Product Documentation

Deploying the Web Interface Behind NetScaler Gateway in the DMZ

Jan 15, 2014

In this configuration, both NetScaler Gateway and the Web Interface are deployed in the DMZ. When users log on with Citrix Receiver, the initial user connection goes to NetScaler Gateway and is then redirected to the Web Interface. To route all HTTPS and ICA traffic through a single external port and require the use of a single SSL certificate, NetScaler Gateway acts as a reverse web proxy for the Web Interface.

Figure 1. Web Interface Located Behind NetScaler Gateway
Web Interface Located Behind NetScaler Gateway

When the Web Interface is deployed behind NetScaler Gateway in the DMZ, you can configure authentication on the appliance but it is not required. You can have either NetScaler Gateway or the Web Interface authenticate users because both reside in the DMZ.