Bril licenses Posted April 6, 2023 Share Posted April 6, 2023 If i connect to the NS portal and launch an App with workspace, the connections are proxied by NS as it is expected to. however, if I configure the Workspace App and launch the Virtual Apps from the Workspace later the ICA connections are not proxied by NS. instead the client establishes a direct connection with storefront and XenApp servers on port . this info can be verified from the Citrix Workspace connection center as well from Wireshark. take a look at the attached file which shows difference in the connection properties. 1) when the app is launched after connected to the portal from a browser 2)when the app is launched directly from the start menu or from Workspace app one its is configured. in both cases I am using workspace app. Another interesting fact is that once I disable all the communication in firewall and only allow 443 to the NS gateway, it works as expected Link to comment
0 CarlStalhood Posted April 6, 2023 Share Posted April 6, 2023 What Internal Beacon is configured in StoreFront Console? If you want Workspace app to use Gateway, then make sure the Internal Beacon is not reachable by the Workspace app client. Link to comment
0 Bril licenses Posted April 6, 2023 Author Share Posted April 6, 2023 Hi Carl, thanks you dear for the quick response. the internal beacon is the storefront URL and it reachable from the clients. does this also explain the reason that when i use the Workspace App to connect to Gateway URL it asks for Authentication twice. once for the NS and one for the SF. What is the impact of me not having anything in internal beacon? Link to comment
0 CarlStalhood Posted April 6, 2023 Share Posted April 6, 2023 You can set it to a fake address to force Workspace app users to use the Gateway. Link to comment
0 Bril licenses Posted April 15, 2023 Author Share Posted April 15, 2023 thanks Carl.. if you have any docs on SF internal Beacons and external beacons kindly share. Link to comment
0 CarlStalhood Posted April 15, 2023 Share Posted April 15, 2023 In StoreFront console, on the top right click Manage Beacons. If the Internal Beacon is not reachable, then Workspace app will go to the Citrix Gateway instead of directly to StoreFront. Link to comment
Question
Bril licenses
If i connect to the NS portal and launch an App with workspace, the connections are proxied by NS as it is expected to.
however, if I configure the Workspace App and launch the Virtual Apps from the Workspace later the ICA connections are not proxied by NS.
instead the client establishes a direct connection with storefront and XenApp servers on port .
this info can be verified from the Citrix Workspace connection center as well from Wireshark.
take a look at the attached file which shows difference in the connection properties.
1) when the app is launched after connected to the portal from a browser
2)when the app is launched directly from the start menu or from Workspace app one its is configured.
in both cases I am using workspace app.
Another interesting fact is that once I disable all the communication in firewall and only allow 443 to the NS gateway, it works as expected
Link to comment
5 answers to this question
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now