<?xml version="1.0"?>
<rss version="2.0"><channel><title>NetScaler ADC &#x2013; Core Features Latest Topics</title><link>https://community.stage.citrix.com/forums/forum/5-netscaler-adc-core-features/</link><description>NetScaler ADC &#x2013; Core Features Latest Topics</description><language>en</language><item><title>How to run two CA groups for mTLS on CS VSERVER</title><link>https://community.stage.citrix.com/forums/topic/258715-how-to-run-two-ca-groups-for-mtls-on-cs-vserver/</link><description><![CDATA[<p>Hello,</p><p>I have a CS VSERVER where I'm using CS policy to decide what "backend" LB vserver should be used based on "HTTP.REQ.HOSTNAME.".</p><p>One backend is PROD, second is UAT and based on which hostname is client connecting, it decides what "backend" LB vserver to use.</p><p>I have SNI enabled and have two SSL certs configured with option -SNICert. One cert for PROD, second for UAT.</p><p>Now I need to enable mTLS, that's not a problem, I set "-clientAuth ENABLED -clientCert Mandatory" in "set ssl vserver &lt;CS_SERVER&gt;" command and bind CA certificates using -CA option. Problem is, that I need separate CAs for PROD and UAT.  In this setup every CA will be able to verify clients on both PROD and UAT. We do not want on clients to use UAT certificate and be able to use PROD service.</p><p>In summary, based for example SNI information, "uat.myservice.com" client will be verified with CA_1 and CA_2, then for "prod.myservice.com" will be verified with CA_3 and CA_4.</p><p>So, if client has a cert from CA_1 and tries to connect to "prod.myservice.com", citrix will refuse.</p><p></p><p>I tried to used ssl policy and action but no success to achieve this.</p><p>Does anyone know how to do it? </p><p>Thank you.</p>]]></description><guid isPermaLink="false">258715</guid><pubDate>Fri, 23 Jan 2026 00:07:20 +0000</pubDate></item><item><title>Trying to generate nonce header in Netscaler version 14.1 with random hash, no path in GUI and cannot seem to get it to work in CLI</title><link>https://community.stage.citrix.com/forums/topic/258706-trying-to-generate-nonce-header-in-netscaler-version-141-with-random-hash-no-path-in-gui-and-cannot-seem-to-get-it-to-work-in-cli/</link><description><![CDATA[<p>I am using the NetScaler GUI version 14.1, I am trying to find the correct way to do the following, however I cannot seem to get it right with the options I am given. Does anyone happen to have a solution.</p><p style="text-align:left;">This is what I tried, keep hitting a road block...</p><pre spellcheck="" class="ipsCode language-plaintext" data-language="Plain Text"><code>add rewrite action RW_GEN_CSP_NONCE \
    replace_all \
    HTTP.RES.HEADER("X-CSP-Nonce") \
    base64(rand(16))
</code></pre><p style="text-align:left;">However in the GUI there seems to be no path to actually add base64(rand(16))</p><p style="text-align:left;">Any suggestions on how to get a random generated hash header added via netscaler?</p><p style="text-align:left;"><strong>I tried the following in CLI:</strong></p><p style="text-align:left;"><code>add rewrite action RW_GEN_CSP_NONCE replace_all HTTP.RES.HEADER("X-CSP-Nonce") base64(rand(16))</code></p><p style="text-align:left;"><code>add rewrite action RW_GEN_CSP_NONCE replace_all HTTP.RES.HEADER("X-CSP-Nonce") "base64(rand(16))"</code></p><p style="text-align:left;">Both throw error <code>ERROR: Invalid argument.</code></p><p style="text-align:left;">What is the proper way to do this, I am at a loss here.</p>]]></description><guid isPermaLink="false">258706</guid><pubDate>Fri, 16 Jan 2026 16:45:24 +0000</pubDate></item><item><title>Support account set up without partner</title><link>https://community.stage.citrix.com/forums/topic/258648-support-account-set-up-without-partner/</link><description><![CDATA[<p>I'm assisting a company that has a couple NetScalers deployed/purchased/licensed thru Azure. There isn't a Citrix partner involved.  I need to get a support account set up for this customer and set up NetScaler cloud console. But i can't seem to find a way to do this myself online. Phone support is no longer in service. I'm not sure how to proceed. </p>]]></description><guid isPermaLink="false">258648</guid><pubDate>Mon, 15 Dec 2025 17:12:15 +0000</pubDate></item><item><title>CCA-AppDS (ADC 14.x with Traffic Management)</title><link>https://community.stage.citrix.com/forums/topic/258691-cca-appds-adc-14x-with-traffic-management/</link><description><![CDATA[<p>I am planning to take this certification, need help with training videos and books I can refer.</p><p>Could someone help on this please? Much appreciate your reply.</p>]]></description><guid isPermaLink="false">258691</guid><pubDate>Sat, 10 Jan 2026 07:37:32 +0000</pubDate></item><item><title>Need Help With NetScaler Scenario</title><link>https://community.stage.citrix.com/forums/topic/258633-need-help-with-netscaler-scenario/</link><description><![CDATA[<p>Hey everyone,</p><p>I’m currently preparing for the 1Y0-312 exam and have been working through different resources, labs, and Citrix documentation. Midway through my prep, I started using CertsMatrix, which has been really helpful for practicing scenario-based questions and understanding how NetScaler behaves in real enterprise environments.</p><p>I’m stuck on a scenario and would appreciate some guidance:</p><p>If you have a NetScaler setup handling high traffic across multiple load-balanced services, and users intermittently report session drops during peak hours, what would be the best troubleshooting path?</p><p>Should I start by reviewing persistence methods, checking load-balancing algorithms, or analyzing TCP/HTTP connection limits on the virtual server?</p><p>Anyone who has taken the exam or dealt with similar production issues your insights would be extremely helpful for my preparation.</p><p>Thanks in advance!</p>]]></description><guid isPermaLink="false">258633</guid><pubDate>Sat, 06 Dec 2025 09:46:23 +0000</pubDate></item><item><title>exchange 2019 LB guide</title><link>https://community.stage.citrix.com/forums/topic/246734-exchange-2019-lb-guide/</link><description><![CDATA[<p>
	Looking for the most up to date guide / best practice for configuring load balancing on Citrix ADC for exchange 2019.  This is on premises exchange.
</p>

