Skip to main content
mr_vaughn
Explorer III
December 31, 2024
Question

ZNTA to limit public facing Citrix NetScaler for published XenApp against brute force login attacks

  • December 31, 2024
  • 3 replies
  • 2654 views

We have a few clients with public facing Citrix NetScalers with a login using MFA. The Fortigate has got Deny for Threat Feeds and limited to Geography of 1 county. but we users are getting hit with password lock outs against AD before the MFA kicks in.

 

Can ZTNA be please in front of the public facing VIP https mapping and only open up if the Forticlient is present and connected?

 

I have concerns on the Citrix Published desktop launching and working correctly using the Citrix Workspace client application to connect via the https proxy the Netscaler provides. via the HTTP Proxy ZTNA provides.

 

Basically we need the ZTNA to only open up to the public IP's of Forticlients to the VIP's and not intercept nor tunnel traffic. Since Citrix already does the encryption and proxy of the ICA traffic over https. and adding it again into another session could likely break it and have massive performance issues.

#XenApp #Citrix

3 replies

FlipperZeroUnleashed
New Member
January 1, 2025

Concerned about protecting public-facing Citrix NetScalers from brute force login attacks while using MFA? ZTNA can help by restricting access to only FortiClient-connected users, preventing unauthorized traffic from reaching the VIP. However, it’s crucial to ensure ZTNA doesn’t interfere with Citrix Workspace’s encrypted ICA traffic, as re-encrypting or tunneling could impact performance and functionality. ZTNA should be configured to only allow FortiClient’s public IPs without disrupting the existing Citrix setup.

mr_vaughn
mr_vaughnAuthor
Explorer III
January 2, 2025

These are my concerns and need to be tested.

diwalpi1
New Member
January 1, 2025

I was thinking about this, however we currently use push authentication for MFA so we would need to switch over to token. Do you happen to have any links or guides that you followed to set this up? I haven't found much on reverse two-factor configuration setup.

mr_vaughn
mr_vaughnAuthor
Explorer III
January 2, 2025

Nope nothing on my side.

mr_vaughn
mr_vaughnAuthor
Explorer III
January 8, 2025

Seems like nobody has an answer.  Opened a Support case and even they cannot get it working. Even with basic ZTNA with the http proxy on a public internet endpoint.