<?xml version="1.0"?>
<rss version="2.0"><channel><title>NetScaler Gateway Latest Topics</title><link>https://community.stage.citrix.com/forums/forum/1603-netscaler-gateway/</link><description>NetScaler Gateway Latest Topics</description><language>en</language><item><title><![CDATA[Since update of our Citrix Netscaler to 14.1 build 51.72, newer Citrix Workspace App versions >= 2503.10 does not connect to the VDAs]]></title><link>https://community.stage.citrix.com/forums/topic/258509-since-update-of-our-citrix-netscaler-to-141-build-5172-newer-citrix-workspace-app-versions-250310-does-not-connect-to-the-vdas/</link><description><![CDATA[<p>Since last upgrade of our Netscaler to version 14.1 build 51.72 and 51.80, newer Citrix Workspace App versions does not launch Citrix sessions over Citrix Netscaler. It get stuck on launching after successfully authorization.</p><p>In our case the main issue is, that newer Citrix Workspace Apps now use port 443 instead of 2598 to connect to the vda:<br></p><p>Citrix Workspaceapp Linux 2503 works by using port 2598:<br><strong><em>Sep 25 12:32:50 &lt;</em></strong><a rel="external nofollow" href="https://local0.info"><strong><em>local0.info</em></strong></a><strong><em>&gt; 123.123.123.123  09/25/2025:10:32:50 GMT NETSCALERNAME 0-PPE-1 : default SSLVPN ICASTART 624703 0 :  [TECHSUPPORT][LAUNCH][TCP][CGP][ICAUUID=0001c17c-1a52-18d5-9678-00e0ed86e2dd] Source 111.222.333.444:56060 - Destination <span data-i-color="red">TERMINALSERVER:2598</span>- customername  - username:domainname USERNAME:DOMAIN - applicationName Desktop $S4-5 - startTime "09/25/2025:10:32:50 GMT" - connectionId 1058960</em></strong></p><p>Citrix Workspaceapp Windows 2503.10 does not work by using port 443:</p><p><strong><em>Sep 25 13:14:02 &lt;</em></strong><a rel="external nofollow" href="https://local0.info"><strong><em>local0.info</em></strong></a><strong><em>&gt; 123.123.123.123 09/25/2025:11:14:02 GMT NETSCALERNAME 0-PPE-0 : default SSLVPN ICASTART 2965635 0 :  [TECHSUPPORT][LAUNCH][TCP][CGP][ICAUUID=000c1972-23fa-18d5-9678-00e0ed86e2dd] Source 111.222.333.444:61950 - Destination <span data-i-color="red">TERMINALSERVER:443 </span>- customername  - username:domainname  USERNAME:DOMAIN  - applicationName IT $S55-80 - startTime "09/25/2025:11:14:02 GMT" - connectionId 6135506</em></strong></p><p>So we need to enable SSL on our VDAs. </p><p>Is there any other way to restore "old" 2598/Session reability option through Netscaler without configure our whole VDAs to work with SSL ?</p><p>Best regards<br>Jens</p>]]></description><guid isPermaLink="false">258509</guid><pubDate>Wed, 08 Oct 2025 06:46:08 +0000</pubDate></item><item><title>Network Telemetry enabled on 14.1 Gateway</title><link>https://community.stage.citrix.com/forums/topic/258488-network-telemetry-enabled-on-141-gateway/</link><description><![CDATA[<p><span style="font-family: Arial, Helvetica, sans-serif;">Environment is Citrix DaaS. VDA version is 2507 on Windows 11. CWA is Windows 25.3.2.196.</span></p><p>Noticed that in Citrix Monitor there was a recommendation of activating Network telemetry to gather L7 client Latency, L7 server latency, and throughput.</p><p>I activated the policy on a device or two and we are seeing that on-prem NetScaler 14.1 Gateway connections fail “Gateway authentication failed because VDA refused connection. Error code 2091.2524.” If access is through 13.1 the connection is successful. I have tested with EDT\UDP and TCP which does not appear to be a factor. Connections work when not going through a Gateway.</p><p>I have had a ticket open with Citrix support and having a working session has been an issue for the last few weeks.</p><p>This feels like a bug that I just want to report but it is such a struggle to get this to Citrix.</p>]]></description><guid isPermaLink="false">258488</guid><pubDate>Mon, 29 Sep 2025 19:49:21 +0000</pubDate></item><item><title>NetScaler software entitlements</title><link>https://community.stage.citrix.com/forums/topic/258710-netscaler-software-entitlements/</link><description><![CDATA[<p><span style="font-family: inherit;">It this true? "NetScaler software entitlements are now included in your Citrix subscription, so there’s no need to purchase NetScaler separately for Citrix deployments."</span></p>]]></description><guid isPermaLink="false">258710</guid><pubDate>Mon, 19 Jan 2026 16:30:18 +0000</pubDate></item><item><title>Netscaler Gateway spinning wheel when using nFactor with Safari or Workspace App for iOS</title><link>https://community.stage.citrix.com/forums/topic/258655-netscaler-gateway-spinning-wheel-when-using-nfactor-with-safari-or-workspace-app-for-ios/</link><description><![CDATA[<p>Latest Gateway version (but issue exists sind a few months).