-
-
WebSocket communication between VDA and Delivery Controller™
-
-
-
-
-
-
-
-
Government Cloud prerequisites for VDA upgrades (VUS)
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Government Cloud prerequisites for VDA upgrades (VUS)
This article documents customer-side prerequisites for upgrading VDAs through the VDA Upgrade Service (VUS) in the Production Government environment.
Use this guidance when outbound firewall or proxy controls are enforced and egress is restricted.
Pre-requisites
These prerequisites apply to Government customers who use VUS to upgrade persistent VDAs and need to allow required outbound connections for package download, schedule retrieval, and version reporting.
This guidance is in addition to the standard VUS prerequisites in Prerequisites for upgrading VDAs using VUS.
Required outbound endpoint access
Allow outbound HTTPS (TCP 443) from the following sources:
- VDAs that run the VDA Upgrade Agent.
- Cloud Connectors, when traffic is connector-routed.
Allow-list the following destination patterns:
- Prod Government VUS release CDN endpoint pattern: https://prod-us-gov-vus-release-endpoint-.z01.azurefd.us/prod-us-gov-vus-release-container/
- Per-customer Government DDC REST endpoint pattern: https://[customerId].xendesktop.us/citrix/vdaupdateservice/*
Why these endpoints are required
| Endpoint pattern | Purpose | Used by |
|---|---|---|
| https://prod-us-gov-vus-release-endpoint-.z01.azurefd.us/prod-us-gov-vus-release-container/ | Downloads VDA installer packages for scheduled upgrades. | VDA Upgrade Agent download flow |
| https://[customerId].xendesktop.us/citrix/vdaupdateservice/* | Gets VUS schedules and posts VDA version report calls. | VDA Upgrade Agent control plane calls |
If either endpoint is blocked by firewall, proxy, SSL inspection policy, or DNS filtering, upgrades can fail.
Government storage and KeyVault pre-requisites
Government storage account and KeyVault resources used by the VUS release pipeline are managed on the service side.
Customer action is typically limited to network egress policy configuration for VDAs and Cloud Connectors. If your organization applies additional outbound controls or private routing constraints, coordinate validation with your Citrix support and security teams before scheduling production upgrades.
FedRAMP boundary considerations
- Review your FedRAMP boundary controls for outbound HTTPS to Azure Government Front Door endpoints (*.azurefd.us) and customer-specific xendesktop.us endpoints.
- Document approved destination patterns and control rationale in your SSP and change records.
- If TLS inspection is mandatory, validate that certificate handling does not break VDA installer download or API communication.
Pre-upgrade verification checklist
- Confirm DNS resolution and TCP 443 reachability from each VDA subnet to the required *.azurefd.us endpoint.
- Confirm DNS resolution and TCP 443 reachability from each VDA subnet to https://[customerId].xendesktop.us.
- Confirm the same reachability from Cloud Connectors for connector-routed traffic paths.
- Run a pilot VUS upgrade on a small machine set and verify package download and version report success.
Share
Share
This Preview product documentation is Citrix Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Citrix Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Citrix product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.