Citrix Cloud Gcp



This repository contains scripts and templates to simplify deployment of the resources described in Citrix's Deploying Citrix Cloud XenApp and XenDesktop Service on the Google Cloud Platform published December 2017. A new cloud service, Citrix Access Control, provides single sign-on as well as additional security and controls for G Suite. By using this Citrix service, IT can control the actions users may take while accessing documents on Google Drive such as watermarking, clipboard access, and printing. The Citrix Virtual Apps and Desktops Service service (CVADS) now supports zone selection on Google Cloud Platform (GCP) to enable sole-tenant node functionality. You specify the zones where you want to create VMs in Citrix Studio. To deploy Citrix ADC CPX as an Ingress in a standalone deployment model in GCP, you should use the Service Type as LoadBalancer. This step creates a load balancer in the Google cloud. Deploy a Citrix ADC CPX ingress with in built Citrix ingress controller in your Kubernetes cluster using the following command. Learn how to deploy ADC instances from the Google Cloud MarketplaceProvisioning Citrix ADC on Google Cloud Marketplace is an activity designed to be done in.

In this post I wanted to discuss the use of Citrix Enlighted Data Transport with Citrix Gateway Service. This is a feature that has been available with Citrix ADC for quite some time but it is a new feature for Gateway Service. I wanted to take you through step by step on how to configure EDT and Adaptive Transport with Gateway Service, as well as discuss any system requirements that are needed to get you up and running.

What is Adaptive Transport

Adaptive transport is a proprietary transport protocol that functions well on highly latent networks, which TCP alone finds challenging. This protocol is adaptive and can switch to TCP or UDP based on network conditions in order to ensure the best user experience for users using HDX.

Enlighted Data Transport System requirements

  • VDA 1912 or later
  • Rendezvous protocol must be enabled and working ( We cover this next)
  • Ports UDP 443 and TCP must be open outbound from VDA to the Internet
  • Adaptive Transport must be enabled
  • EDT is supported with all supported OS’s. Citrix do recommend the use of Windows 10 and Windows 2019 when running EDT with Citrix Gateway Service
  • Latest Workspace App Version ( 1908 or above for Parallel connections)

Configuring Rendezvous Protocol

When you are configuring Rendezvous protocol for use with Citrix CVAD Service the following is required.

  • VDA 1912 or later
  • Enable the Rendezvous protocol in the Citrix policies in Studio
  • The Cloud Connectors must obtain the VDA’s FQDN when brokering a session. This can be achieved by using the the following commands in Powershell:
    • asnp citrix*
    • Get- XDAuthentication

Citrix Cloud Capital One

Set the DNS Resolution to True

Set-Brokersite -DNSResolutionEnabled $True

Citrix Cloud Gcp

To check that the DNS Settings are configured correctly – Type Get-Brokersite

Citrix Cloud Gcps

The DNS Resolution should now be set to True.

Citrix Policy Requirements

Now that the DNS settings are complete, we need to ensure the Citrix Policies are also set for Rendezvous protocol. (The Rendezvous protocol allows HDX sessions to bypass the Citrix Cloud Connector and connect directly and securely to the Citrix Gateway service.)

Please see more detail here: https://docs.citrix.com/en-us/citrix-virtual-apps-desktops-service/hdx/rendezvous-protocol.html

Citrix

Citrix Cloud Control

To set the Citrix policy, Open Citrix Studio and create a new policy for Rendezvous protocol.

Click enable , and also enable Adaptive transport.

Lets also set up Session Reliability setting, as our final policy requirement. Enabling Session Reliability will allow users to automatically reconnect to Citrix sessions after a disruption.

Now that Rendezvous protocol is setup, lets move on to complete the setup to allow for the use of EDT.

Open Microsoft Group Policy Manager, and create a policy that will allow for you to set the Cipher Suite for the VDA workloads. Choose Computer configuration, Network, SSL Configuration, SSL Cipher Suite Order.

Lets now check if the settings are working as expected

Within the HDX session, launch a desktop and open powershell

The transport protocols used are displayed as below when successfully using EDT

Citrix Cloud Cost

It is also possible to check via Director