</p><p>We use nFactor (the new one) configuration. Short:<br>login schema with username, password and drop-down for decision which site to use -&gt; two decision factors noschema depending on which site the user has selected in the drop-down -&gt; ldap noschema noauth group extraction and set default authorization group  -&gt; radius noschma authentication</p><p>It works fine for windows devices and most of the time for mac devices, but it never works on iOS. Safari works sometimes, chrome and edge work always.  After entering sms code it stops working with a spinning wheel.</p><p>I presume it's related to nfactor.</p>]]></description><guid isPermaLink="false">258655</guid><pubDate>Thu, 18 Dec 2025 12:53:19 +0000</pubDate></item><item><title>Citrix connection timeout with latest Netscaler (ica-in-ica)</title><link>https://community.stage.citrix.com/forums/topic/258602-citrix-connection-timeout-with-latest-netscaler-ica-in-ica/</link><description><![CDATA[<p>Hi everybody.</p><p>Since the latest Netscaler Update (14.1 Build 56.74 from 11.11.), our users receive conenction timeouts in 10-15 seconds. The published app or desktop is disconnecting, getting greyed out and after a second it is reconnected. That´s impossible to work with. This happens only, if the ressources are startet in an existing Citrix session. As example: Our IT-Admins start a published Desktop, open an internal Citrix Gateway (same Controllers, separate Netscaler) and then start some published Apps. Then the Apps are getting constantly disconnected.</p><p>Are there any issues with ica-in-ica or something else? two version before, everything worked fine.</p><p>Greets, Thomas</p>]]></description><guid isPermaLink="false">258602</guid><pubDate>Mon, 17 Nov 2025 13:37:03 +0000</pubDate></item><item><title>Netscaler new nFactor flow domain drop-down domain attribute persistent</title><link>https://community.stage.citrix.com/forums/topic/258635-netscaler-new-nfactor-flow-domain-drop-down-domain-attribute-persistent/</link><description><![CDATA[<p>At the moment I'm using a cookie configuration with a loginschema which has 2 domains. User enters username, password and choose domain. Domain is set in a cookie as soon as the user select it. User clicks the logon button and see the sms response page and after that the forwarding to one of the StoreFront Groups happens, whatever the selected domain in the cookie value is.</p><p>I'm right now in the process to get rid of the cookie configuration and use the new nFactor in Authentication Virtual Server. </p><p>loginschema with drop-down for the 2 domains is bound to the auth vserver.</p><p>1st factor: ldap group and attributes extraction no authn with true</p><p>2nd factor: noSchema, RADIUS policy with true</p><p>As long as I use e.g. true in the test session profile, which is bound to the gateway vserver it works. </p><p>If I try something like HTTP.REQ.BODY(4096).CONTAINS("domain=DOMA") it doesn't work. I assume it's because of the 2nd factor and the body changes. </p><p>How can I configure this in a good way?</p><p></p><p>example:</p><p>username</p><p>password</p><p>domain drop-down with DOMA &amp; DOMB</p><p>-&gt; save the "domain=" somewhere the browser / Session policy is able to get it after the 2nd factor.</p><p>In the loginschema maybe?</p>]]></description><guid isPermaLink="false">258635</guid><pubDate>Mon, 08 Dec 2025 15:01:48 +0000</pubDate></item><item><title>Netscaler ram drive running out of space</title><link>https://community.stage.citrix.com/forums/topic/258622-netscaler-ram-drive-running-out-of-space/</link><description><![CDATA[<p>Hi all,</p><p>I'm not sure if this is normal, but since the upgrade to the latest version from November 11th, 14.1 56.74, the /dev/md0 ram disk is running full.</p><p>If you do a df -h you can see it:</p><p>Filesystem Size Used Avail Capacity Mounted on</p><p>/dev/md0 395M 389M -2.1M 101% /</p><p>The cause seems to be a cache folder in /tmp which is not being deleted.</p><p>/tmp/par-726f6f74/cache-2da1179f0f323155b445015df38e981e9e1fb94b.</p><p>These contain all .pm files and one file nsgslbautosync. So I assume it has something to with sync. It's only around 9M large, but enough to fill the drive to 101%.</p><p>When doing show ha node sync is stuck 'in progress' so it probably has to do something with it. Rebooting doesn't solve it. Deleting the file doesn't either. It's always the active node that's out of space.</p><p>We have 4 HA pairs on the new version, all with the same problem.</p><p>Any idea?</p>]]></description><guid isPermaLink="false">258622</guid><pubDate>Fri, 28 Nov 2025 15:57:43 +0000</pubDate></item><item><title>New WSTheme change Button Color</title><link>https://community.stage.citrix.com/forums/topic/253716-new-wstheme-change-button-color/</link><description><![CDATA[<p>
	Hi,
</p>

