NetScaler is the industry’s leading web and application delivery controller that maximizes the performance and availability of all applications and data, and also provide secure remote access to any application from any device type. NetScaler products are easily selected by determining the edition providing functional needs and the appropriate physical or virtual appliance platform to fulfill performance needs.

Share tech news, updates, or what's on your mind.

Sign up to Post

Hello.  We have a discrepency on the order of steps we need to enable FIPS in a HA setup for Netscaler MPX9700.  These are running version 11.1.

From the Articles, such as and, it reads as though you start with the HSM/FIPS module and then the HA portion of the GUI.  We are planning to use a WildCard for the certificate on the FIPS module and the URL's provided to users.

However; from research a co-worker insists that the HA portion through the GUI needs to be setup first, and then do the HSM/FIPS portion.

Any clarification from experience is appreciated.
Good day. I have removed one Xenapp delivery controller and made another primary. I have changed the storefront and studio to point to the new one. I have updated the STA in netscaler. I can connect to citrix resources internally fine but externally i now get the following error: Connection to the server "x.x.x.x:1494" was interrupted. Please check your network connection and try again.

I am newbie to Citrix Netscaler. ;)

I have create a loadbalancer to some https servers. I works as expected.

Is it possible to use content switching on the VIP (of the loadbalancer i just created)? -> VIP ->
https://* -> VIP -> (to one of the https servers)

Thanks in advance.

Hello.  Trying to do some customization's to Citrix StoreFront 3.15.  I have found numerous articles that have helped, but getting stuck on the following two items.

#1 - Is there a way to move the Description next to the icon instead of below?  (I've attached a screen shot of what I see and would like to do)

#2 - Trying to set a footer on all pages as we front end Citrix Storefront with Netscaler (MPX9700) running version 11.  I have found an article to add the following in the custom\style.css, but doesn't seem to be working.  (Choosing black as our background screen is fairly light)

.customBottom {

The other part of this is the text in the custom\script.js.  

$('.customBottom').html("Copyright & Copy 1996-2018. All rights reserved.<br />Terms of Service | Privacy Policy | Customer Service<br />");

Any direction is appreciated with the footer.  I am trying to put here on Storefont as I haven't had success using the instructions on displaying on the users login screen for Netscaler.

Thanks in advance for your help.
Citrix error "There are no apps or desktops available to you at this time"
Citrix XenApp 7.15 LTSR
NetScaler 12.1 VPX
SSO configured through GPO's.
When login to StoreFront URL is working fine.
But login to NetScaler StoreFront load balance URL is giving above Error.
Configured SSO as per CTX133982 and followed CTX200583 /CTX233380
Please suggest.
Citrix NetScaler ADC 12.1 48.13 nc ---StoreFront, Director, LDAP Virtual Servers are down when I configured with SSL. But they are UP, when I configured with http.
Please suggest how to troubleshoot.

Edit: I will leave that there but I think I initially misread your question, but the same steps are true of SSL - can you telnet from the NS to the SF / XA servers successfully, as a start.
How can we use the secondary Citrix NetScaler Server, in an H.A. pair to safely test out new configurations before the same changes are propagated to the other NetScaler?

We have 2 x version 12.0 Citrix NetScaler Servers in our environment.  They both are setup for auto-sync and propagation by default; but according to websites:


There are commands to that can be executed to turn the HA Sync and HA Propagation off and then back on later.  At my company we would like to test out a 2 factor authentication option (during a planned maintenance window) and see how that works before it is available for all of the users.  I am thinking of doing the following:

1.  Enable the 2 factor authentication settings on the Authentication server.
       a.  Whatever it may be, that is a separate topic from this question.

2.  Then after the Authentication server is ready, disable auto-sync and auto-propagation on the NetScaler HA-Pair.

3.  Then configure the secondary NetScaler to work with the 2nd factor Authentication server.
        a.  Then plan a maintenance window to temporarily make the secondary NetScaler Server into the new primary NetScaler Server.
        b.  When I fail over the primary server, the secondary server will then become the new 'primary' server …
Is Azure Market Place "Citrix NetScaler" can authenticate with "On Prem AD" using  "Site 2 Site VPN" connection?
How many seconds Azure "Citrix NetScaler" token will be valid for Authentication?
At On Prem side, ADFS required?
Please suggest
How can I completely disable IPv6 from all network adapters on a Windows 7 Pro. computer?  The use this method to roll-out that configuration change to hundreds of computers?  Is there perhaps a script?

What I am looking for is to disable or un-check the ipv6 settings.

I want it to be grey'd out or disabled.

