Category: NetScaler
Notes from the field: Citrix NetScaler VLAN tagging and Hyper-V / VMM
Long story short if you want to use VLAN trunk tagging, Hyper-V itself will not let you see this in the GUI and this is only supported via CLI/Powershell and further down the road VMM will allow this in an compute fabric for GEN2 only! (and NetScaler is still GEN1) see https://charbelnemnom.com/what-is-vlan-trunk-mode-in-hyper-v-hyperv/ and https://learn.microsoft.com/en-us/system-center/vmm/vm-settings?view=sc-vmm-2025&tabs=AddvNIC%2CConfigureQoS%2CProcessorThrottling#support-for-trunk-mode After…
Notes from the field: Citrix NetScaler “VPX” hard drive errors
In a particular case with one of our customers we encountered the reporting messages “Hard disk drive errors” in our logging and checked the solution with the customer, at first all seemed to be alright and no issues but this particular node would keep giving the event entries. From article https://support.citrix.com/s/article/CTX214458-netscaler-vpx-hard-drive-errors?language=en_US all indicates that the…
Notes from the field: Citrix NetScaler Native OTP stopped working
In a recente P1 outage at a customer we got messages that some users would not be able to logon and some would, authentication debugging would show cascading events that would work and some that would deny logons. In this particular setup there are two MFA solutions, one not native to the NetScaler and one…
Notes from the field: Citrix NetScaler and the authentication policy limit
For a customer who is using the NetScaler as a IDP/SP service with the NetScaler Gateway and some service provider requirements we had a nice policy limitations which caught us by surprise: https://support.citrix.com/s/article/CTX227301-error-32-authentication-policies-are-already-bound-while-binding-authentication-policy?language=en_US#:~:text=When%20multiple%20policies%20(two%2Dfactor,binding%20for%20one%20virtual%20server. The mentioned RFE is still in the works or forgotten but to solve this little puzzle you’ll need to go to the…
Notes from the field: Citrix NetScaler Admin Partitions Cleanup
In a previous blogpost we’ve discussed some pain points regarding a whole bunch of admin partitions and the inability to upgrade regarding disk space usage, see it here: https://www.technicalfellow.com/2023/12/notes-from-the-field-citrix-netscaler-partitions-performance-and-pain/ After a support case and discussions about when to use the reporting feature of the NetScaler or not, we needed a solution to clean all those…
Notes from the field: Citrix NetScaler, partitions, performance, and pain
On a recent joint project with my partner in crime Anton van Pelt there was a long outstanding support issue which needed our dedicated attention. Long story short we have a customer in a nice new greenfield which got migrated from F5 to NetScaler and the introduction of Citrix Gateway and migrated the backend to…
Notes from the field: Citrix Gateway DTLS fail-over UDP/TCP
On a recent troubleshoot a customer complained that after a failover all ICA sessions would do a fallback to TCP and not uplift again to UDP until the DTLS checkmark would be disabled/enabled Well this worked in the past but since 13.0 build 58.x we have the ability to create a DTLS listener VIP for…
Notes from the field: Microsoft Azure MFA Number Matching and the one with NPS extension
Regarding the upcoming change of Microsoft MFA number matching, some customers started to ask me hey what’s going on? Do we need to do something? Is there any impact for our users? Well, the short answer is yes. The long answer is well it depends, can we live with the current setup or is there…
Notes from the field: Citrix NetScaler Azure subscription-based licensing
Just a quick blog regarding a deployment model of Citrix NetScaler on Azure. There is an option to use subscription-based licensing for a deployment, meaning you pay by the hour it is running in Azure. See Deploy a Citrix ADC VPX instance on Microsoft Azure for more details. This setup was chosen by a customer…
Notes from the field: The Kerberos chronicles, the one with Citrix NetScaler
The same as my previous Kerberos blog but this time we have Citrix NetScaler in the mix with drumrolls… Kerberos Constrained Delegation henceforth to be known as KCD. This in an setup derived from the following article: Tutorial: Azure Active Directory single sign-on integration with Citrix ADC SAML Connector for Azure AD (Kerberos-based authentication) –…