<p>
	i have installed the new Version of the Netscaler 14.1 and there is a new Theme called WStheme. It look like the Cloud Theme.
</p>

<p>
	In the GUI i can change the Background and Center Logo.
</p>

<p>
	But there is no Option to change the Color of the Logon Button.
</p>

<p>
	Does somebody know if there a CSS Code to change the COlor from the Buttons?
</p>

<p>
	And where i must insert the CSS code? In the custom.css file inside the theme Folder?
</p>

<p>
	Thanks for help.
</p>

<p>
	Regards
</p>

<p>
	Uwe
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">253716</guid><pubDate>Thu, 27 Mar 2025 09:18:24 +0000</pubDate></item><item><title>Help with Netscaler Design in Azure</title><link>https://community.stage.citrix.com/forums/topic/258623-help-with-netscaler-design-in-azure/</link><description><![CDATA[<p>Hello everyone</p><p>Thoroughly confused here…</p><p>We are designing an Azure based architecture for using Netscaler VPXs to perform these functions:</p><ol><li><p>Handle Internet sourced clients via a VPN Gateway with all the good stuff - SSO etc.</p></li><li><p>Load balance the requests to multiple backend Storefront servers (on a different subnet).</p></li><li><p>Also allow internal connectivity to be load balanced to same Storefront servers.</p></li></ol><p>The Netscalers are in a HA pair.</p><p>So, and bear with me…</p><p>We’ve currently done this:</p><ol><li><p>Created a public Azure standard load balancer for the VPN Gateway connection. The front end IP shares the same public IP as the VPX VIP.</p></li><li><p>Created an internal Azure standard load balancer for balancing Storefront. Again, the frontend private IP is shared with the VPX Storefront load balancing VIP (private IP on front end subnet).</p></li></ol><p>Stopping here for a recap: yes, two Azure LBs are pointing to the same VPX.</p><p>3. In the Session Profile setting where you define the Storefront store/URL - we have defined the internal VIP, i.e. the one mentioned above.</p><p>The front end and back end VPX SNIPs are on different subnets.</p><p>The public flow is then like this:</p><p>Client -&gt; Public Azure LB -&gt; VPX Gateway VIP —&gt; hairpin back around via internal Azure LB to VPX storefront VIP -&gt; Storefront.</p><p>The internal flow is like this:</p><p>Client -&gt; internal Azure LB to VPX storefront VIP -&gt; Storefront</p><p>It actually works. Although currently we can only test with a single Storefront server.</p><p>I consulted my best mate, let’s call him Mr GPT, wait that too obvious - Mr Chat.</p><p>It highlighted concerns with this deployment that the hairpin method may cause issues. It recommend to use the VPXs internal routing mechanism instead of the hairpin. This is what it specifically says:</p><p>*<em>1. A user connects to the NetScaler Gateway VServer (public-facing).</em></p><p><em>2. The user authenticates.</em></p><p><em>3. The Session Profile instructs the Gateway component to send the user to </em><a rel="external nofollow" href="https://10.0.0.100"><em><u>https://10.0.0.100</u></em></a><em> (the StoreFront LB vServer VIP).</em></p><p><em>4. Because the IP 10.0.0.100 is an address owned and hosted by the NetScaler itself, the request is processed by the local networking stack and immediately passed to the StoreFront LB vServer component.</em></p><p><em>5. The StoreFront LB vServer then processes the request and proxies it to the actual backend StoreFront servers using the Backend SNIP, completing the successful loopback</em>.*</p><p>My question to you patient people is: is AI right? Is this internal routing possible as I cannot find any documentation supporting this?</p><p>Still. Thoroughly confused.</p><p>Thank you for taking the time to get to the end!</p>]]></description><guid isPermaLink="false">258623</guid><pubDate>Sat, 29 Nov 2025 09:51:41 +0000</pubDate></item><item><title>SSL certificates disappeared after firmware update 14.1-56.71</title><link>https://community.stage.citrix.com/forums/topic/258551-ssl-certificates-disappeared-after-firmware-update-141-5671/</link><description><![CDATA[<p>Hello everyone,</p><p>After updating from version 14.1-47.48 to 14.1-56.71, all SSL and CA certificates disappeared and can no longer be installed.</p><p>We have an official certificate from Geo Trust for a Netscaler instance.</p><p>However, I was unable to reinstall the SSL certificate in this case.</p><p>A message appeared stating that only certificates up to RSA512 and DSA512 are compatible.</p><p>However, the certificate is within these guidelines.</p>]]></description><guid isPermaLink="false">258551</guid><pubDate>Wed, 29 Oct 2025 10:14:38 +0000</pubDate></item><item><title>setting up transport protocol for RADIUS authentication server in FIPS mode</title><link>https://community.stage.citrix.com/forums/topic/258549-setting-up-transport-protocol-for-radius-authentication-server-in-fips-mode/</link><description><![CDATA[<p><span style='font-family: "Times New Roman", Georgia, serif;'>Hi all, I’m looking for some NetScaler expertise.