According to web page:

I have tried opening a command prompt as administrator and running
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters" /v DisabledComponents /t REG_DWORD /d 0x000000FF /f

Open in new window

But after I run this command I think IPv6 is disabled partly; but, I still see the check mark on the adapters indicating that it is still enabled.  

Question1: How can I disable the ipv6 for all adapters on a windows 7 Pro. PC?  My manager specifically asked me to do the un-check box, to make it look disabled.

Question2:  How can I use that method for a mass deployment to change the config on hundreds of devices?

Question3:  How can I verify that IPv6 is indeed disabled?

Before the registry changes, if I ran an ipconfig all, under "Ethernet adapter Local Area Connection"  I saw
IPv4 Address. . . . . . . . . . . :  ###.##.##.###
Then I saw
DHCPv6 Client DUID. . . . . . . . : ##-##-##-##-##-##-##-##-##-##-##-##-##-##

After the Registry changes, I do not see any reference to DHCPv6 Client DUID. . . . . . . . : ##-##-##-##-##-##-##-##-##-##-##-##-##-##
How to create SHA256 CSR file for SSL certificate in Windows 2016?
Windows 2016 IIS
Citrix XenApp 7.15 CU2
NetScaler VPX 12.0
On  a netscaler 16500 - suppose I want to traffic to to redirect to But the same mechanism would deliver to redirect to What would I need to cofigure? thank you
We have 2 Citrix NetScalers (Virtual Servers) configured in an HA-Pair.  We have updated the 'secondary' NetScaler and everything looks to be working just fine on that NetScaler when we have planned maintenance windows and failed over the Primary (with the older version) and then our pilot test group of users and devices logged on to the updated NetScaler.

Hence we have 1 x Primary 'NetScaler1' (version 11.0) and 1 x Secondary 'NetScaler2' (version 12.0).

I am planning on failing over the 11.0 NetScaler1 to become the secondary and then to have NEtScaler2 become the new Primary in the HA-Pair.  Eventually I will update NetScaler1 to version 12.0.  I think it would be a less disruptive to our employees if I just leave the Netcaler1 to be the secondary after I update it; however I need to test it after the update.

Is there a way to have specific user accounts only login to a Specific NetScaler Server IP address?  Or doe s HA simply not work that way?  Then I simply must fail over the NetScalers again for testing and plan another maintenance window?
How to setup an AAA server?

I have a project on the horizon that involves setting up Dual Factor Authentication on a Citrix NetScaler Server.  I have a rough outline from:

But questions today are regarding setting up an Authentication server from scratch.  I have never setup or used an AAA server or RADIUS server before.

Question1:  Will I need to simply setup a Windows 2012 R2 or 2016 Server with the Remote Access Server role?

Quesiton2:  Will I need a certificate from a Certificate Authority?

Question3:  What is required for this AAA server to work with NetScaler?  All NetScaler configuration is separate from this question.
When I look at the elliptic curve information for some VIPs in my Netscaler Load Balancer - I see
that there might be four or five lines dedidicated to elliptic curves. I forget the numbers
but one might be 128, 164, then 256, then 324 - let's say. Now I understand the larger the
number the higher the encryption level. But why would a vip have several elliptic curves
associated with it instead of just one?
Citrix Licensing Models: Apart below licenses, do we need any other software licenses for Citrix XenApp XenDesktop 7.x deployments?
Especially, VMWare licensing details required for XenDesktop SBC/VDI deployments.

Model 1: Rich Model

Citrix XenAppXenDesktop Platinum Edition
NetScaler MPX
Microsoft CIS Datacenter (Included RDS and Hyper-V VMs OS)  OR  VMWare ESXi with VCenter
MS SQL Server (Enterprise) AllwaysON

Model 2: Economic Model
Citrix XenAppXenDesktop Enterprise – Limited Director reports (31 days of historical analytic data), No Comtrade SCOM pack.
NetScaler VPX Model
MS SQL Server (Standard) without AllwayON
Microsoft CIS Datacenter (Included RDS and Hyper-V VMs OS)  OR Citrix XenServer

Microsoft License :
Hyper-V, Server OS, Desktop OS : Data Center Edition will cover Hyper-V, Server OS and Desktop OS on the Host server.
Extra Windows Desktop OS license for XenDesktop
I’m buying VDI software from VMware/Citrix/another vendor. Do I still need Windows VDA?
Yes. If you are accessing a Windows client OS as your guest operating system in the datacenter from a thin client, Windows VDA is the appropriate licensing vehicle regardless of the VDI software vendor you choose. The only scenario where you would not need Windows VDA is if you were using PCs covered under Software Assurance as the access devices, since …
How do i restrict access to a vServer on a netscaler based on which user tries to login.
Citrix NetScaler VPX 12.0 Configuration for StoreFront Loadbalance in Intranet 7.15 CU2 environment. 

