Citrix XenApp / vApps

  • 3 June 2023
  • 8 replies
  • 232 views

Badge +12
  • Explorer III
  • 43 replies

Hi There, 

 

What is the recommended deployment method for Citrix XenApp / vApps where multiple users log onto the same server concurrently. (Multiple users sharing same IP)


8 replies

Userlevel 2
Badge +15

Deploying the NSclient in multi-user mode will solve this but need more information on your environment. Are these servers AD-joined? Are the users connecting to them AD users?

Badge +12

Hi Ryans, XenApp servers are AD joined and users connecting to them are domain users. These servers do not move and hosted in the datacenter/Corp network. They might be some instances where local admin account is used for management tasks. 

 

Our ideal design is to have multiuser mode NSclient installed in XenApp but only serve identity for GRE tunnel. This approach provides us to quickly fallback in case of any netskope outages. 

 

Unfortunately in this GRE mode, skopeit shows all events under last logged in user. Thoughts/Suggestions? 

Userlevel 2
Badge +15

The Netskope client, by default, will fail open and stand down if a GRE tunnel is detected. This shouldn't be problematic as long as your client configuration is set to continue sending device classification and user alert data to the endpoint. This setting is under Client Configuration > Advanced. Give that a shot.

 

 

Badge +12

Unfortunately in this GRE mode, skopeit shows all events under last logged in user.

Userlevel 2
Badge +15

@Siva - I understand that. Do you have the configuration on the client configuration in place like I posted previously? You need to make sure that your client was installed onto the Citrix XenApp servers with mode=peruserconfig. If you didn't do that, you'll need to remove and reinstall the agent to switch to multi-user mode.

Refer to Netskope Client for Windows for installation parameters.

 

Badge +12

Hi @ryans, NSClient was installed with peruserconfig on XenApp and Client config has the checkbox checked as per your screencap. Thoughts? 

Userlevel 2
Badge +15

@Siva - if the users are not logging off before another user logs on, then this is a limitation we are working to address. What org are you with? I can add you to the internal enhancement tracker. 

Badge +12

Hi @ryans , send the requested info via private message. Thanks for your help, anything you could do to get this on enhancement list would be great. 

Reply