</span></p><p><span style='font-family: "Times New Roman", Georgia, serif;'>I’m building out a new FIPS VPX using the latest FIPS-approved firmware: </span><strong><span style='font-family: "Times New Roman", Georgia, serif;'>Build 13.1-37.247</span></strong><span style='font-family: "Times New Roman", Georgia, serif;'>. Unfortunately, FIPS mode does </span><strong><span style='font-family: "Times New Roman", Georgia, serif;'>not</span></strong><span style='font-family: "Times New Roman", Georgia, serif;'> allow UDP as the transport protocol for RADIUS authentication servers. When I try to add a RADIUS server, I get the following error:</span></p><p><em>Operation not permitted [Invalid transport mode in RadiusAction. FIPS devices only support TLS transport mode]</em></p><p><span style='font-family: "Times New Roman", Georgia, serif;'>Our RSA server does </span><strong><span style='font-family: "Times New Roman", Georgia, serif;'>not</span></strong><span style='font-family: "Times New Roman", Georgia, serif;'> support TLS, so I need to route authentication through </span><strong><span style='font-family: "Times New Roman", Georgia, serif;'>ISE</span></strong><span style='font-family: "Times New Roman", Georgia, serif;'> instead. Our older MPX appliances use RSA over RADIUS (UDP), which worked fine.</span></p><p><span style='font-family: "Times New Roman", Georgia, serif;'>So, I rebuilt my services and LB vServer according to the NetScaler documentation, which states:</span></p><p><em>If transport mode is TLS, specify the name of a LB vServer to associate. The LB vServer needs to be of type TCP, and the associated service must be SSL_TCP.</em></p><p><span style='font-family: "Times New Roman", Georgia, serif;'>I followed this setup, but the bound monitor (</span><code>TCP_default</code><span style='font-family: "Times New Roman", Georgia, serif;'>) shows as </span><strong><span style='font-family: "Times New Roman", Georgia, serif;'>down</span></strong><span style='font-family: "Times New Roman", Georgia, serif;'>. I tried switching the monitor to plain </span><code>TCP</code><span style='font-family: "Times New Roman", Georgia, serif;'>, but the result is the same. I’ve verified:</span></p><ul><li><p><span style='font-family: "Times New Roman", Georgia, serif;'>Network connectivity is up</span></p></li><li><p><span style='font-family: "Times New Roman", Georgia, serif;'>No firewall blocks</span></p></li><li><p><span style='font-family: "Times New Roman", Georgia, serif;'>Valid certificates are in place</span></p></li></ul><p><span style='font-family: "Times New Roman", Georgia, serif;'>Audit logs show that the connection times out </span><strong><span style='font-family: "Times New Roman", Georgia, serif;'>after</span></strong><span style='font-family: "Times New Roman", Georgia, serif;'> LDAP authentication completes.</span></p><p><span style='font-family: "Times New Roman", Georgia, serif;'>I’ve spent several hours on support calls with Citrix, submitted logs and screenshots, but haven’t received helpful guidance yet.</span></p><p><strong>Any suggestions or insights would be greatly appreciated!</strong></p>]]></description><guid isPermaLink="false">258549</guid><pubDate>Mon, 27 Oct 2025 18:39:43 +0000</pubDate></item><item><title>Choose authentification method according to the source IP with a Netscaler Gateway</title><link>https://community.stage.citrix.com/forums/topic/258522-choose-authentification-method-according-to-the-source-ip-with-a-netscaler-gateway/</link><description><![CDATA[<p><span style="font-family: Helvetica, Arial, sans-serif;">With an ADC VPX 50 Gateway (last version of branch 13.1), is it possible to redirect users to different authentication methods based on conditions defined by the client’s source IP address?</span></p>]]></description><guid isPermaLink="false">258522</guid><pubDate>Fri, 17 Oct 2025 08:35:40 +0000</pubDate></item><item><title>2FA (optional) on Gateway Depending on the user group</title><link>https://community.stage.citrix.com/forums/topic/258503-2fa-optional-on-gateway-depending-on-the-user-group/</link><description><![CDATA[<p>Hi folks,</p><p>I want to create a login that only requires the second factor if the user is in a group (let's say 2FA).</p><p>My idea is that the user enters their username and password and then the check is performed. </p><p>If they are in the group, the next window will only ask for the 2FA token. </p><p>If they are not in the group, the login should be successful.<br><br><a href="//media.invisioncic.com/r328636/monthly_2025_10/image.png.4c3941fef2b1d68ce5268f4a4fca22f4.png" class="ipsAttachLink ipsAttachLink_image ipsRichText__align--block" data-fileid="39232" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="39232" src="//media.invisioncic.com/r328636/monthly_2025_10/image.thumb.png.4ad3598d1ff18de5f5090e626d83d883.png" alt="image.png" title="" width="1000" height="366" loading="lazy"></a><br></p><p>At first, I thought I would have to build a new login scheme for this, but it should actually be possible to implement it with the existing ones in Netscaler. </p><p>Does anyone here have any experience with this idea?