  (Choosing black as our background screen is fairly light)

.customBottom {

The other part of this is the text in the custom\script.js.  

$('.customBottom').html("Copyright & Copy 1996-2018. All rights reserved.<br />Terms of Service | Privacy Policy | Customer Service<br />");

Any direction is appreciated with the footer.  I am trying to put here on Storefont as I haven't had success using the instructions on displaying on the users login screen for Netscaler.

Thanks in advance for your help.
Citrix error "There are no apps or desktops available to you at this time"
Citrix XenApp 7.15 LTSR
NetScaler 12.1 VPX
SSO configured through GPO's.
When login to StoreFront URL is working fine.
But login to NetScaler StoreFront load balance URL is giving above Error.
Configured SSO as per CTX133982 and followed CTX200583 /CTX233380
Please suggest.
Citrix NetScaler ADC 12.1 48.13 nc ---StoreFront, Director, LDAP Virtual Servers are down when I configured with SSL. But they are UP, when I configured with http.
Please suggest how to troubleshoot.

Edit: I will leave that there but I think I initially misread your question, but the same steps are true of SSL - can you telnet from the NS to the SF / XA servers successfully, as a start.
How can we use the secondary Citrix NetScaler Server, in an H.A. pair to safely test out new configurations before the same changes are propagated to the other NetScaler?

We have 2 x version 12.0 Citrix NetScaler Servers in our environment.  They both are setup for auto-sync and propagation by default; but according to websites:


There are commands to that can be executed to turn the HA Sync and HA Propagation off and then back on later.  At my company we would like to test out a 2 factor authentication option (during a planned maintenance window) and see how that works before it is available for all of the users.  I am thinking of doing the following:

1.  Enable the 2 factor authentication settings on the Authentication server.
       a.  Whatever it may be, that is a separate topic from this question.

2.  Then after the Authentication server is ready, disable auto-sync and auto-propagation on the NetScaler HA-Pair.

3.  Then configure the secondary NetScaler to work with the 2nd factor Authentication server.
        a.  Then plan a maintenance window to temporarily make the secondary NetScaler Server into the new primary NetScaler Server.
        b.  When I fail over the primary server, the secondary server will then become the new 'primary' server …
Is Azure Market Place "Citrix NetScaler" can authenticate with "On Prem AD" using  "Site 2 Site VPN" connection?
How many seconds Azure "Citrix NetScaler" token will be valid for Authentication?
At On Prem side, ADFS required?
Please suggest
How can I completely disable IPv6 from all network adapters on a Windows 7 Pro. computer?  The use this method to roll-out that configuration change to hundreds of computers?  Is there perhaps a script?

What I am looking for is to disable or un-check the ipv6 settings.

I want it to be grey'd out or disabled.

According to web page:

I have tried opening a command prompt as administrator and running
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters" /v DisabledComponents /t REG_DWORD /d 0x000000FF /f

Open in new window

But after I run this command I think IPv6 is disabled partly; but, I still see the check mark on the adapters indicating that it is still enabled.  

Question1: How can I disable the ipv6 for all adapters on a windows 7 Pro. PC?  My manager specifically asked me to do the un-check box, to make it look disabled.

Question2:  How can I use that method for a mass deployment to change the config on hundreds of devices?

Question3:  How can I verify that IPv6 is indeed disabled?

Before the registry changes, if I ran an ipconfig all, under "Ethernet adapter Local Area Connection"  I saw
IPv4 Address. . . . . . . . . . . :  ###.##.##.###
Then I saw
DHCPv6 Client DUID. . . . . . . . : ##-##-##-##-##-##-##-##-##-##-##-##-##-##

After the Registry changes, I do not see any reference to DHCPv6 Client DUID. . . . . . . . : ##-##-##-##-##-##-##-##-##-##-##-##-##-##
How to create SHA256 CSR file for SSL certificate in Windows 2016?
Windows 2016 IIS
Citrix XenApp 7.15 CU2
NetScaler VPX 12.0
On  a netscaler 16500 - suppose I want to traffic to to redirect to But the same mechanism would deliver to redirect to What would I need to cofigure? thank you
We have 2 Citrix NetScalers (Virtual Servers) configured in an HA-Pair.  We have updated the 'secondary' NetScaler and everything looks to be working just fine on that NetScaler when we have planned maintenance windows and failed over the Primary (with the older version) and then our pilot test group of users and devices logged on to the updated NetScaler.

Hence we have 1 x Primary 'NetScaler1' (version 11.0) and 1 x Secondary 'NetScaler2' (version 12.0).

I am planning on failing over the 11.0 NetScaler1 to become the secondary and then to have NEtScaler2 become the new Primary in the HA-Pair.  Eventually I will update NetScaler1 to version 12.0.  I think it would be a less disruptive to our employees if I just leave the Netcaler1 to be the secondary after I update it; however I need to test it after the update.

Is there a way to have specific user accounts only login to a Specific NetScaler Server IP address?  Or doe s HA simply not work that way?  Then I simply must fail over the NetScalers again for testing and plan another maintenance window?
How to setup an AAA server?

I have a project on the horizon that involves setting up Dual Factor Authentication on a Citrix NetScaler Server.  I have a rough outline from:

But questions today are regarding setting up an Authentication server from scratch.  I have never setup or used an AAA server or RADIUS server before.

Question1:  Will I need to simply setup a Windows 2012 R2 or 2016 Server with the Remote Access Server role?

Quesiton2:  Will I need a certificate from a Certificate Authority?

Question3:  What is required for this AAA server to work with NetScaler?  All NetScaler configuration is separate from this question.
When I look at the elliptic curve information for some VIPs in my Netscaler Load Balancer - I see
that there might be four or five lines dedidicated to elliptic curves. I forget the numbers
but one might be 128, 164, then 256, then 324 - let's say. Now I understand the larger the
number the higher the encryption level. But why would a vip have several elliptic curves
associated with it instead of just one?






NetScaler is the industry’s leading web and application delivery controller that maximizes the performance and availability of all applications and data, and also provide secure remote access to any application from any device type. NetScaler products are easily selected by determining the edition providing functional needs and the appropriate physical or virtual appliance platform to fulfill performance needs.