PoPs for commercial regions
For HDX™ traffic, we recommend the following configuration:
-
*.nssvc.net(including all sub-domains)
If you have not enabled all the sub-domains, we recommend the following configurations (less preferred):
-
*.c.nssvc.net -
*.g.nssvc.net
This wildcard applies to all existing and new PoP FQDNs. Customers who use wildcard-based allowlisting are not required to add the individual FQDNs.
Note:
It is recommended to configure firewalls and Secure Web Gateways as mentioned in System and Connectivity Requirements.
If DNS forwarders are configured to allow recursive DNS resolution for specific domains, you must include
*.akadns.netin the allowed list. This configuration enables the Citrix Cloud Connector, Citrix Virtual Apps and Desktops, or client to connect to the Citrix Gateway service.
Global FQDNs with defined set of PoPs
| Type | FQDN | Purpose |
|---|---|---|
| Global
|
|
Global FQDN
|
| Global |
|
Global FQDN including service continuity feature |
| Global | reg.c.nssvc.net | Connectors/VDA to register to Citrix Cloud |
| Azure only | azure-reg.c.nssvc.net | Connectors in Azure to register to Citrix Cloud |
PoP FQDNs
The following table lists the Citrix Gateway service FQDNs associated with each Point of Presence (PoP):
Resource-side PoP FQDN (Cloud Connector or VDA): Used for connections to the Citrix Gateway service that originate from the resource side. Based on the configured connection path, the connection might originate from either a Citrix Cloud Connector or a Virtual Delivery Agent (VDA).
Important:
Customers who already allow list
*.nssvc.net, the more specific*.g.nssvc.netand*.c.nssvc.netdomains, or the published Citrix Gateway service FQDNs, do not need to allow each PoP FQDN individually.If your environment restricts Citrix Gateway service connectivity by IP address, review your current configuration against the published connectivity requirements. Citrix recommends using FQDN‑based rules, because the destination IP addresses for the Citrix Gateway service can change.
| PoP code | Resource-side PoP FQDN (Cloud Connector or VDA) | Cloud service provider | Country | Location |
|---|---|---|---|---|
| az-in-c | az-in-c-rdvz.g.nssvc.net | Azure | India | Pune |
| az-eu-c | az-eu-c-rdvz.g.nssvc.net | Azure | Germany | Frankfurt |
| az-us-c | az-us-c-rdvz.g.nssvc.net | Azure | USA | Iowa |
| az-asia-hk | az-asia-hk-rdvz.g.nssvc.net | Azure | Hong Kong | Hong Kong |
| az-asia-se | az-asia-se-rdvz.g.nssvc.net | Azure | Singapore | Singapore |
| az-aus-e | az-aus-e-rdvz.g.nssvc.net | Azure | Australia | New South Wales |
| az-bz-s | az-bz-s-rdvz.g.nssvc.net | Azure | Brazil | Sao Paulo |
| az-ca-c | az-ca-c-rdvz.g.nssvc.net | Azure | Canada | Toronto |
| az-eu-n | az-eu-n-rdvz.g.nssvc.net | Azure | Ireland | Dublin |
| az-eu-w | az-eu-w-rdvz.g.nssvc.net | Azure | Netherlands | Amsterdam |
| az-in-s | az-in-s-rdvz.g.nssvc.net | Azure | India | Chennai |
| az-jp-e | az-jp-e-rdvz.g.nssvc.net | Azure | Japan | Tokyo |
