Citrix DaaS™

Network telemetry

Network metrics are critical for Citrix session troubleshooting because the performance and stability of a Citrix session are heavily dependent on the underlying network conditions. Unlike a local application, a Citrix session involves streaming an interactive desktop or application experience over a network, meaning any network instability or bottleneck will directly impact the user’s perception of performance.

For details about the network metrics available in Citrix Monitor and Director, see Diagnose Session Performance issues.

System requirements

The following are the system requirements for using Network Telemetry:

  • Control plane
    • Citrix DaaS
    • Citrix Virtual Apps and Desktops 2503 or later
  • Virtual Delivery Agent (VDA)
    • Windows: version 2503 or later
    • Linux: version 2507 or later
    • Mac: version 2507 or later
  • Workspace app
    • Windows: version 2503 or later
    • Linux: version 2508 or later
    • Mac: version 2505 or later
  • Access tier
    • Citrix Workspace
    • Citrix Storefront 2402 or later
    • Citrix Gateway Service
    • Citrix NetScaler Gateway 14.1 Build 47.46 or later

Network requirements

If you are using Citrix Gateway Service, there are no additional network requirements. However, if you are using NetScaler Gateway, there are additional requirements to use Network Telemetry, which are outlined below.

Session hosts

If your session hosts have a firewall such as Windows Defender Firewall, you must allow the following inbound traffic for connections from NetScaler Gateway.

Description Source Protocol Port
Connection from Gateway NetScaler SNIP TCP 443

NOTE:

The VDA installer adds the appropriate inbound rules to Windows Defender Firewall. If you use a different firewall, you must add the rules above.

Internal network

The following are the firewall requirements for your internal network:

Description Protocol Source Source port Destination Destination port
Connection from Gateway TCP NetScalet SNIP 1024-65535 VDA network 443

Configuration

Network telemetry is disabled by default. You can configure this feature via Citrix policy in Studio using the following setting.

  • Network telemetry: defines whether to enable or disable the feature.

Considerations

The following are considerations for using Network Telemetry:

  • Currently, only TCP is supported; enabling Network Telemetry forces sessions to use TCP.
  • With Network Telemetry enabled, NetScaler Gateway connections to the VDA are encrypted at the network level. For certificate management details, see HDX Direct certificate management. Please note that this does not enable HDX Direct.
Network telemetry