<p>
	I am using Citrix ADC LB.
</p>

<p>
	#NS12.1 Build 57.18
</p>

<p>
	 
</p>

<p>
	They have some older guides in PDF here:
</p>

<p>
	<a href="https://www.citrix.com/products/citrix-adc/resources/deploy.html" rel="external nofollow">https://www.citrix.com/products/citrix-adc/resources/deploy.html</a><br>
	And a newer guide here but different format:
</p>

<p>
	<a href="https://docs.citrix.com/en-us/citrix-adc/current-release/load-balancing/load-balancing-common-protocols/lb-microsoft-exchange-server.html" rel="external nofollow">https://docs.citrix.com/en-us/citrix-adc/current-release/load-balancing/load-balancing-common-protocols/lb-microsoft-exchange-server.html</a>
</p>

<p>
	 
</p>

<p>
	Which guide to go with ?<br><br>
	Also on the newer guide they mention CAS server, which is confusing because Exchange no longer uses a dedicated CAS server.  
</p>]]></description><guid isPermaLink="false">246734</guid><pubDate>Thu, 26 Aug 2021 22:10:11 +0000</pubDate></item><item><title>Service groups, services and virtual servers in a DOWN state (state and effective state)</title><link>https://community.stage.citrix.com/forums/topic/245443-service-groups-services-and-virtual-servers-in-a-down-state-state-and-effective-state/</link><description><![CDATA[<p>
	Hey folks,
</p>

