In the last part we looked at SSL certificates and load balancing StoreFront servers. In this post, we’ll go over configuring NetScaler Gateway to work with a load balanced StoreFront configuration.

Configuring NetScaler Gateway for StoreFront

In conjunction with the configuration in the NetScaler appliance, you will need to ensure in the StoreFront console that:

  • The authentication method “Pass-through from NetScaler Gateway” is configured and enabled
  • The NetScaler Gateway appliance has been added and configured (with STA servers) in the NetScaler Gateway node.
  • Remote Access has been configured as No VPN tunnel for the StoreFront store and to use the NetScaler Gateway appliance.

Also, like in the load balancing example from part 3 of this blog series, you’ll need an SSL certificate configured as a certificate and key pair. This cert/key pair is bound to the NetScaler Gateway virtual server as seen in the example below.

Creating a new NetScaler Gateway configuration for StoreFront
(New-NSGatewaySFConfiguration.ps1 example)

To create a gateway configuration that connects to StoreFront, you would normally go over the following steps:

  • Enable features
  • Create LDAP authentication action
  • Create LDAP authentication policy
  • Create VPN virtual server
  • Bind LDAP authentication policy to VPN virtual server
  • Create VPN action policies for StoreFront
  • Create VPN session policies for StoreFront
  • Bind VPN session policies to VPN virtual server
  • Bind SSL certificate and key to VPN virtual server

This is how we would call the example script which consumes new functions in the example NetScaler Configuration module:

New-NSGatewaySFConfiguration.ps1 -NSAddress "" -LDAPServerIP "" -LDAPBindDN "" -LDAPBindDNPassword "p4ssw0rd" -VirtualServerName "" -VirtualServerIPAddress "" -StoreFrontServerURL "" -STAServerURL "","" -SingleSignOnDomain "" -ReceiverForWebPath "/Citrix/MyStoreWeb" -CertKeyName "" -NetScalerConfigurationPSModuleLocation "C:\NetScalerConfigurationPart4"

Keep in mind that the values for the parameters in all of the example calls must be modified to fit your configuration.

Get the example PowerShell Module and scripts (Part 4)

Santiago Cardenas

Citrix Solutions Lab


This software / sample code is provided to you “AS IS” with no representations, warranties or conditions of any kind. You may use, modify and distribute it at your own risk. CITRIX DISCLAIMS ALL WARRANTIES WHATSOEVER, EXPRESS, IMPLIED, WRITTEN, ORAL OR STATUTORY, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT. Without limiting the generality of the foregoing, you acknowledge and agree that (a) the software / sample code may exhibit errors, design flaws or other problems, possibly resulting in loss of data or damage to property; (b) it may not be possible to make the software / sample code fully functional; and (c) Citrix may, without notice or liability to you, cease to make available the current version and/or any future versions of the software / sample code. In no event should the software / code be used to support of ultra-hazardous activities, including but not limited to life support or blasting activities. NEITHER CITRIX NOR ITS AFFILIATES OR AGENTS WILL BE LIABLE, UNDER BREACH OF CONTRACT OR ANY OTHER THEORY OF LIABILITY, FOR ANY DAMAGES WHATSOEVER ARISING FROM USE OF THE SOFTWARE / SAMPLE CODE, INCLUDING WITHOUT LIMITATION DIRECT, SPECIAL, INCIDENTAL, PUNITIVE, CONSEQUENTIAL OR OTHER DAMAGES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. You agree to indemnify and defend Citrix against any and all claims arising from your use, modification or distribution of the code.