<br></p>]]></description><guid isPermaLink="false">258503</guid><pubDate>Mon, 06 Oct 2025 14:37:17 +0000</pubDate></item><item><title>Access Gatway Timeouts not working for Worspace App only WebInterface</title><link>https://community.stage.citrix.com/forums/topic/258429-access-gatway-timeouts-not-working-for-worspace-app-only-webinterface/</link><description><![CDATA[<p>Hi everyone,</p><p>I’m running into the following issue: Our users access Citrix published desktops via NetScaler Access Gateway. Authentication is handled via nFlow with AD and RADIUS, using only ICA Proxy.</p><p>The goal is for the NetScaler/StoreFront session to disconnect after 5 minutes of inactivity—without affecting the desktop sessions themselves.</p><p>This works perfectly when logging in through the web interface (browser). After 5 minutes of inactivity, users are prompted to re-authenticate at the NetScaler, as expected.</p><p>The problem occurs when using the Citrix Workspace App. Users authenticate once at the NetScaler, and then they can leave it idle indefinitely—the desktop session continues, and starting the Citrix Workspace App reconnects them all the way to the desktop without requiring re-authentication at the NetScaler.</p><p>Ideally, we want the NetScaler to require re-authentication after 5 minutes of inactivity, regardless of which client is used. I’ve already set all timers to 5 minutes, but with the Workspace App, the connection from NetScaler to StoreFront either stays open or automatically re-authenticates.</p><p>Has anyone encountered this before or know how to enforce the 5-minute re-authentication for Workspace App users?</p>]]></description><guid isPermaLink="false">258429</guid><pubDate>Mon, 08 Sep 2025 14:30:53 +0000</pubDate></item><item><title>Citrix Workspace Linux Client hanging on white screen when connecting via Netscalar Gateway</title><link>https://community.stage.citrix.com/forums/topic/258419-citrix-workspace-linux-client-hanging-on-white-screen-when-connecting-via-netscalar-gateway/</link><description><![CDATA[<p>Hi all,</p><p>We are having an issue when trying to access our Citrix deployment via Netscalar Gateway using the Citrix Workspace Linux client on Ubuntu 24 and were wondering if anyone has come across anything similar?</p><p>We are seeing the following flow:</p><ol><li><p>Enter Netscalar Gateway domain into Add Account dialog and click Add Account.</p></li><li><p>The Netscalar Gateway login page is displayed. We enter username and password and click Login.</p></li><li><p>The login page closes and we are presented with a white screen, which hangs forever.</p></li></ol><p>Connecting to the same infrastructure using the Windows Citrix client and the Android Citrix client works correctly, but for some reason on Linux it hangs like this.</p><p>If we connect to the storefront directly without going via Netscalar, things also work fine.</p><p>We cannot see any logs at ~/.ICAClient/logs/ whilst hanging on the white screen. There are logs for the Netscalar login page, but as soon as you get to the white screen the logs just stop (set to verbose).</p><p>All we can see is that the "PrimaryAuthManager" process gets stuck at 100% CPU usage.</p><p>Any help would be much appreciated,</p><p>Thanks!</p>
<p><a href="//media.invisioncic.com/r328636/monthly_2025_09/citrix-white-screen.png.cdcf794e557281c20a007097cb49426b.png" class="ipsAttachLink ipsAttachLink_image" ><img data-fileid="39017" src="//media.invisioncic.com/r328636/monthly_2025_09/citrix-white-screen.thumb.png.53f93dd0110232a37fdf77b95fc4a517.png" height="561" width="1000" class="ipsImage ipsImage_thumbnailed" alt="citrix-white-screen.png" loading='lazy'></a></p>]]></description><guid isPermaLink="false">258419</guid><pubDate>Fri, 05 Sep 2025 12:58:36 +0000</pubDate></item><item><title>NetScaler Gateway - Connection Refused - VPX Express</title><link>https://community.stage.citrix.com/forums/topic/256768-netscaler-gateway-connection-refused-vpx-express/</link><description><![CDATA[<p>Hi everyone<br><br>Recently got around to deploying a Citrix Virtual Apps + Citrix NetScaler 14.1 environment in my lab, I am using the unlicensed/free version of NetScaler (14.1-47.46); VPX Express. </p><p><a href="//media.invisioncic.com/r328636/monthly_2025_08/image.png.54f2f53b3b6b7b47e59d14183451615c.png" class="ipsAttachLink ipsAttachLink_image ipsRichText__align--block" data-fileid="38949" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="38949" src="//media.invisioncic.com/r328636/monthly_2025_08/image.thumb.png.062cd62245a209ffe64e4a11273a1a66.png" alt="image.png" width="1000" height="628" loading="lazy"></a></p><p>Latest version of StoreFront/VDA 2402.</p><p></p><p>I've noticed, when I play a YouTube video, or do anything really bandwidth-intensive in a single Citrix session, I run into the issue that my NetScaler Gateway refuses/drops connections (ERR_CONNECTION_REFUSED) for other clients trying to connect:</p><p><a href="//media.invisioncic.com/r328636/monthly_2025_08/CF0A6DD3-C9E8-41B4-BE6B-261AB419ADD7.png.24d0327d25c63b30cf27fbe31442ef6a.png" class="ipsAttachLink ipsAttachLink_image ipsRichText__align--block" data-fileid="38944" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="38944" src="//media.invisioncic.com/r328636/monthly_2025_08/CF0A6DD3-C9E8-41B4-BE6B-261AB419ADD7.thumb.png.714b2a295dbef4ee2e92654d4a18a19a.png" alt="{CF0A6DD3-C9E8-41B4-BE6B-261AB419ADD7}.png" width="1000" height="540" loading="lazy"></a></p><p>If I stop playing a video, the problem "fixes" itself after a few moments.