A Different Approach to a Single FQDN for StoreFront and NetScaler Gateway
How can users be educated to use a single URL, while still having a StoreFront base URL that is different from the NetScaler Gateway URL? We’re going to show you.
Please keep in mind this solution works best for Receiver for Web. This solution does work with the Native Receiver, but the Provisioning file would be the easiest way to configure the Native Receiver in my opinion.
In this scenario, I will use connect.example.com for external access to the Citrix environment. Int-connect.example.com will be used for internal access to the Citrix environment.
Here is an overview of the requirements for the scenario:
- SAN certificate for int-connect.example.com and connect.example.com.
- Connect.example.com will resolve to the publicly accessible NetScaler Gateway VIPs.
- Int-connect.example.com will resolve to the internal StoreFront Load Balanced VIPs.
- CNAME on the internal DNS. connect.example.com –> int-connect.example.com.
- Responder Policy to redirect from connect.example.com to int-connect.example.com.
Now for the magic of creating the single FQDN that users need to know.
In this example, the “single URL” for users is connect.example.com. On the internal DNS infrastructure, create a CNAME for connect.example.com to point to int-connect.example.com. Then, on the NetScaler appliance, create a Responder Policy that redirects traffic with the HTTP Host header of “connect.example.com” to “int-connect.example.com”. Bind this policy to the StoreFront LB VIP on NetScaler.
So, what is the expected user behavior?
A user on the internal network types connect.example.com into their browser. Connect.example.com resolves as a CNAME for int-connect.example.com. The user will resolve int-connect.example.com. After obtaining the IP address for int-connect.example.com, the user connects to the SF LB VIP using the IP address and the HTTP host header connect.example.com. The Responder policy redirects the user to int-connect.example.com. The user’s browser follows the redirect and is able to access the StoreFront LB VIP. By using a SAN certificate with the names we need, the user will not receive a certificate warning.