NetScaler

452

Solutions

452

Contributors

NetScaler is the industry’s leading web and application delivery controller that maximizes the performance and availability of all applications and data, and also provide secure remote access to any application from any device type. NetScaler products are easily selected by determining the edition providing functional needs and the appropriate physical or virtual appliance platform to fulfill performance needs.

Share tech news, updates, or what's on your mind.

Sign up to Post

Citrix NetScaler ADC 12.1 48.13 nc ---StoreFront, Director, LDAP Virtual Servers are down when I configured with SSL. But they are UP, when I configured with http.
Please suggest how to troubleshoot.

Edit: I will leave that there but I think I initially misread your question, but the same steps are true of SSL - can you telnet from the NS to the SF / XA servers successfully, as a start.
0
How can we use the secondary Citrix NetScaler Server, in an H.A. pair to safely test out new configurations before the same changes are propagated to the other NetScaler?

We have 2 x version 12.0 Citrix NetScaler Servers in our environment.  They both are setup for auto-sync and propagation by default; but according to websites:

- https://support.citrix.com/article/CTX124439 
- https://docs.citrix.com/zh-cn/netscaler/11/system/high-availability-introduction/configuring-command-propagation-high-availability.html

There are commands to that can be executed to turn the HA Sync and HA Propagation off and then back on later.  At my company we would like to test out a 2 factor authentication option (during a planned maintenance window) and see how that works before it is available for all of the users.  I am thinking of doing the following:

1.  Enable the 2 factor authentication settings on the Authentication server.
       a.  Whatever it may be, that is a separate topic from this question.

2.  Then after the Authentication server is ready, disable auto-sync and auto-propagation on the NetScaler HA-Pair.

3.  Then configure the secondary NetScaler to work with the 2nd factor Authentication server.
        a.  Then plan a maintenance window to temporarily make the secondary NetScaler Server into the new primary NetScaler Server.
        b.  When I fail over the primary server, the secondary server will then become the new 'primary' server …
0
Is Azure Market Place "Citrix NetScaler" can authenticate with "On Prem AD" using  "Site 2 Site VPN" connection?
How many seconds Azure "Citrix NetScaler" token will be valid for Authentication?
At On Prem side, ADFS required?
Please suggest
0
How can I completely disable IPv6 from all network adapters on a Windows 7 Pro. computer?  The use this method to roll-out that configuration change to hundreds of computers?  Is there perhaps a script?

What I am looking for is to disable or un-check the ipv6 settings.

ipv6_1
I want it to be grey'd out or disabled.

ipv6_2
According to web page: https://techjourney.net/disable-turn-off-ipv6-support-in-windows-10-8-1-8-7-vista/

I have tried opening a command prompt as administrator and running
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters" /v DisabledComponents /t REG_DWORD /d 0x000000FF /f

Open in new window


But after I run this command I think IPv6 is disabled partly; but, I still see the check mark on the adapters indicating that it is still enabled.  

Question1: How can I disable the ipv6 for all adapters on a windows 7 Pro. PC?  My manager specifically asked me to do the un-check box, to make it look disabled.

Question2:  How can I use that method for a mass deployment to change the config on hundreds of devices?

Question3:  How can I verify that IPv6 is indeed disabled?

Before the registry changes, if I ran an ipconfig all, under "Ethernet adapter Local Area Connection"  I saw
IPv4 Address. . . . . . . . . . . :  ###.##.##.###
Then I saw
DHCPv6 Client DUID. . . . . . . . : ##-##-##-##-##-##-##-##-##-##-##-##-##-##

After the Registry changes, I do not see any reference to DHCPv6 Client DUID. . . . . . . . : ##-##-##-##-##-##-##-##-##-##-##-##-##-##
0
How to create SHA256 CSR file for SSL certificate in Windows 2016?
Environment:
Windows 2016 IIS
Citrix XenApp 7.15 CU2
NetScaler VPX 12.0
VMWARE ESXi 6.5
0
On  a netscaler 16500 - suppose I want to traffic to https://yaya.foo.com/whatdoyouknow to redirect to https://www.sharktown.com/whatdoyouknow. But the same mechanism would deliver https://yaya.foo.com/somwhere to redirect to https://www.sharktown.com/somewhere. What would I need to cofigure? thank you
0
We have 2 Citrix NetScalers (Virtual Servers) configured in an HA-Pair.  We have updated the 'secondary' NetScaler and everything looks to be working just fine on that NetScaler when we have planned maintenance windows and failed over the Primary (with the older version) and then our pilot test group of users and devices logged on to the updated NetScaler.

Hence we have 1 x Primary 'NetScaler1' (version 11.0) and 1 x Secondary 'NetScaler2' (version 12.0).

I am planning on failing over the 11.0 NetScaler1 to become the secondary and then to have NEtScaler2 become the new Primary in the HA-Pair.  Eventually I will update NetScaler1 to version 12.0.  I think it would be a less disruptive to our employees if I just leave the Netcaler1 to be the secondary after I update it; however I need to test it after the update.

