Professional Documents
Culture Documents
he Citrix XenApp & XenDesktop Service hosted in the Citrix Cloud is a variant of a hybrid
cloud architecture except that the access and control layers of the solution are managed by Citrix
in the Citrix Cloud, eliminating the need Microsoft Hyper-V, Nutanix Acropolis, VMware
vSphere and physical servers across multiple on-premises data centers.
cloud hosting providers for resource layer components (Windows and Linux desktops and
applications), while all managed from a centralized controller architecture.
or the local infrastructure team to manage, maintain and upgrade the access and control
components. Each unique cloud or on-premises location hosting resources must deploy a Citrix
Cloud Connector component, which Virtual Desktop Models
provides the link to the Citrix Cloud service.
Host
Host
Host
XenApp & XenDesktop Components
XenApp & XenDesktop Cloud Components
NetScaler Gateway Service – an offering within the Citrix Cloud providing secure VPN access to
XenApp, XenDesktop and XenMobile applications
Users
Access Control Resources Users
Access Control Resources Studio
Licenses Director Studio
HDX Technologies
HDX Broadcast – ensure reliable, high-performance connectivity over any network
Receiver (External User)
HDX RealTime – support for softphones, voice chat and unified communications like Skype for
Business
HDX Mobile – optimizes the delivery of Windows apps to mobile form factor devices
HDX Plug-n-Play – extends hosted virtual resources to support locally attached USB devices
HDX RichGraphics – optimizes delivery of 2D and 3D graphics to remote devices
HDX WAN Optimization – optimizes bandwidth requirements, allowing access from satellite
and branch office locations
HDX Adaptive Orchestration – dynamically integrates all HDX Technologies based on host,
network and device
80 HTTP
1
A user initiates a connection to the NetScaler Gateway URL and provides logon credentials.
Resources
Users
Access Control Resources
Host
88 Kerberos
135 RPC
2
The credentials are validated against Active Directory.
389 LDAP
11
2
443
1494 2598 443 8008 FH IA
443 SSL/TLS
3
NetScaler Gateway forwards the user credentials to StoreFront.
6
NetScaler Gateway
Active Directory
NetScaler
Virtual Desktop
464
Native Change Windows Passwords
Auth
HDX MediaStream – optimized technologies for playing video and audio recordings
80/443
36
4a
Director
4a
4a
8000
Active Directory
Pooled Windows Desktops
TML5 Receiver 6
(External User)
3268 LDAP Global Catalog
5
3389 Remote Assistance
SQL Database
8000 NetScaler Load Balancing Monitor
Studio
SQL Database
Licenses
FH 3224-3324 - Framehawk
ICA Protocol
Enlightened Data Transport
636 LDAP SSL
When StoreFront is in the same domain as the controller, StoreFront validates the user
Microsoft Azure
credentials against Active Directory and forwards to the Delivery Controller.
4b
3269 LDAP Global Catalog SSL
STA
Amazon AWS
b the Delivery Controller, credentials are forwarded to the Delivery Controller for
389/636
Citrix XenServer
2598 Citrix Session Reliability
Pool Master
validation against Active Directory.
StoreFront
XenApp / XenDesktop
The XenDesktop Delivery Controller retrieves a
Controller
80/443 STA 443
5
list of available resources by querying the SQL Database.
StoreFront
XenApp / XenDesktop
VMware vCenter
Controller
8008 ICA for HTML5
The list of available resources is sent to 6
StoreFront, which populates the user’s Citrix Receiver, Windows Start Menu or browser
1433
Microsoft SCVMM Server
80, 443, or custom - Secure Ticket Authority
8100 WCF
LS 27000, 7279, 8083 - License Server
IA 16500-16509 – ICA Audio
Session Launch
When the user selects a resource from 1
Receiver, the request is sent to StoreFront through NetScaler Gateway.
Users
Access Control Resources
The ICA protocol integrates the different HDX technologies into the network stack by use of
virtual channels.
StoreFront forwards the resource request to
Drives
kype 2
80 HTTP
The Delivery Controller queries the SQL 3
Database to determine an appropriate host to
Keyboard / ICA
Mouse
Audio Clipboard
Seamless Smartcards
Windows
Adaptive Display
2598
Virtual Desktop
Pool Master
StoreFront
XenApp / XenDesktop Controller
Adaptive
Printing
Multitouch
Transport
8
(TCP or EDT)
Multimedia
Flash
AD
1494
Citrix Receiver uses the launch file and makes a connection to the NetScaler Gateway (443).
Keyboard / ICA
Mouse
Audio Clipboard
Seamless Smartcards
Windows
Adaptive Display
80
VMware vCenter
3268 – LDAP Global Catalog 3269 – LDAP Global Catalog SSL
NetScaler Gateway validates the ticket with the STA (80 or 443)
3 – DNS Mobile
8 – Kerberos Sensors
Cloud
Connector
9
SQL Database
Amazon AWS
ersion 1.02 NetScaler Gateway initiates a connection to the resource (1494 or 2598) on the user’s
behalf.