ZNTA to limit public facing Citrix NetScaler for published XenApp against brute force login attacks
We have a few clients with public facing Citrix NetScalers with a login using MFA. The Fortigate has got Deny for Threat Feeds and limited to Geography of 1 county. but we users are getting hit with password lock outs against AD before the MFA kicks in.
Can ZTNA be please in front of the public facing VIP https mapping and only open up if the Forticlient is present and connected?
I have concerns on the Citrix Published desktop launching and working correctly using the Citrix Workspace client application to connect via the https proxy the Netscaler provides. via the HTTP Proxy ZTNA provides.
Basically we need the ZTNA to only open up to the public IP's of Forticlients to the VIP's and not intercept nor tunnel traffic. Since Citrix already does the encryption and proxy of the ICA traffic over https. and adding it again into another session could likely break it and have massive performance issues.
#XenApp #Citrix