<p>
	 
</p>

<p>
	I have some issues testing load balancing feature on my appliance (CITRIX ADC MPX 5901 build 11.1). After creating services, service groups, virtual servers and binding the service groups and services to virtual servers, they all appear to be in a DOWN state, both state and effective state.
</p>

<p>
	Please, where may be the issue?
</p>

<p>
	 
</p>

<p>
	PS1 : The servers appears ENABLED and the services are of different protocols  (HTTP, FTP, TCP, SSL and DNS).
</p>

<p>
	PS2 : Load balancing and SSL Offloading are enabled also
</p>]]></description><guid isPermaLink="false">245443</guid><pubDate>Wed, 24 Mar 2021 17:54:42 +0000</pubDate></item><item><title>How to clean up bad ACL on NetScaler SDX</title><link>https://community.stage.citrix.com/forums/topic/232467-how-to-clean-up-bad-acl-on-netscaler-sdx/</link><description><![CDATA[
<p>
	Someone created a bad ACL on the NetScaler SDX and we want to clean it up.  However there does not seem to be a way to remove it.
</p>

<p>
	 
</p>

<p>
	This is what they did:  (All in the GUI, because it looks like on the SDX I could not find a way to configure the ACL via the command line on SDX.)
</p>

<p>
	1.  Enabled ACL
</p>

<p>
	2.  Added a bad rule that removed all access to the SDX SVM.
</p>

<p>
	 
</p>

<p>
	Because we could no longer connect to the SDX via SSH or HTTPS I connected via the XenServer and issued this command to disable the ACL
</p>

<p>
	pfctl -d   Per:  <a href="https://docs.citrix.com/en-us/sdx/12-1/configuring-management-service/access-control-lists.html" rel="external nofollow">https://docs.citrix.com/en-us/sdx/12-1/configuring-management-service/access-control-lists.html</a> 
</p>

<p>
	 
</p>

<p>
	So now I can connect back to the SDX via SSH And HTTPS.
</p>

<p>
	 
</p>

<p>
	However there does not seem to be a way to remove/cleanup the bad rule.
</p>

<p>
	 
</p>

<p>
	I can't disable/delete the rule with ACL Disabled.
</p>

<p>
	I can't add a good rule with the ACL disabled.
</p>

<p>
	If I enable ACL then, because of the bad rule, I will immediately be kicked out of the HTTPS and SSH.   
</p>