Is there a way to have specific user accounts only login to a Specific NetScaler Server IP address?  Or doe s HA simply not work that way?  Then I simply must fail over the NetScalers again for testing and plan another maintenance window?
0
How to setup an AAA server?

I have a project on the horizon that involves setting up Dual Factor Authentication on a Citrix NetScaler Server.  I have a rough outline from: https://www.carlstalhood.com/nfactor-authentication-for-netscaler-gateway-12/

But questions today are regarding setting up an Authentication server from scratch.  I have never setup or used an AAA server or RADIUS server before.

Question1:  Will I need to simply setup a Windows 2012 R2 or 2016 Server with the Remote Access Server role?

Quesiton2:  Will I need a certificate from a Certificate Authority?

Question3:  What is required for this AAA server to work with NetScaler?  All NetScaler configuration is separate from this question.
0
When I look at the elliptic curve information for some VIPs in my Netscaler Load Balancer - I see
that there might be four or five lines dedidicated to elliptic curves. I forget the numbers
but one might be 128, 164, then 256, then 324 - let's say. Now I understand the larger the
number the higher the encryption level. But why would a vip have several elliptic curves
associated with it instead of just one?
0
Citrix Licensing Models: Apart below licenses, do we need any other software licenses for Citrix XenApp XenDesktop 7.x deployments?
Especially, VMWare licensing details required for XenDesktop SBC/VDI deployments.

Model 1: Rich Model

Citrix XenAppXenDesktop Platinum Edition
NetScaler MPX
Microsoft CIS Datacenter (Included RDS and Hyper-V VMs OS)  OR  VMWare ESXi with VCenter
MS SQL Server (Enterprise) AllwaysON

Model 2: Economic Model
Citrix XenAppXenDesktop Enterprise – Limited Director reports (31 days of historical analytic data), No Comtrade SCOM pack.
NetScaler VPX Model
MS SQL Server (Standard) without AllwayON
Microsoft CIS Datacenter (Included RDS and Hyper-V VMs OS)  OR Citrix XenServer

Microsoft License :
Hyper-V, Server OS, Desktop OS : Data Center Edition will cover Hyper-V, Server OS and Desktop OS on the Host server.
Extra Windows Desktop OS license for XenDesktop
http://www.purchasing.ufl.edu/contracts/microsoft-select-plus/Microsoft-VDI-Suites-and-Windows-VDA-FAQ-v31.pdf
I’m buying VDI software from VMware/Citrix/another vendor. Do I still need Windows VDA?
Yes. If you are accessing a Windows client OS as your guest operating system in the datacenter from a thin client, Windows VDA is the appropriate licensing vehicle regardless of the VDI software vendor you choose. The only scenario where you would not need Windows VDA is if you were using PCs covered under Software Assurance as the access devices, since …
0
How do i restrict access to a vServer on a netscaler based on which user tries to login.
0
Citrix NetScaler VPX 12.0 Configuration for StoreFront Loadbalance in Intranet 7.15 CU2 environment.
http://www.carlstalhood.com/storefront-load-balancing-netscaler-12/ 

How to create SSL certificates using MS CA :
https://mizitechinfo.wordpress.com/2013/08/29/step-by-step-deploying-a-standalone-root-ca-in-server-2012-r2-part-1/
https://mizitechinfo.wordpress.com/2013/08/31/step-by-step-deploying-an-enterprise-subordinate-ca-in-server-2012-r2-part-2/
https://support.citrix.com/article/CTX206492
http://www.citrixguru.com/2015/11/15/lab-part-15-configure-ssl-in-storefront/


1. SSL certificates requirement - PFX/CRT/PEM, How to generate required SSL certificate?  -- PFX
2. SSL Certificates required for StoreFront, DDC, and NetScaler? How to generate?
Windows 2016 Certificate Authority role required to generate these certificates? If yes, How to generate?
https://www.experts-exchange.com/questions/26672335/'Web-Server'-Certificate-Template-not-an-option-on-http-server-certsrv.html
3.  Service Accounts requirement for LDAP authentication. -- One Service Account Required
4.  How many IPs required for SF LB?
NS IP, SNIP, SF LB VIP, DDC LB VIP, Director LB VIP, DNS LB VIP.

Please close the thread.
0
Hello,

I'm unable to launch Citrix XenDesktop from outside my network. It gives me protocol driver error when launched from store front. Has anyone seen this error message before?


P.S I do not have a netscaler gateway in between. Currently using my firewall for port forwarding.

Thanks,

Kemar
0
Hello,

How can I create URL redirection on Netscaler

I need to redirect https://cportal/sites/NCSC/rfpanswers/*    to    https://sp.compugen.com/sites/rfp/RFP Document Database

please advise.
0
Good day. I am busy configuring my first netscaler gateway for Xenapp 7 but i am not seeing the VPN tab on the web interface. Any ideas why?
0
Hi EE,

If I wish to forego Citrix Netscaler , can I then simply create a virtual server load balancing port 443 with SSL offload on my F5 Big IP device using the traffic manager ? I tried searching the F5 and Citrix  knowledge base with no luck. Looking for any persons experienced in this area.
0
Hello.  Running Citrix Secure Gateway, 3.3.4, Web Interface 5.4.2.59 and XenApp 6.5.  We have 11 different servers running CSG/WI that point to the same XenApp 6.5 farm.

