We have a few clients with public facing Citrix NetScalers with a login using MFA. The Fortigate has got Deny for Threat Feeds and limited to Geography of 1 county. but we users are getting hit with password lock outs against AD before the MFA kicks in.
Can ZTNA be please in front of the public facing VIP https mapping and only open up if the Forticlient is present and connected?
I have concerns on the Citrix Published desktop launching and working correctly using the Citrix Workspace client application to connect via the https proxy the Netscaler provides. via the HTTP Proxy ZTNA provides.
Basically we need the ZTNA to only open up to the public IP's of Forticlients to the VIP's and not intercept nor tunnel traffic. Since Citrix already does the encryption and proxy of the ICA traffic over https. and adding it again into another session could likely break it and have massive performance issues.
#XenApp #Citrix
Concerned about protecting public-facing Citrix NetScalers from brute force login attacks while using MFA? ZTNA can help by restricting access to only FortiClient-connected users, preventing unauthorized traffic from reaching the VIP. However, it’s crucial to ensure ZTNA doesn’t interfere with Citrix Workspace’s encrypted ICA traffic, as re-encrypting or tunneling could impact performance and functionality. ZTNA should be configured to only allow FortiClient’s public IPs without disrupting the existing Citrix setup.
These are my concerns and need to be tested.
I was thinking about this, however we currently use push authentication for MFA so we would need to switch over to token. Do you happen to have any links or guides that you followed to set this up? I haven't found much on reverse two-factor configuration setup.
Nope nothing on my side.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1743 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.