<p>
	 
</p>

<p>
	Any Advice?
</p>

<p>
	 
</p>

<p>
	Thanks,
</p>

<p>
	Carl
</p>

<p>
	 
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">232467</guid><pubDate>Wed, 31 Oct 2018 02:25:40 +0000</pubDate></item><item><title>Lack of anti-CSRF tokens in Netscaler GUI replies</title><link>https://community.stage.citrix.com/forums/topic/258651-lack-of-anti-csrf-tokens-in-netscaler-gui-replies/</link><description><![CDATA[<p>Some time ago, we conducted a security audit. The auditor detected an <strong>issue with missing Anti-CSRF tokens when accessing the Netscaler GUI</strong>. I know that CSRF protection is available through Web Application Firewall (WAF) and is fully supported for applications hosted behind Netscaler, such as Gateway and vServer load balancers. My NSIP is available on a trusted internal network, exposure to CSRF risk is limited. Nevertheless, my company's security department still requires anti-CSRF protection when accessing the Netscaler GUI. Could you consider and implement the required feature in a future release?</p>]]></description><guid isPermaLink="false">258651</guid><pubDate>Wed, 17 Dec 2025 11:57:14 +0000</pubDate></item><item><title>Help with Netscaler Syslog forwarding</title><link>https://community.stage.citrix.com/forums/topic/258653-help-with-netscaler-syslog-forwarding/</link><description><![CDATA[<p>Hi all,<br><br>We've got a 'bit of a strange issue, that I can't quite wrap my head around.<br><br>We've got two distinct Syslog servers configured to receive logs, one UDP, the other TCP.<br><br>Each has it's own Auditing Policy, bound Globally. The UDP Server and Policy are setup and working, but the TCP one is giving us all kinds of hell. We're getting a TCP connection to the receiving server, but when I view the packet capture data, they're just empty packets.<br><br>I've replicated the setup in my lab environment, with UDP and TCP destinations, albeit the same destination IP, and then it works as expected.<br><br>Is there some caveat I'm missing? Or something really obvious?</p>]]></description><guid isPermaLink="false">258653</guid><pubDate>Thu, 18 Dec 2025 11:58:48 +0000</pubDate></item><item><title>Optimizing Citrix Workspace Experience on New AI PC Endpoints</title><link>https://community.stage.citrix.com/forums/topic/258613-optimizing-citrix-workspace-experience-on-new-ai-pc-endpoints/</link><description><![CDATA[<p>Hi Citrix Community,</p><p>I’m testing Citrix Virtual Apps and Desktops on a new set of <a rel="external nofollow" href="https://www.lenovo.com/gb/en/lenovoauraedition/"><strong>AI PC</strong></a> endpoints in our environment, and I’m hoping to gather some best-practice insights from others who may be doing similar upgrades. These devices are delivering great local performance, and I’m exploring how to fully leverage their advanced CPU/GPU capabilities within HDX sessions.</p><p>Our current setup includes CVAD 2203 LTSR, Windows 11 VDAs, and the latest Workspace App. I’ve enabled various graphics optimizations such as hardware acceleration and enhanced display policies, and I’m now evaluating which settings produce the smoothest user experience, especially for teams working with design tools and analytics dashboards.</p><p>I’m curious whether anyone has recommendations for ideal HDX policies, GPU tuning, or endpoint configurations specifically for AI-enhanced PCs. Any shared experiences or tuning tips would be greatly appreciated!</p><p>Thank you!</p>]]></description><guid isPermaLink="false">258613</guid><pubDate>Mon, 24 Nov 2025 05:20:31 +0000</pubDate></item><item><title>How to add SameSite, Secure and HttpOnly security flags on citrix_ns_id cookie</title><link>https://community.stage.citrix.com/forums/topic/258629-how-to-add-samesite-secure-and-httponly-security-flags-on-citrix_ns_id-cookie/</link><description><![CDATA[<p>Hello, we are using Netscaler <span style="font-family: Helvetica, Arial, sans-serif;">ADC VPX (200) NS14.1 56.74.nc, and I need to add SameSite, Secure and HttpOnly security flags to citrix_ns_id cookie.</span></p><p>I've tried adding them with request policy on CS and LB and also using NetScaler Web App Firewall profile/policy but it didn't worked.</p><p>How can I achieve this?</p><p>Thank you!