Citrix Templates
about citrix templates the system supports several mechanisms for intermediating traffic between a citrix server and client, including the citrix services client proxy, jsam, psam, and vpn tunneling feature the citrix web template enables you to easily configure access to a citrix server using the citrix services client proxy, jsam, or psam the citrix web template is a resource profile that controls access to citrix applications and configures citrix settings as necessary citrix web templates significantly reduce your configuration time by consolidating configuration settings into one place and by prepopulating a variety of resource policy settings for you depending on the type of citrix setup you select you should use the citrix web template if you have the citrix web interface already installed in your environment or if you are using a web server to host your ica files because of their highly simplified configurations, templates are the ideal citrix configuration method if you want to deliver activex citrix web templates simplify your configuration by automatically detecting whether the citrix web client is being used and employing the appropriate access mechanism accordingly for instance, if you have configured the citrix web interface to deliver a java client, the system automatically uses its java rewriting engine to tunnel traffic if you have configured the citrix web interface to deliver an activex client, the system uses its citrix terminal services feature, jsam, or psam (depending on the option you select) to tunnel traffic we strongly recommend using citrix templates instead of the traditional role and resource policy configuration options available through the system ivanti does not support saving a citrix application shortcut to the desktop through the system when the loopback ip address is running on the client double clicking this shortcut returns an error as it does not use jsam or psam comparing access mechanisms for configuring citrix ivanti connect secure supports several mechanisms for intermediating traffic between a citrix server and client, including the citrix terminal services proxy, jsam, psam, and vpn tunneling, feature table docid\ jof mzesjdsohzl pc7zg describes key differences when accessing a citrix metaframe server through a citrix web interface server the descriptions in this table focus on configuring citrix terminal services, jsam, and psam through web resource profile templates (select users > resource profiles > web, click new profile and select citrix web interface/jica from the type list ) if you want to configure access to a citrix metaframe server through a citrix web interface server, you must use web resource profile templates if you want to configure access to a citrix metaframe server without using a citrix web interface server, you must use a standard citrix terminal services or psam resource profile or role the following table describes accessing the citrix web interface server using web resource profile templates it describes key differences when accessing a citrix metaframe server without using a citrix web interface requirement terminal services jsam psam user experience the user clicks a citrix web interface bookmark in the web bookmarks section of the end user console the user is taken to the citrix web interface (wi) sign in page (assuming you do not configure form post sso) once the user signs into the wi portal (either manually or automatically through sso), he is taken to the citrix wi portal page, which contains the list of published applications in icon form when the user clicks the published application, the citrix services client (cts) proxy launches and the ica traffic is tunneled through the cts proxy the user launches jsam the user clicks a citrix web interface bookmark in the web bookmarks section of the end user console the user is taken to the citrix web interface (wi) sign in page (assuming you do not configure form post sso) once the user signs into the wi portal (either manually or automatically through sso), he is taken to the citrix wi portal page, which contains the list of published applications in icon form when the user clicks the published application, the ica traffic is tunneled through jsam the user launches psam the user clicks a citrix web interface bookmark in the web bookmarks section of the end user console the user is taken to the citrix web interface (wi) sign in page (assuming you do not configure form post sso) once the user signs into the wi portal (either manually or automatically through sso), he is taken to the citrix wi portal page, which contains the list of published applications in icon form when the user clicks the published application, the ica traffic is tunneled through psam accessing published applications from mac or linux not supported on mac and linux supported on mac and linux not supported on mac and linux configuring ports automatically monitor all traffic on port 1494 if session reliability is turned off on the server the system monitors port 2598 if session reliability is turned on you do not need to specify which ports to monitor or which applications to intermediate you must specify which ports to monitor this enables you to access published applications that use ports other than 1494 you do not need to specify which ports to monitor or which applications to intermediate psam works in app mode and monitors all traffic coming from certain citrix executables administrator privileges if a citrix web client is not installed on the user's desktop, administrator privileges are required this is a limitation of the installation of the citrix client to install and run the citrix services client proxy client, administrator privileges are not required if a citrix web client is not installed on the user's desktop, administrator privileges are required this is a limitation of the installation of the citrix client to run jsam, administrator privileges are not required requires administrator privileges to install psam modifying host file does not require modification of the etc/hosts file does not require modification of the etc/hosts file does not require modification of the etc/hosts file interface server the descriptions in this table focus on configuring citrix terminal services, jsam, and psam through standard resource profiles (select users > resource profiles > sam or terminal services ) the following table describes accessing citrix metaframe server without using a citrix web interface server requirement terminal services jsam psam user experience the user launches the published application by clicking the bookmark or icon in the terminal services section of the end user console jsam auto launches when the user signs into the device or the user launches jsam manually the user launches the published application using standard methods such as the windows start menu or a desktop icon psam auto launches when the user signs into the device or the user launches psam manually the user launches the published application using standard methods such as the windows start menu or a desktop icon accessing published applications from mac or linux macintosh and linux users cannot access published applications from a citrix metaframe server macintosh and linux users can access published applications from