While investigating why we are seeing an increase in client connections drop, I noticed that our CSG logs are only showing that STA's are coming from 1 server instead of the 5 that are defined.  There are actually more in the server farm, so we were just using a subset.  I confirmed through logs and pulled that particular server from the server configuration and at that point, no one could execute apps in Citrix.  I need to remove this single point of failure.

I have confirmed that the webinterface.config reflect all the systems that are in the Web Interface and CSG.  The Citrix XML Service is running on all XenApp systems.  How can I force CSG to use more than a single CTXSTA?

Thanks in advance for your help.

And yes - we are in the process of moving to Netscaler, however; that is not in place quite yet.

Thanks.
0
Hello,

I am a Citrix novice, so I will certainly fill in any gaps that I can when trying to frame the situation and additional information needed.

I have a few users who are getting the error message "Unable to connect to the server. Contact your system administrator with the following error SSL Error 4 The operation completed successfully" when attempting to log into their environment.

Some information I have retrieved:

We are running: NetScaler VPX (50) - NS10.1: Build 121.10.nc, Date: Oct 18 2013

These are a couple of errors from the logs:

Mon Jan 22 07:09:32 'server_svc_internal_NSSVC_SSL_TCP_192.168.100.6:3008(nsrpcs-127.0.0.1-3008)' DOWN
Mon Jan 22 07:09:32 'server_svc_internal_NSSVC_SSL_192.168.100.6:443(nshttps-127.0.0.1-443)' DOWN
Mon Jan 22 07:11:01 MonServiceBinding_192.168.100.204:80_(tcp-default)(internal): DOWN; Last response: Failure - TCP syn sent, reset received
Mon Jan 22 07:11:02 MonServiceBinding_192.168.100.204:443_(tcp-default)(internal): DOWN; Last response: Failure - TCP syn sent, reset received

This occurs with varying versions of the Citrix Receiver. I was able to replicate the issue with the latest and greatest version.

This is something that just started happening about 18 hours ago.

I am in a position to reboot the Netscaler appliance, but didn't want to do so during a time which we still have a few people working and having someone provide some initial feedback.

Any assistance is greatly appreciated.
0
We are on Xenapp 7.8.  I just found out that our Netscaler license did not belong to us, but to the company that set up Citrix.  Who is now gone.
I got a temporary Netscaler license.  When The Citrix rep called me to give me pricing, it is $7000.  

I spoke to the guy who set up Netscaler and he told me that the SSL certificate could be pointed to the Store Front, which would eliminate the need for Netscaler.

All we use Xenapp for is "Desktop".  We don't deploy any apps.   Is it OK to not use Netscaler?
0
Hi,

When we are trying to connect to citrix we are getting

This site can’t be reached
citrix.ephs.ealing.sch.uk refused to connect.
Try:

Checking the connection
Checking the proxy and the firewall
ERR_CONNECTION_REFUSED

It was working and since this weekend it is not working at all. How do I trace back where the problem is and where do i start?

Thanks
Arpit
0
I am new to this and I cannot figure out the life for me why this virtual is coming up as unregistered. I followed our KB - reinstalled VDA 7.6 rebooted and still nothing. Any experts in this area?
0
Are there major features missing for load balancing purposes? Throughput limits? High cost?
0
Running ldp.exe on domain controller using domain admin credentials and simple bind, I got the same error the first run. Now it gives me The token supplied to the function is invalid.

Running ldp.exe on a different domain controller on different domain/forest, the results are valid.

So something wrong on first domain controller. How/Where to find the problem?

Thanks!
0
Anyone could share the Basic Tutorial link\URL to learn NetScaler and its configuration/features.

Any help would be appreciated.
0
Hello,

We are are looking into replacing our ADFS Proxy Servers with Citrix Netscaler (See link -> https://www.citrix.com/content/dam/citrix/en_us/documents/products-solutions/guide-to-deploying-netscaler-as-an-active-directory-federation-services-proxy.pdf)

We are also looking at buying Duo and using it for ADFS (Link->https://duo.com/docs/adfs-30)

We don't to make our network engineer go through all of the work switching ADFS proxy over to the Netscaler if will not work with Duo. Wanted to check to see if anyone here has or is doing this?

Thanks!!!
0

NetScaler

452

Solutions

452

Contributors

NetScaler is the industry’s leading web and application delivery controller that maximizes the performance and availability of all applications and data, and also provide secure remote access to any application from any device type. NetScaler products are easily selected by determining the edition providing functional needs and the appropriate physical or virtual appliance platform to fulfill performance needs.