</p>]]></description><guid isPermaLink="false">258629</guid><pubDate>Tue, 02 Dec 2025 16:28:23 +0000</pubDate></item><item><title>unable to create Auditing server</title><link>https://community.stage.citrix.com/forums/topic/258535-unable-to-create-auditing-server/</link><description><![CDATA[<p>Hi,</p><p>we are unable to create new Auditing SYSLOG server nor edit existing. It shows the error :</p><p>"Password length should adhere to minimum password length value in system parameter settings."</p><p>We have global strong local passwd set, and minimum length is 8. All standard checks done. We can delete existing audit syslog server or actions, but not add new one.</p><p>Any1 could advice on this?</p><p>Thanks</p><p>Rasto</p>]]></description><guid isPermaLink="false">258535</guid><pubDate>Wed, 22 Oct 2025 12:01:47 +0000</pubDate></item><item><title>Cannot access MySQL when load-balanced behind Netscaler</title><link>https://community.stage.citrix.com/forums/topic/258568-cannot-access-mysql-when-load-balanced-behind-netscaler/</link><description><![CDATA[<p>I just tested to load balance 3 mariadb galera server using netscaler. i want to do load balance based on request (read/write). So far i have configure the service to use mysql protocol and also configure virtual server using mysql protocol. However, when i try to connect, it just keep disconnecting after i keyin the password. for your info, this test i just use 1 server first just to see if connection is ok. However, when i change the protocol to TCP for both services and also virtual server, i can login to the backend mariadb through netscaler without any issue.</p><p>is there anything else that i need to configure or that i missed? please advise.</p>]]></description><guid isPermaLink="false">258568</guid><pubDate>Fri, 07 Nov 2025 09:08:35 +0000</pubDate></item><item><title>Content switch Target-type GSLB</title><link>https://community.stage.citrix.com/forums/topic/258538-content-switch-target-type-gslb/</link><description><![CDATA[<p>HI</p><p>Trying to understand the Content Switch with 'target type = GSLB'.</p><p>(NB! its not a GSLB Service pointing to a 'CSVS IP'  i'm interrested in, but the setup using CSVS with 'target type = GSLB')</p><p>When setting up and creating af content switch policy (with or without action), I get '<span style="font-family: Helvetica, Arial, sans-serif;">CS Policy has no action or CS action doesn't have targetVserver'</span><br><span style="font-family: Helvetica, Arial, sans-serif;">(off course I have pointet to an LB vserver of the same protocol..)</span></p><p><span style="font-family: Helvetica, Arial, sans-serif;">Besides the above error, there seems to be NO usable guides how to set it up, and this link doesn't clearify it either '</span><a rel="external nofollow" href="https://docs.netscaler.com/en-us/citrix-adc/current-release/global-server-load-balancing/how-to/configure-gslb-content-switch.html"><span style="font-family: Helvetica, Arial, sans-serif;">https://docs.netscaler.com/en-us/citrix-adc/current-release/global-server-load-balancing/how-to/configure-gslb-content-switch.html</span></a><span style="font-family: Helvetica, Arial, sans-serif;">'</span></p><p><span style="font-family: Helvetica, Arial, sans-serif;">Hope someone has a config they can share, or a usable documentation.</span></p><p>/Frank</p>]]></description><guid isPermaLink="false">258538</guid><pubDate>Thu, 23 Oct 2025 08:28:55 +0000</pubDate></item><item><title>Content Switch not working as expected after update to 14.1 Build 56.74 ADFS</title><link>https://community.stage.citrix.com/forums/topic/258618-content-switch-not-working-as-expected-after-update-to-141-build-5674-adfs/</link><description><![CDATA[<p>We're having a strange behavior on a CS that is pointing to ADFS. The CS has a very simple Policy expression:</p><p><span style="font-family: Helvetica, Arial, sans-serif;">HTTP.REQ.HOSTNAME.EQ("</span><a rel="external nofollow" href="https://adfs.rhenus.ch"><span style="font-family: Helvetica, Arial, sans-serif;">adfs.example.com</span></a><span style="font-family: Helvetica, Arial, sans-serif;">")</span></p><p>This works as expected, as long as the requested URL does not containt "/adfs/ls/"</p><p>e.g:</p><p>Works:<br><a rel="external nofollow" href="https://adfs.example.com/">https://adfs.example.com/</a><br><a rel="external nofollow" href="https://adfs.example.com/adfs/">https://adfs.example.com/adfs/</a></p><p><a rel="external nofollow" href="https://adfs.example.com/adfs/ls">https://adfs.example.com/adfs/ls</a></p><p><a rel="external nofollow" href="https://adfs.example.com/adfs/ls/">https://adfs.example.com/adfs/ls123/</a></p><p><a rel="external nofollow" href="https://adfs.example.com/adfs/ls/">https://adfs.example.com/adfs/ls123/123</a></p><p></p><p>Does not work:</p><p><a rel="external nofollow" href="https://adfs.example.com/adfs/ls/">https://adfs.example.com/adfs/ls/</a></p><p><a rel="external nofollow" href="https://adfs.example.com/adfs/ls/">https://adfs.example.com/adfs/ls/123</a></p><p>The LB Vserver that is the target has Authentication enabled. In the non-working example, we receive a HTTP 1.1 in the other examples we get redirected to the Auth vserver, as expected. An existing Session will also not work, the HTTP 1.1 persists.</p><p></p><p>This worked for years before we've updated. I also logged a case with citrix, but so far they did not find the issue.</p><p>Anyone else experiencing the same?</p><p></p>]]></description><guid isPermaLink="false">258618</guid><pubDate>Wed, 26 Nov 2025 10:55:46 +0000</pubDate></item><item><title>NetScaler OTP encryption tool</title><link>https://community.stage.citrix.com/forums/topic/258579-netscaler-otp-encryption-tool/</link><description><![CDATA[<p>Does anyone use the <a rel="external nofollow" href="https://docs.netscaler.com/en-us/citrix-adc/current-release/aaa-tm/authentication-methods/native-otp-authentication/otp-encryption-tool.html">OTP encryption tool?</a>  The certificate we use to encrypt OTP is expiring in a few months, so I was going to set it up to rotate the certificate.  The docs suggest it just needs to be python 3.5+.  I copied the files over to a linux server with Python 3.12.3, created a venv and tried to install all the requirements.  The process fails trying on step "Building wheel for cffi (pyproject.toml) ... error".</p><p>Before I go too far down the route of troubleshooting to get this work, I am wondering if someone has already figured this out.  (Or maybe it isn't used much.)</p><p></p>]]></description><guid isPermaLink="false">258579</guid><pubDate>Wed, 12 Nov 2025 20:47:49 +0000</pubDate></item><item><title>Content Inspection not working as expected</title><link>https://community.stage.citrix.com/forums/topic/258578-content-inspection-not-working-as-expected/</link><description><![CDATA[<p>Hello everyone,<br><br>I'm following to this document <a rel="external nofollow" href="https://docs.netscaler.com/en-us/citrix-adc/current-release/content-inspection/intrusion-detection-system-for-l3">Integrating NetScaler layer 3 with passive security devices </a>to send TCP packets via L3 Iptunnel, I followed every step and not able to see packet at IDS. My environment runs on Azure, I can reach our API application over Netscaler, I tried to manage it with Netscaler IP and Vırtual IP(with second interface). <br><br>I can see at Content Inspection policy, hit count's are increasing but no packet delivered to IDS service and also the stats not increased at IDS Service statistics. <br><br></p>]]></description><guid isPermaLink="false">258578</guid><pubDate>Wed, 12 Nov 2025 17:06:17 +0000</pubDate></item><item><title>Anybody migrated NetScaler VPXs from SDX8015 to new SDX9100Z? Is there any defined process for it?</title><link>https://community.stage.citrix.com/forums/topic/325-anybody-migrated-netscaler-vpxs-from-sdx8015-to-new-sdx9100z-is-there-any-defined-process-for-it/</link><description>Anybody migrated NetScaler VPXs from SDX8015 to new SDX9100Z? Is there any defined process for it?</description><guid isPermaLink="false">325</guid><pubDate>Mon, 08 Jan 2024 22:21:29 +0000</pubDate></item><item><title>Netscalers with cloudbased WAF/DDoS in front causing issues.</title><link>https://community.stage.citrix.com/forums/topic/258548-netscalers-with-cloudbased-wafddos-in-front-causing-issues/</link><description><![CDATA[<p>Hi</p><p>After enabling a cloud based WAF, we have had issues when used in combination with Citrix Netscaler maintenance page.</p><p>The issue is that the maintenance page seems to stay active, even after the primary Vserver come online after a maintenance window.