</p><p>When looking at Wireshark logs, I see RST, ACK when this happens (blurred out a line, that wasn't related to the client-NetScaler traffic):</p><p><a href="//media.invisioncic.com/r328636/monthly_2025_08/image.png.783a2d6ec191301fbec6acfda73c658f.png" class="ipsAttachLink ipsAttachLink_image ipsRichText__align--block" data-fileid="38945" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="38945" src="//media.invisioncic.com/r328636/monthly_2025_08/image.thumb.png.4ff171fb6c080c1029092e7b8d0672b6.png" alt="image.png" width="1000" height="97" loading="lazy"></a></p><p>10.61.1.93 - client<br>172.28.28.22 - NetScaler Gateway VS</p><p>My NetScaler does not exceed 20Mbps throughput (the error logs under the "System Log" tab were me experimenting with Exchange Server + NetScaler load balancing; I only have ICA Proxy traffic going through my NetScaler; I'm not really using any other features at the moment):</p><p><a href="//media.invisioncic.com/r328636/monthly_2025_08/image.png.7645842cb32acc718faff3fa5fa07350.png" class="ipsAttachLink ipsAttachLink_image ipsRichText__align--block" data-fileid="38946" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="38946" src="//media.invisioncic.com/r328636/monthly_2025_08/image.thumb.png.fcb778b620ee54e59dada5763ad3b9d0.png" alt="image.png" width="1000" height="629" loading="lazy"></a>:</p><p></p><p>In fact, I even tried setting a bandwidth limit policy in Citrix Studio to no avail:</p><p>:<a href="//media.invisioncic.com/r328636/monthly_2025_08/image.png.6d52b92f8825b084c90e4bfd45ffcbcd.png" class="ipsAttachLink ipsAttachLink_image ipsRichText__align--block" data-fileid="38947" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="38947" src="//media.invisioncic.com/r328636/monthly_2025_08/image.thumb.png.dd1d77ae2b788c8062544e2350943932.png" alt="image.png" width="1000" height="591" loading="lazy"></a></p><p><a href="//media.invisioncic.com/r328636/monthly_2025_08/image.png.5fc37ccfd446d1a585bc62066f05b0fd.png" class="ipsAttachLink ipsAttachLink_image ipsRichText__align--block" data-fileid="38948" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="38948" src="//media.invisioncic.com/r328636/monthly_2025_08/image.thumb.png.6a83a37207e18adf760e3d1732521c3b.png" alt="image.png" width="1000" height="538" loading="lazy"></a></p><p>Anyone have any idea what could be causing this? This is in a lab environment, so I don't have active Citrix licensing for this deployment (VPX Express/30 day trial)<br><br>Thanks in advance!</p><p></p>]]></description><guid isPermaLink="false">256768</guid><pubDate>Sun, 17 Aug 2025 19:34:09 +0000</pubDate></item><item><title>How to confirm SNMP version enabled on NetScaler</title><link>https://community.stage.citrix.com/forums/topic/256728-how-to-confirm-snmp-version-enabled-on-netscaler/</link><description><![CDATA[<p>Hello all. </p><p>Simple question, but I cannot figure out how to find out what version(s) of SNMP are installed on my NetScaler ADC. I have a pair of MPX-5900 NetScaler's running firmware version 13.1.59.19. </p><p>I appreciate any help here that I can get. </p><p>Thank you,</p><p>Shane</p>]]></description><guid isPermaLink="false">256728</guid><pubDate>Thu, 31 Jul 2025 02:53:32 +0000</pubDate></item><item><title>Netscaler Gateway: X-Forward-For info</title><link>https://community.stage.citrix.com/forums/topic/256750-netscaler-gateway-x-forward-for-info/</link><description><![CDATA[<p>Hello,<br>I would like to configure Netscaler Gateway so that both successful and failed login attempts include the <strong>X-Forward-For</strong> information in the logs, and have these logs sent to an external syslog server for security purposes.<br>So far, I have only found documentation related to the Load Balancer, but nothing specific to Netscaler Gateway.<br>Could you please advise or provide guidance on how to achieve this?</p>]]></description><guid isPermaLink="false">256750</guid><pubDate>Fri, 08 Aug 2025 06:27:56 +0000</pubDate></item><item><title>EDT is working on internall network but not on external network via citrix gateway</title><link>https://community.stage.citrix.com/forums/topic/256600-edt-is-working-on-internall-network-but-not-on-external-network-via-citrix-gateway/</link><description><![CDATA[<p>EDT is working on internall network but not on external network via citrix gateway</p>]]></description><guid isPermaLink="false">256600</guid><pubDate>Mon, 16 Jun 2025 15:52:08 +0000</pubDate></item><item><title>NetScaler Gateway VPN issue with Windows 11 24H2</title><link>https://community.stage.citrix.com/forums/topic/253532-netscaler-gateway-vpn-issue-with-windows-11-24h2/</link><description><![CDATA[<p>
	Hi all:
</p>

