Citrix DaaS

Connection to XenServer

Create and manage connections and resources provides detailed instructions using the wizard to create a connection. Before establishing a connection to XenServer (formerly Citrix Hypervisor), you need to first finish setting up your XenServer as a host. See Add a resource type or activate an unused domain in Citrix Cloud.

Create a connection to XenServer

When you create a connection to XenServer, you must provide the credentials for a Virtual Machine Power Administrator (VM Power Admin) or higher-level user.

Citrix recommends using HTTPS to secure communications with XenServer. To use HTTPS, you must replace the default TLS certificate installed on XenServer. For more information, see Install a TLS certificate on your server.

You can configure high availability if it is enabled on the XenServer server. Citrix recommends that you select all servers in the pool (from Edit High Availability) to allow communication with the XenServer server if the pool master fails.

Note:

If you are using HTTPS and want to configure high-availability servers, do not install a wildcard certificate for all servers in a pool. An individual certificate for each server is required.

When using local storage on one or more XenServer hosts for temporary data storage, make sure that each storage location in the pool has a unique name. (To change a name in XenCenter, right-click the storage and edit the name property.)

If you connect to the XenServer that supports vGPU, you can verify the GPU group and the GPU type in the Summary page of the wizard for creating a connection.

Summary page of XenServer connection creation

Use IntelliCache for XenServer connections

Using IntelliCache, hosted VDI deployments are more cost-effective because you can use a combination of shared storage and local storage. This enhances performance and reduces network traffic. The local storage caches the master image from the shared storage, which reduces the amount of reads on the shared storage. For shared desktops, writes to the differencing disks are written to local storage on the host and not to shared storage.

The important considerations are:

  • Shared storage must be NFS when using IntelliCache.
  • Citrix recommends that you use a high-performance local storage device to ensure the fastest possible data transfer.

To use IntelliCache, enable IntelliCache as detailed:

  • When installing XenServer, select Enable thin provisioning. See Install the XenServer host for information on installing XenServer host from local media. Citrix does not support mixed pools of servers with some servers that have IntelliCache enabled and some servers that do not IntelliCache enabled.
  • In Citrix DaaS, IntelliCache is disabled by default. You can change the setting only when creating a XenServer connection. You cannot disable IntelliCache later. When you create a XenServer connection:
    • Select Shared as the storage type.
    • Select the Use IntelliCache checkbox.

See IntelliCache for more information.

Required XenServer permissions

The XenServer permissions are role-based (RBAC). The Role-Based Access Control (RBAC) feature in XenServer allows you to assign users, roles, and permissions to control who has access to your XenServer and what actions they can perform. The XenServer RBAC system maps a user (or a group of users) to defined roles (a named set of permissions). The roles have associated XenServer permissions to perform certain operations.

For more information, see Role-based access control.

The role hierarchy, in order of increasing permissions is: Read-Only → VM Operator → VM Admin → VM Power Admin → Pool Operator → Pool Admin.

The following section summarizes the minimum role required for each provisioning task.

Creating a host connection

Task Minimum role required
Add a host connection using the information obtained from XenServer Read-Only
View users and their assigned role Read-Only

Power management of VMs

Task Minimum role required
Power on or off the VMs VM Operator

Creating, updating, or deleting VMs

Task Minimum role required
Add or remove VMs to existing snapshots schedules VM Power Admin
Add, modify, delete snapshot schedules Pool Operator
Publish master image Pool Operator (Requires switch-port locking)
Create a machine catalog Pool Operator: Requires switch-port locking
Add or remove VMs (not GPU enabled VMs) VM Admin
Add or remove VMs (GPU enabled VMs) Pool Operator
Add, remove, or configure virtual disk or CD devices VM Admin
Manage Tags VM Operator

For more information on RBAC roles and permissions, see RBAC roles and permissions.

For information on switch port locking, see Use switch port locking.

Where to go next

More information

Connection to XenServer