</p><p>Our suspicion is, that session reuse in the cloud, is kept active/open, and thus seen from the cloud service as a valid connection to use. I can manually then close the maintenance vserver and reopen it, which will terminate all existing connections. The Netscaler does not seem to have a way to enforce breaking maintenance connections.</p><p>Have you experience anything similar to this?</p><p></p><p>/Peter</p>]]></description><guid isPermaLink="false">258548</guid><pubDate>Mon, 27 Oct 2025 10:12:28 +0000</pubDate></item><item><title>Load balance LDAP/LDAPS</title><link>https://community.stage.citrix.com/forums/topic/258478-load-balance-ldapldaps/</link><description><![CDATA[<p>Hello Im trying to load balance 2 AD servers since we currently doesnt have any good load balancing tool for older systems </p><p><a rel="external nofollow" href="https://AD1.DOMAIN.COM">AD1.DOMAIN.COM</a> and <a rel="external nofollow" href="https://AD2.DOMAIN.COM">AD2.DOMAIN.COM</a>	</p><p>Created servers  <span class="ipsEmoji" title="check mark button">✅</span></p><p>Created Virtual Server with 636 and 389 port (Same IP and same SNIP as the AD1 and AD2 <span class="ipsEmoji" title="check mark button">✅</span></p><p>Created 2 monitors with a SVC account <span class="ipsEmoji" title="check mark button">✅</span></p><p>To check I created services for each AD1 and each port <span class="ipsEmoji" title="check mark button">✅</span> - Will convert to group after confirmed working</p><p>Bound said services to LBVS server and the monitor to each services </p><p>I still get the failure - Failed to search on the server but when connecting with said account directly to the server it works. Citrix support has been a bit frustrating as they had me try several things without any real explanation. Our AD people cant see any searches with the account on their end so im wondering what am I doing wrong here? </p><p>Kind Regards</p><p>Markus</p><p></p><p></p>
<p><a href="//media.invisioncic.com/r328636/monthly_2025_09/Monitor.png.7c22ed0f1f0dba1e053f422387371887.png" class="ipsAttachLink ipsAttachLink_image" ><img data-fileid="39208" src="//media.invisioncic.com/r328636/monthly_2025_09/Monitor.thumb.png.cc49164c5715c5b4417e188115634b6a.png" height="690" width="1000" class="ipsImage ipsImage_thumbnailed" alt="Monitor.png" loading='lazy'></a></p>
<p><a href="//media.invisioncic.com/r328636/monthly_2025_09/LBS.png.00db86d6015270cde0c7809756f38587.png" class="ipsAttachLink ipsAttachLink_image" ><img data-fileid="39209" src="//media.invisioncic.com/r328636/monthly_2025_09/LBS.thumb.png.1982cccd83103b0f0df114863fc95f73.png" height="690" width="1000" class="ipsImage ipsImage_thumbnailed" alt="LBS.png" loading='lazy'></a></p>]]></description><guid isPermaLink="false">258478</guid><pubDate>Thu, 25 Sep 2025 13:57:41 +0000</pubDate></item><item><title>SSL LB VIP Certificate upgrades - disruptive or not ?</title><link>https://community.stage.citrix.com/forums/topic/258531-ssl-lb-vip-certificate-upgrades-disruptive-or-not/</link><description><![CDATA[<p>Hi everyone,</p><p>I’m looking for clarification on how Citrix ADC handles SSL certificate updates for Load Balancing VIPs.</p><p>Specifically:<br>If I use the <strong>Update</strong> method to replace the certificate-key pair bound to an SSL LB VIP, will <strong>existing SSL sessions</strong> be disrupted? Or will the new certificate only be used for <strong>new incoming connections</strong>, while existing sessions continue using the old certificate until they expire or renegotiate?</p><p>I understand this is how SSL/TLS typically behaves, but I’m looking for <strong>Citrix-specific confirmation</strong> — ideally from documentation or real-world experience.<br><br>Background:<br>I need this information so I can implement an Ansible automation for implementing SSL certificate upgrades.<br>After a successful upgrade automation will remove old certificate and key files.</p><p>Thanks in advance!</p>]]></description><guid isPermaLink="false">258531</guid><pubDate>Tue, 21 Oct 2025 10:39:58 +0000</pubDate></item><item><title>problem with two NetScaler SAML</title><link>https://community.stage.citrix.com/forums/topic/249461-problem-with-two-netscaler-saml/</link><description><![CDATA[<p>
	Greeting.
</p>

