


The Citrix Receiver should perform domain passthrough (SSO) authentication.A direct ICA/Session Reliability connection to the backend is not acceptable All traffic to the XenApp/XenDesktop servers must be routed through the NSGW.Traffic between Storefront servers and NetScaler must be encrypted (your NetScaler can offload this traffic ofcourse if this is not a requirement).Storefront traffic between client and Storefront Servers must be encrypted.The Storefront servers must be loadbalanced by the NetScalers.So in this tut I will try to give you the complete tutorial how to implement NSGW with Storefront so the Receiver can actually SSO, and all traffic is routed through the NetScaler Gateway. A nice job which already gave me quite a headache. I’m preparing our environment for a big upgrade off all Citrix Receivers, implement Storefront and decommission our last two webinterface servers. So this is one of those topics why I actually started this blog.