How to create SSL certificates using MS CA :

1. SSL certificates requirement - PFX/CRT/PEM, How to generate required SSL certificate?  -- PFX
2. SSL Certificates required for StoreFront, DDC, and NetScaler? How to generate?
Windows 2016 Certificate Authority role required to generate these certificates? If yes, How to generate?'Web-Server'-Certificate-Template-not-an-option-on-http-server-certsrv.html
3.  Service Accounts requirement for LDAP authentication. -- One Service Account Required
4.  How many IPs required for SF LB?

Please close the thread.

I'm unable to launch Citrix XenDesktop from outside my network. It gives me protocol driver error when launched from store front. Has anyone seen this error message before?

P.S I do not have a netscaler gateway in between. Currently using my firewall for port forwarding.



How can I create URL redirection on Netscaler

I need to redirect https://cportal/sites/NCSC/rfpanswers/*    to Document Database

please advise.
Good day. I am busy configuring my first netscaler gateway for Xenapp 7 but i am not seeing the VPN tab on the web interface. Any ideas why?
Hi EE,

If I wish to forego Citrix Netscaler , can I then simply create a virtual server load balancing port 443 with SSL offload on my F5 Big IP device using the traffic manager ? I tried searching the F5 and Citrix  knowledge base with no luck. Looking for any persons experienced in this area.
Hello.  Running Citrix Secure Gateway, 3.3.4, Web Interface and XenApp 6.5.  We have 11 different servers running CSG/WI that point to the same XenApp 6.5 farm.

While investigating why we are seeing an increase in client connections drop, I noticed that our CSG logs are only showing that STA's are coming from 1 server instead of the 5 that are defined.  There are actually more in the server farm, so we were just using a subset.  I confirmed through logs and pulled that particular server from the server configuration and at that point, no one could execute apps in Citrix.  I need to remove this single point of failure.

I have confirmed that the webinterface.config reflect all the systems that are in the Web Interface and CSG.  The Citrix XML Service is running on all XenApp systems.  How can I force CSG to use more than a single CTXSTA?

Thanks in advance for your help.

And yes - we are in the process of moving to Netscaler, however; that is not in place quite yet.


I am a Citrix novice, so I will certainly fill in any gaps that I can when trying to frame the situation and additional information needed.

I have a few users who are getting the error message "Unable to connect to the server. Contact your system administrator with the following error SSL Error 4 The operation completed successfully" when attempting to log into their environment.

Some information I have retrieved:

We are running: NetScaler VPX (50) - NS10.1: Build, Date: Oct 18 2013

These are a couple of errors from the logs:

Mon Jan 22 07:09:32 'server_svc_internal_NSSVC_SSL_TCP_192.168.100.6:3008(nsrpcs-' DOWN
Mon Jan 22 07:09:32 'server_svc_internal_NSSVC_SSL_192.168.100.6:443(nshttps-' DOWN
Mon Jan 22 07:11:01 MonServiceBinding_192.168.100.204:80_(tcp-default)(internal): DOWN; Last response: Failure - TCP syn sent, reset received
Mon Jan 22 07:11:02 MonServiceBinding_192.168.100.204:443_(tcp-default)(internal): DOWN; Last response: Failure - TCP syn sent, reset received

This occurs with varying versions of the Citrix Receiver. I was able to replicate the issue with the latest and greatest version.

This is something that just started happening about 18 hours ago.

I am in a position to reboot the Netscaler appliance, but didn't want to do so during a time which we still have a few people working and having someone provide some initial feedback.

Any assistance is greatly appreciated.
We are on Xenapp 7.8.  I just found out that our Netscaler license did not belong to us, but to the company that set up Citrix.  Who is now gone.
I got a temporary Netscaler license.  When The Citrix rep called me to give me pricing, it is $7000.  

I spoke to the guy who set up Netscaler and he told me that the SSL certificate could be pointed to the Store Front, which would eliminate the need for Netscaler.

All we use Xenapp for is "Desktop".  We don't deploy any apps.   Is it OK to not use Netscaler?

When we are trying to connect to citrix we are getting

This site can’t be reached refused to connect.

Checking the connection
Checking the proxy and the firewall

It was working and since this weekend it is not working at all. How do I trace back where the problem is and where do i start?







NetScaler is the industry’s leading web and application delivery controller that maximizes the performance and availability of all applications and data, and also provide secure remote access to any application from any device type. NetScaler products are easily selected by determining the edition providing functional needs and the appropriate physical or virtual appliance platform to fulfill performance needs.