<p>
	One customer have reported VPN connection issue when some of the user have upgraded to Windows 11 24H2. I see there are Windows forums where they say this version have issues with multiple VPN vendors. Is there any Secure access client upgrade to overcome this issue?
</p>

<p>
	Thank you an best regards
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">253532</guid><pubDate>Tue, 07 Jan 2025 10:17:34 +0000</pubDate></item><item><title>SessionID in the auditmessages</title><link>https://community.stage.citrix.com/forums/topic/256702-sessionid-in-the-auditmessages/</link><description><![CDATA[<p>Hello,</p><p>We updated our Gateway appliance from NS14.1: Build <a rel="external nofollow" href="https://12.35.nc">12.35.nc</a> to NS14.1: Build <a rel="external nofollow" href="https://47.46.nc">47.46.nc</a> and noticed that the structure of loglines has changed.</p><p>Loglines of SSLVPN events don't contain Context and SessionId fields in the NS14.1: Build <a rel="external nofollow" href="https://47.46.nc">47.46.nc</a> . Events with AAA LOGIN_FAILED also disappeared. Unfortunately, I couldn't find any information in the release notes changes. <br><a rel="external nofollow" href="https://docs.netscaler.com/en-us/updates?product=NetScaler%2520Console%2520on-prem%2520%28ADM%29&amp;version=14.1&amp;build=47.46">https://docs.netscaler.com/en-us/updates?product=NetScaler%2520Console%2520on-prem%2520%28ADM%29&amp;version=14.1&amp;build=47.46</a> .</p><p>Could someone please provide some information about these changes?</p><p></p><p>Example of NS14.1: Build <a rel="external nofollow" href="https://12.35.nc">12.35.nc</a><br>&lt;190&gt; 02/21/2024:15:49:46 GMT netscaler-14 0-PPE-0 : default SSLVPN LOGIN 4349 0 : Context vpnuser-1@9X.X.X.252 - SessionId: 17 - User vpnuser-1 - Client_ip 9X.X.X.252 - Nat_ip 192.168.199.2 - Vserver 10.52.0.154:5443 - Browser_type "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36 Edg/121.0.0.0" - SSLVPN_client_type Agent - Group(s) "N/A"</p><p>Example of NS14.1: Build <a rel="external nofollow" href="https://47.46.nc">47.46.nc</a><br>&lt;190&gt; 07/22/2025:08:45:14 GMT netscaler-14 0-PPE-0 : default SSLVPN LOGIN 564 0 : User vpnuser-1 - Client_ip 9X.X.X.252 - Nat_ip 192.168.199.1 - Vserver 10.52.0.154:5443 - Browser_type "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0" - SSLVPN_client_type Clientless - Group(s) "N/A"</p>]]></description><guid isPermaLink="false">256702</guid><pubDate>Tue, 22 Jul 2025 12:13:48 +0000</pubDate></item><item><title>Citrix 1Y0-241 Certification Guidance</title><link>https://community.stage.citrix.com/forums/topic/253457-citrix-1y0-241-certification-guidance/</link><description><![CDATA[<p>
	Hi All,
</p>