<p>
	I have two NetScaler and I need to make SAML.
</p>

<p>
	one of them as SP with AAA for LB and use Authentication Virtual Servers. and one as IDP, and in the "Redirect URL :https://xxx.xx.com/saml/login" with Policy I use "true".<br>
	when I make SAML IDP Profile use in the "Assertion Consumer Service Url: https://xxx.xx.com/cgi/samlauth" with policy I use "true" , and I try to bind to policy of the IDP on "Authentication Virtual Server" in the NetScaler with the IDP the binding not working and stay blank.
</p>

<p>
	but when I try to connect to the web I get : "ACS URL in request is invalid. Please contact your administrator" and if I do Refresh i get anther error: "Malformed Assertion sent to Netscaler; Please contact your administrator"  I didn't understand why I get this message.
</p>

<p>
	I try to change policy and noting work. 
</p>

<p>
	I have version : 13.1 24.38.nc
</p>
]]></description><guid isPermaLink="false">249461</guid><pubDate>Mon, 18 Jul 2022 10:41:03 +0000</pubDate></item><item><title>Netscaler AAA vserver for ReCaptcha giving Error 403 Forbidden</title><link>https://community.stage.citrix.com/forums/topic/256549-netscaler-aaa-vserver-for-recaptcha-giving-error-403-forbidden/</link><description><![CDATA[<p>Hi</p><p>I'm working on a NetScaler Google ReCAPTCHA deployment. I got this working with a VPX running NS14.1 <a rel="external nofollow" href="https://34.42.nc">34.42.nc</a> and tried to transfer this configuration onto the production MPX 8900 HA pair (also running NS14.1 <a rel="external nofollow" href="https://34.42.nc">34.42.nc</a>).</p><p>When the authentication virtual server tries to load on the MPX, the browser is redirected to <strong>https://&lt;VSERVER&gt;/logon/LogonPoint/index.html </strong>which results in:</p><p><strong>Error 403 Forbidden You don't have permission to access this resource.</strong></p><p>With the same setup on the VPX the browser is redirected to<strong> https://&lt;VSERVER&gt;/logon/LogonPoint/tmindex.html</strong></p><p>Copying themes across from the VPX to MPX (following the CTX209526 article) made no difference.</p><p>The "<strong>/var/netscaler/logon</strong>" directory is already present on the MPX - I've seen some threads that suggest copying this folder from a working node to a one that is having issues. Can anyone advise on this please and whether this requires a reboot on the destination node?</p><p>Thanks</p><p>Andy</p>]]></description><guid isPermaLink="false">256549</guid><pubDate>Wed, 04 Jun 2025 08:30:35 +0000</pubDate></item><item><title>NetScaler-Build 14.1-47.46 breaks SAML-authentication for ShareFile</title><link>https://community.stage.citrix.com/forums/topic/256627-netscaler-build-141-4746-breaks-saml-authentication-for-sharefile/</link><description><![CDATA[<p>One of my customers tried to address CVE-2025-5349 &amp; CVE-2025-5777 last week.</p><p>Once upgraded to 14.1-47.46, both Gateway-vServers (XenMobile &amp; CVAD/HDX-Proxy) and also the WAF-features continued to work fine. Unfortunately, SAML-authentication (LDAP) for ShareFile stopped working:</p><p><img class="ipsImage ipsRichText__align--block" data-fileid="38764" src="//media.invisioncic.com/r328636/monthly_2025_06/image.png.2ad7288a574eee33dd882fdf3587327a.png" alt="image.png" width="929" height="236" loading="lazy"></p><p>As workaround, we identified 14.1-43.56... As it didn't suffer from that issue.</p><p>Today, CVE-2025-6543 was published, but no new 14.1-build was released :-\</p>]]></description><guid isPermaLink="false">256627</guid><pubDate>Wed, 25 Jun 2025 14:26:43 +0000</pubDate></item></channel></rss>