a citrix metaframe server macintosh and linux users cannot access published applications from a citrix metaframe server admin configuration you can specify which ports the system intermediates if you do not configure this information, the system automatically monitors ports 1494 and 2598 you cannot configure citrix as a standard application instead, you need to create a custom jsam application, provide the server names of all metaframe servers, and specify which ports to monitor this enables you to use applications such as citrix secure gateways (csgs) and published applications that use ports other than 1494 you must specify which ports and applications the system monitors this enables you to use applications such as citrix secure gateways (csgs) and published applications that use ports other than 1494 administrator privileges if a citrix web client is not installed on the user's desktop, administrator privileges are required this is a limitation of the installation of the citrix client to install and run the citrix services client proxy client, administrator privileges are not required requires administrator privileges to run jsam because etc/hosts file modifications are required requires administrator privileges to install psam modifying host file does not require modification of the etc/hosts file requires modification of the etc/hosts file does not require modification of the etc/hosts file creating resource profiles for citrix storefront server if you have the citrix storefront, you can create a web template to allow users to access citrix applications without the need for a citrix client users must have one of the following browser versions (or later) to support html5 and websockets internet explorer 10 safari 6 google chrome 23 mozilla firefox 17 you can collect all the logs related to this feature using hprewrite server as the process name to create a resource profile using the citrix template select users > resource profiles > web in the admin console click new profile select citrix storefront 3 1 and above from the type list enter a unique name and optionally a description for the citrix resource profile enter the url of the citrix storefront web server in the base url field use the format \[protocol //]host\[ port]\[/path] the system uses the specified url to define the default bookmark for the citrix resource profile you may enter a directory url or a file url under citrix settings, select the ica client access option admin can either choose to go with the html5 way of delivery or can choose to deliver ica over cts/wasm access clients if admin chooses the ica over cts/wsam access, the corresponding acl should be created and when ics rewrites ica content it should launch the appropriate client add the number of servers/applications and citrix ports which require ica client access select the autopolicy web access control check box to create a policy that allows or denies users access to a specific resource under the base url enter the full url of the resource, select allow or deny , and click add by default, the system automatically creates a policy that enables access to the resource and all of its subdirectories select the autopolicy terminal services access control check box to create a policy that allows or denies users access to terminal services enter the full url of the resource, select allow or deny , and click add by default, the system automatically creates a terminal acl policy when admin allows citrix storefront with the ica client to connect over cts client select the autopolicy single sign on check box to automatically pass data such as usernames and passwords to the citrix application the system automatically adds the most commonly used values to the single sign on autopolicy if you want to perform a form post when a user makes a request to the resource specified in the resource field, select the post the following data check box and specify the following in the resource field, specify the application's sign in page, such as http //my domain com/public/login cgi wildcard characters are not supported in this field to automatically post values to a specific url when an end user clicks on a system bookmark, the resource that you enter here must exactly match the url that you specify in the base url field in the post url field, specify the absolute url where the application posts the user's credentials, such as http //yourcompany com/login cgi you can determine the appropriate url using a tcp dump or by viewing the application's sign in page source and searching for the post parameter in the form tag select the deny direct login for this resource check box if you do not want to allow users to manually enter their credentials in a sign in page users may see a sign in page if the form post fails ) select the allow multiple posts to this resource check box if you want to send post and cookie values to the resource multiple times if required if you do not select this option, the system does not attempt single sign on when a user requests the same resource more than once during the same session optionally specify the following for each item of user data you want to post and click add label the name used to identify the data name the name used to identify the data in the value field the back end application should expect this name value the value to post to the form for the specified name you can enter static data, a system variable, or system session variables containing username and password values user modifiable? select not modifiable to prevent users from changing the information in the value field select user can change value to allow users to specify data for a back end application select user must change value if users must enter additional data to access a back end application if users can or must change the value, a field for data entry appears on the user's advanced preferences page this field is labeled using the name in the label field if you enter a value in the value field, this data appears in the field but is editable to post header data to the specified url when a user makes a request to a resource specified in the resource field, select the send the following data as request headers check box then in the resource section, specify the resources to which this policy applies optionally specify the header data to post by entering data in the following fields and clicking add header name the text to send as header data value the value for the specified header click save and continue select the roles in the roles tab to which the citrix resource profile applies and click add the selected roles inherit the autopolicies and bookmarks created by the citrix resource profile if it is not already enabled, the system also automatically enables the web option in the users > user roles > select role > general > overview page of the admin console and the allow java applets option in the users > user roles > select role > web > options page of the admin console for all of the roles you select click save changes (optional ) select the bookmarks tab to modify the default bookmark created by the system and/ or create new bookmarks by default, the system creates a bookmark for the url defined in the base url field and displays it to all users assigned to the role specified in the roles tab