| az-nw-e | az-nw-e-rdvz.g.nssvc.net | Azure | Norway | Oslo |
| az-uae-n | az-uae-n-rdvz.g.nssvc.net | Azure | UAE | Dubai |
| az-us-e | az-us-e-rdvz.g.nssvc.net | Azure | USA | Virginia |
| az-us-e2 | az-us-e2-rdvz.g.nssvc.net | Azure | USA | Virginia |
| az-us-sc | az-us-sc-rdvz.g.nssvc.net | Azure | USA | Texas |
| az-us-w | az-us-w-rdvz.g.nssvc.net | Azure | USA | California |
| az-za-n | az-za-n-rdvz.g.nssvc.net | Azure | South Africa | Johannesburg |
| aws-eu-s | aws-eu-s-rdvz.g.nssvc.net | AWS | Italy | Milan |
| aws-aus-e | aws-aus-e-rdvz.g.nssvc.net | AWS | Australia | Sydney |
| aws-asia-se | aws-asia-se-rdvz.g.nssvc.net | AWS | Singapore | Singapore |
| aws-asia-tw | aws-asia-tw-rdvz.g.nssvc.net | AWS | Taiwan | Taipei |
| aws-bz-s | aws-bz-s-rdvz.g.nssvc.net | AWS | Brazil | Sao Paulo |
| aws-ca-e | aws-ca-e-rdvz.g.nssvc.net | AWS | Canada | Montreal |
| aws-eu-c | aws-eu-c-rdvz.g.nssvc.net | AWS | Germany | Frankfurt |
| aws-eu-w | aws-eu-w-rdvz.g.nssvc.net | AWS | France | Paris |
| aws-in-sc | aws-in-sc-rdvz.g.nssvc.net | AWS | India | Hyderabad |
| aws-in-w | aws-in-w-rdvz.g.nssvc.net | AWS | India | Mumbai |
| aws-jp-w | aws-jp-w-rdvz.g.nssvc.net | AWS | Japan | Osaka |
| aws-uk-se | aws-uk-se-rdvz.g.nssvc.net | AWS | UK | London |
| aws-us-e | aws-us-e-rdvz.g.nssvc.net | AWS | USA | North Virginia |
| aws-us-nc | aws-us-nc-rdvz.g.nssvc.net | AWS | USA | Ohio |
| aws-us-w | aws-us-w-rdvz.g.nssvc.net | AWS | USA | North California |
Regional FQDNs for geo-location routing
Notes:
Each geo-location has two FQDNS:
The FQDN ending with
rgn.g.nssvc.netis the general FQDN.The FQDN ending with
rgn-s.g.nssvc.netis the FQDN that includes the service continuity feature.Geo-location routing FQDNs do not require additional allow list entries during enhanced upgrades, as they automatically resolve to the active PoP infrastructure.
| Geo-location | FQDNs | PoPs included |
|---|---|---|
| United States - East
|
|
az-us-e, aws-us-e, aws-us-nc, az-us-e2
|
| United States - Central and West
|
|
az-us-w, aws-us-w, az-us-sc
|
| United States
|
|
az-us-sc, az-us-e, az-us-w, az-us-e2, aws-us-e, aws-us-w, aws-us-nc
|
| United States - Azure only
|
|
az-us-e, az-us-w, az-us-sc, az-us-e2
|
| Europe
|
|
aws-eu-c, aws-eu-w, az-eu-w, az-eu-n
|
| Australia
|
|
az-aus-e, aws-aus-e
|
| Global - Azure only
|
|
az-us-e, az-us-w, az-us-sc, az-bz-s, az-eu-w, az-eu-n, az-aus-e, az-asia-se, az-jp-e, az-in-s, az-uae-n, az-za-n, az-asia-hk, az-ca-c, az-us-e2, az-nw-e
|
| Asia
|
|
az-uae-n, aws-in-w, az-in-s, az-asia-se, az-jp-e, aws-in-sc, aws-asia-tw, aws-asia-se, aws-jp-w
|
| India
|
|
aws-in-w, aws-in-sc, az-in-s
|
| Global - Alternate
|
|
az-asia-se, az-aus-e, az-bz-s, az-ca-c, az-eu-n, az-eu-w, az-in-s, az-jp-e, az-nw-e, az-uae-n, az-us-e, az-us-sc, az-us-w, az-za-n, aws-aus-e, aws-bz-s, aws-ca-e, aws-eu-c, aws-in-w, aws-uk-se, aws-us-e, aws-us-nc, aws-us-w, az-us-e2, aws-asia-se, aws-eu-w, aws-in-sc, aws-jp-w
|