NetScaler Gateway plug-in Upgrade Control
System Administrators control how the NetScaler plug-in performs when its version does not match the NetScaler Gateway revision. The new options control the plug-in upgrade behavior for Mac, and Windows or operating systems.
For VPN plug-ins, the upgrade option can be set in two places in the NetScaler user interface:
- At the Global Settings
- At the Session Profile level
For each client type, NetScaler Gateway allows the following three options to control plug-in upgrade behavior:
The plug-in always gets upgraded whenever the end user’s plug-in version doesn’t match with the plug-in shipped with NetScaler. This is the default behavior. Choose this option if you don’t want multiple plug-in versions running in your enterprise.
- Essential (and security)
The plug-in only upgraded when it is deemed necessary. Upgrades are deemed necessary in the following two circumstances
Installed Plug-in is incompatible with the current NetScaler version.
Installed Plug-in must be updated for the necessary security fix.
Choose this option if you want to minimize the number of plug-in upgrades, but don’t want to miss any plug-in security updates
The plug-in does not get upgraded.
CLI Parameters for Controlling VPN Plug-in Upgrade
NetScaler Gateway supports two types of plug-ins (EPA and VPN) for Windows and Mac operating systems. To support VPN plug-in upgrade control at the session level, NetScaler Gateway supports two session profile parameters named WindowsinPluginUpgrade and MacPluginUpgrade.
These parameters are available at global, virtual server, group, and user level. Each parameter can have a value of Always, Essential or Never. For a description of these parameters see Plug-in Behaviors.
CLI Parameters for Controlling EPA Plug-in Upgrade
NetScaler Gateway supports EPA plug-ins for Windows and Mac operating systems. To support EPA plug-in upgrade control at the virtual server level, NetScaler Gateway supports two virtual server parameters named windowsEPAPluginUpgrade and macEPAPluginUpgrade.
The parameters are available at the virtual server level. Each parameter can have a value of Always, Essential or Never. For a description of these parameters see Plug-in Behaviors
Follow these steps for the VPN configuration of Windows, Linux, and Mac plug-ins.
Go to Citrix NetScaler > Policies > Session.
Select the desired session policy, and then click Edit.
Click the + icon.
Select the Client Experience tab.
These dialog boxes options affect the upgrade behavior.
- Never The default is Always.
Select the check box to the right of each option. Select the frequency to apply the upgrade behavior.
Follow these steps for the EPA configuration of Windows, Linux, and Apple plug-ins.
Go to NetScaler Gateway > Virtual Servers.
Select a Server and click the Edit button.
Click the pencil icon.
The dialog boxes that appear affect the upgrade behavior. The available options are:
Windows EPA and VPN plug-in version must be greater than 220.127.116.11
Mac EPA plug-in version must be greater than 18.104.22.168
Mac VPN plug-in version must be greater than 3.1.4 (357)
Note: If NetScaler is upgraded to the 11.0 release, all previous VPN (and EPA) plug-ins upgrade to the latest version irrespective of upgrade control configuration. For subsequent upgrades, they respect the previous upgrade control configuration.