Citrix DaaS

User access

There are two primary components that provide access to applications and desktops in Citrix DaaS deployments:

  • Citrix Workspace: Citrix Workspace is a service managed by Citrix. This is the simplest way to provide access to DaaS resources, requiring no deployment effort and always kept up to date with the latest features.

  • On-premises StoreFront: StoreFront is an on-premise product that you install in your own environment. This is recommended when you need to aggregate resources from DaaS and on-prem CVAD deployments or where you need more control of the deployment. You can deploy a Citrix Gateway to allow users to authenticate and connect to StoreFront from outside your internal network.

In either case, end-users access their workspaces or stores using Citrix Workspace app, either in a web browser or a locally installed app.

Using Citrix Workspace

Access to workspaces occurs through one or more URL https://<subdomain>.cloud.com, where you can choose <subdomain>. Alternatively you can register your own custom domain.

For more information about using Citrix Workspace, see:

To provide remote access for to the resources managed by DaaS, you can use either Citrix Gateway service or your own Citrix Gateway.

  • To use the Citrix Gateway service:

    1. In Citrix Cloud > Resource Locations, select Gateway for the resource location you want to use.
    2. Select Gateway Service and then click Save.
    3. In Citrix Cloud > Workspace Configuration > Service Integrations, locate the Gateway service and select Enable from the ellipsis menu.
  • To use your own Citrix Gateway:

    1. Set up Citrix Gateway as an ICA Proxy (No authentication or session policies are needed).
    2. Configure a resource location to use Citrix Gateway:
      1. In Citrix Cloud > Resource Locations, select Gateway for the resource location you want to use.
      2. Select Traditional Gateway and enter the external FQDN. Do not add a protocol. Ports are optional. Combination remote and internal access is not supported in Citrix Workspace.
    3. Bind Citrix Cloud Connectors as Secure Ticket Authority (STA) servers to Citrix Gateway. For details, see CTX232640.

      Note:

      Only Citrix Cloud Connector machines are supported for use as STA servers with Citrix Gateway. Using other connectors as STA servers, such as Connector Appliance, isn’t supported.

For more information about the Citrix Gateway service and Citrix Gateway, see Citrix Gateway.

Service continuity

Service continuity allows users to connect resources when Citrix Cloud is not available. For more information, see Service continuity.

Using on-premises StoreFront

StoreFront is a Windows application that you can install on your own servers to provide access to CVAD, DaaS and SPA resources. It connects to DaaS using Citrix Cloud Connectors that proxies the requests to Citrix Cloud. The connector encrypts passwords before they are sent to Citrix Cloud, using a key that is returned directly to Citrix Workspace app and never sent to the cloud.

  1. Install the connectors. You should have at least two connectors in each location for redundancy.
  2. Ensure the Cloud Connector can reach the Cloud NFuse/STA URL at (https://<customername\>.xendesktop.net/Scripts/wpnbr.dll and ctxsta.dll).
  3. Enable HTTPS on the connector to ensure data between StoreFront and the Cloud connector is encrypted, see How to Enable SSL on Cloud Connectors to Secure XML Traffic.
  4. If you do not already have a StoreFront deployment, Install StoreFront and Create a deployment.
  5. Add a resource feed to your StoreFront store. In the server list including all cloud connectors. Choose the HTTPS protocol.

End user access

To provide access to end-users using Citrix Workspace app, see User access options

Remote access using Citrix Gateway

You should not expose your StoreFront server directly to the internet. Instead provide authentication and remote access using Citrix Gateway. You can also use a Citrix Gateway for internal access to take advantage of its security features.

Local Host Cache

Local Host Cache enables connection brokering operations in Citrix DaaS deployment to continue when Cloud Connectors cannot communicate with Citrix Cloud.

The Local Host Cache feature works only in resource locations containing a customer-deployed on-premises StoreFront. Local Host Cache is not supported for use with Citrix Workspace.

Each resource location must have a customer-deployed on-premises StoreFront. Verify that the resource location contains a local StoreFront that points to all the Cloud Connectors in that resource location.

For more information, see Local Host Cache.

User access