<p>
	Can you help me with Citrix Certification exam 1Y0-241  preparation.
</p>

<p>
	Looking for material and topics to pass the exam.
</p>
]]></description><guid isPermaLink="false">253457</guid><pubDate>Sun, 01 Dec 2024 05:37:35 +0000</pubDate></item><item><title>please guide us regarding actual VPN logs.</title><link>https://community.stage.citrix.com/forums/topic/253725-please-guide-us-regarding-actual-vpn-logs/</link><description><![CDATA[<p style="background-color:#ffffff;color:#353c41;font-size:14px;">
	Dear Sir,
</p>

<p style="background-color:#ffffff;color:#353c41;font-size:14px;">
	we are unable to search  actual VPN logs which are shown below 
</p>

<p style="background-color:#ffffff;color:#353c41;font-size:14px;">
	Nov 28 12:17:01 &lt;local0.info&gt; 10.x.x.x 11/28/2019:17:17:01 GMT ns 0-PPE-0 : default<span> </span><strong>SSLVPN LOGIN</strong><span> </span>217333 0 : Context<span> </span>sjacobs@100.x.x.x<span> </span>- SessionId: 75- User sjacobs - Client_ip 100.x.x.x - Nat_ip "Mapped Ip" - Vserver 10.x.x.x:443 - Browser_type "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36 Edge/17.171" 
</p>

<p style="background-color:#ffffff;color:#353c41;font-size:14px;">
	 
</p>

<p style="background-color:#ffffff;color:#353c41;font-size:14px;">
	We are using below commands for vpn logs which are not detailed about vpn logs.
</p>

<p>
	cd /var/log 
</p>

<p>
	tail -f ns.log | grep -i vpn
</p>

<p>
	 
</p>

<p>
	Mar 29 10:10:41 &lt;local0.info&gt; xxx.xx.xxx.xx 03/29/2025:04:40:41 GMT NS-VPX-01 0-PPE-2 : default SSLVPN Message 786674983 0 :  "GwInsight: Sent App launch record, StatusCode=254 VPNexportState=6 Func=ns_sslvpn_send_app_launch_record Username=xxx@yyy.com SessSeq=996 Clientip=78456ce6a:78945 Destip=5be8a9c0:50 Gwip=78fa675a:443 CSappid=0 CSAppname=(null) VPNfqdn=yyy.com SSOAuthMethod=0 BackendServername=xx.xx.xxx.x SSOurl= SSOduration=0 email=xxx@yyy.COM" 
</p>
]]></description><guid isPermaLink="false">253725</guid><pubDate>Sat, 29 Mar 2025 06:44:26 +0000</pubDate></item><item><title>AlwaysOn after User Logon and Windows 11 24h2</title><link>https://community.stage.citrix.com/forums/topic/256624-alwayson-after-user-logon-and-windows-11-24h2/</link><description><![CDATA[<p>Howdy All,</p><p>Thought I would post here...  We do an ALwaysOn connection currently, post User logon. We do not do the pre-machine tunnel connection, only after User Auth to Windows.</p><p>In Win10 there are no issues, it all works as expected, user logs into device, client starts up, has their credentials and logs them into the VPN service, all Happy.</p><p>However, with Windows 11 24h2 this is not working.  The client opens as expected, but does not remember the client credentials, and prompts for password.  Once that it does it connects, no issues...</p><p>Anyone got the User Tunnel auto Logon working with Win11 24h2 at all?</p><p>Are ADC still at <a rel="external nofollow" href="https://13.1.XXX">13.1.XXX</a> secure access client is the latest one available we are testing with.</p><p>Auth Policies on the ADC are NOT nFactor set up yet, we need to migrate at some point prior to 14 upgrades.</p><p>We think it might be something around new LSA lockdowns and policies in Win11, preventing the password from being stored as it usually is for the user?  but no logs are really showing us anything of value.</p><p>Any assistance? surely we cannot be the only ones facing this issue?  And yeah we have a support case, but trying to reach out to wider community to see if others have also had the same issues??</p>]]></description><guid isPermaLink="false">256624</guid><pubDate>Wed, 25 Jun 2025 04:29:37 +0000</pubDate></item><item><title>Sudden NTLM Fallback with Microsoft Edge on Netscaler Gateway Login Page</title><link>https://community.stage.citrix.com/forums/topic/256496-sudden-ntlm-fallback-with-microsoft-edge-on-netscaler-gateway-login-page/</link><description><![CDATA[<p>
	Hi,
</p>

<p>
	we are using netscaler gateway as remote login via storefront and LDAP.  We have noted that after a password change,  the old password still work for some minutes.
</p>

<p>
	Google says that this comes from an usage of NTLM  Authentication.  
</p>

<p>
	Where Can i deactivate this NTLM Fallback in Netscaler ?
</p>

<p>
	 
</p>

<p>
	regards
</p>

<p>
	Robert
</p>
]]></description><guid isPermaLink="false">256496</guid><pubDate>Mon, 28 Apr 2025 11:23:44 +0000</pubDate></item></channel></rss>
