Recommendations for Client Connections to Cloud Gateway Service Behind a VPN or Proxy

book

Article ID: CTX696881

calendar_today

Updated On:

Description

Overview

Citrix Workspace app communicates directly with a Citrix Gateway Service Point of Presence (PoP) throughout the user's HDX session. This connection is encrypted and is designed to remain unchanged between the client and Citrix Gateway Service. Security devices that decrypt, inspect, or modify this traffic can interfere with normal connection establishment or transport selection.

 


 

Recommended Configuration

For the best compatibility and performance, Citrix recommends the following:

  • Allow clients to communicate directly with Citrix Gateway Service
  • Bypass TLS/SSL inspection and decryption for Gateway Service traffic
  • Do not modify or rewrite encrypted traffic
  • Allow normal DNS resolution
  • Preserve UDP connectivity when EDT is desired
  • TLS / SSL Inspection

TLS or SSL inspection devices terminate encrypted connections, inspect the traffic, and establish a new encrypted connection on behalf of the client.

This process may:

  • Prevent successful session establishment
  • Prevent EDT from being established
  • Introduce additional latency
  • Cause intermittent connection or performance issues

 

Recommendation

Configure VPNs, Secure Web Gateways (SWGs), proxy appliances, and TLS inspection devices to bypass inspection for Citrix Gateway Service traffic whenever possible.

 


 

DNS

Workspace app relies on DNS to locate an appropriate Citrix Gateway Service Point of Presence (PoP), by supplying the geographical coordinates to the Global-all.g.nssvc.net Intelligent Traffic Manager (ITM). DNS responses should not be modified or redirected by intermediary network devices, without knowing the consequences of doing so. If appending client subnets, or redirecting the DNS resolutions of the Global-all.g.nssvc.net traffic manager, the determined PoP may be suboptimal for the users real location.

 

Recommendation

  • Allow standard DNS resolution
  • Do not replace Citrix Gateway Service addresses with internal proxy or gateway addresses
  • Avoid static DNS mappings unless directed by Citrix Support for testing purposes only

 


 

VPN Recommendations

VPN solutions should provide network connectivity without modifying Gateway Service traffic.

 

Recommended configuration:

  • Allow outbound TLS and UDP traffic
  • Do not decrypt Gateway Service traffic
  • Do not perform application-layer inspection
  • Avoid redirecting traffic through additional inspection devices

 


 

Proxy Recommendations

When Workspace app is configured to use an explicit proxy, the proxy should allow Gateway Service traffic to pass without inspection or decryption. If Adaptive Transport (EDT/UDP) is enabled, Workspace app attempts to establish the UDP-based EDT connection first.

Only SOCKS5 proxies support proxying EDT traffic. If the proxy does not support SOCKS5 for UDP traffic, the EDT connection cannot be established and Workspace app will automatically fall back to TCP. This fallback is expected behavior, although TCP may provide lower performance than EDT in some network conditions.

 


 

Deep Packet Inspection (DPI)

Some firewalls, Secure Web Gateways, and security appliances perform additional inspection beyond TLS decryption.

Examples include:

  • Deep Packet Inspection (DPI)
  • Protocol normalization
  • Traffic optimization
  • Application-aware inspection

These features may alter or delay Gateway Service traffic.

 

Recommendation

Where possible, configure these features to bypass Citrix Gateway Service traffic.



Issue/Introduction

When Citrix Workspace app connects through Citrix Gateway Service, the client establishes a secure connection to a Citrix Gateway Service Point of Presence (PoP). Corporate VPNs, secure web gateways, proxies, and other intermediary network devices may inspect or modify this traffic. While these devices can coexist with Citrix Gateway Service, certain network configurations may prevent EDT from establishing, force fallback to TCP, or introduce connection and performance issues.

This article outlines the recommended network configuration for client connections that traverse VPNs or proxy infrastructure.

 

Recommendation Quick Glance

 

Component Recommendation
TLS / SSL Inspection Bypass
HTTPS Inspection Bypass
DNS Allow normal resolution
VPN Route traffic without modification
Proxy Do not inspect Gateway Service traffic
EDT through Explicit Proxy SOCKS5 support required
Deep Packet Inspection Bypass

Additional Information

Supporting Documentation

 

Additional References for Citrix Traffic