Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mr_vaughn
New Contributor III

ZNTA to limit public facing Citrix NetScaler for published XenApp against brute force login attacks

We have a few clients with public facing Citrix NetScalers with a login using MFA. The Fortigate has got Deny for Threat Feeds and limited to Geography of 1 county. but we users are getting hit with password lock outs against AD before the MFA kicks in.

 

Can ZTNA be please in front of the public facing VIP https mapping and only open up if the Forticlient is present and connected?

 

I have concerns on the Citrix Published desktop launching and working correctly using the Citrix Workspace client application to connect via the https proxy the Netscaler provides. via the HTTP Proxy ZTNA provides.

 

Basically we need the ZTNA to only open up to the public IP's of Forticlients to the VIP's and not intercept nor tunnel traffic. Since Citrix already does the encryption and proxy of the ICA traffic over https. and adding it again into another session could likely break it and have massive performance issues.

#XenApp #Citrix

4 REPLIES 4
FlipperZeroUnleashed
New Contributor

Concerned about protecting public-facing Citrix NetScalers from brute force login attacks while using MFA? ZTNA can help by restricting access to only FortiClient-connected users, preventing unauthorized traffic from reaching the VIP. However, it’s crucial to ensure ZTNA doesn’t interfere with Citrix Workspace’s encrypted ICA traffic, as re-encrypting or tunneling could impact performance and functionality. ZTNA should be configured to only allow FortiClient’s public IPs without disrupting the existing Citrix setup.

mr_vaughn

These are my concerns and need to be tested.

diwalpi1
New Contributor

I was thinking about this, however we currently use push authentication for MFA so we would need to switch over to token. Do you happen to have any links or guides that you followed to set this up? I haven't found much on reverse two-factor configuration setup.

mr_vaughn
New Contributor III

Nope nothing on my side.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors