15cb7e05-92ec-4822-97cb-7d3c15da2b01
15cb7e05-92ec-4822-97cb-7d3c15da2b01
15cb7e05-92ec-4822-97cb-7d3c15da2b01
Citrix XenDesktop
Citrix XenDesktop delivers virtual Windows apps and desktops as secure mobile services. With
XenDesktop, IT can mobilize a business while reducing costs by centralizing control and
security of intellectual property. XenDesktop can deliver full desktops or just the apps to any
device. XenDesktop enables the delivery of a native touch-enabled mobile experience that is
optimized for the type of device, as well as the network. XenDesktop is built on a 3rd-generation
FlexCast Management Architecture (FMA), and is the only hybrid cloud-ready platform that
separates the management plane from the workload to enable IT to securely deliver published
apps on-premises, and manage workers and mobile workspaces either on-premises or in the
cloud.
Configuration Overview
The following example illustrates a configuration of the Alteon NG load balancer to manage and
monitor the Citrix XenDesktop environment using StoreFront and DDC (Desktop Delivery
Controller) servers. In this implementation, client traffic goes to the StoreFront, and in the back-
end from the StoreFront to DDC servers. All traffic is managed by the Alteon NG load balancer
to ensure client persistency all the way to the StoreFront and DDC servers. The Alteon NG
terminates the SSL sessions in order to offload the CPU processing of the StoreFront servers.
Alteon NG Active
Network Configuration
/c/sys/mmgmt
dhcp disabled
addr 192.168.142.3
mask 255.255.255.0
broad 192.168.142.255
gw 192.168.142.254
ena
/c/sys/access
tnet ena
/c/port 1
pvid 5
/c/l2/vlan 1
learn ena
def 0
/c/l2/vlan 5
ena
name "VLAN 5"
learn ena
def 1
/c/l2/stg 1/clear
/c/l2/stg 1/add 1 2 5
VRRP Configuration
/c/l3/vrrp/vr 11
ena
ipver v4
vrid 11
if 1
prio 250
addr 192.168.141.4
/c/l3/vrrp/vr 12
ena
ipver v4
vrid 12
if 1
prio 250
addr 192.168.141.200
/c/l3/vrrp/vr 13
ena
ipver v4
vrid 13
if 1
prio 250
addr 192.168.141.205
/c/slb/accel/compress
on
/c/slb/accel/compress/comppol 1
minsize 1
ena
SSL Configuration
/c/slb/ssl/certs/key 1
/c/slb/ssl/certs/import key "1" text
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: DES-EDE3-CBC,1D470BDDA99ECEF1
YVGgPQA6k0SS2K9DDA4MFpT9k7an7FKX1VSW5uVY+2LvkE1FzcdeG8UKiVH5Dj/o
xO/Ak9kzdX/Zh1M0CnuPi5VzPiaJrbpS0XFy+hZ0+o/23MuAjn8a7m3Sa4BcaAP+
gQw5xOs+PLZYBsDKHh7tlp7ND8S+JOVZH9wV+5CTkJuIxoC/It9/XPhNYGI0bdZM
lAmeE5xVl3YyEr5KF8ONFyQvL6WyIr3lCpzMbAe2E60me9WSoFfgyayDWUVBa0LM
IYQm8srttUWtX+8CUQPtS3abGZMv5wcZxlaAQNyzRMRe1clAOM3rC8GgKBl1x59w
1KTjsAm6yVz7lszp7fDxscD8KxkRIzdaTaR0SzngoVPEecT2DyivGO7CpKOwAqVV
IcQ0/gEsM34r0sWeZr8sIMjWflgVyFzUh/3VlQHLs65mh04Lmx6UWhVURmsIMXPr
BqDLHJYXAmoWm0wjcjguM5XTK5Ja+HeR4wEmZqBEXYpbOTEytoPVEgq0vN8NVjGF
QQp62b85/UIfWwKI+zluqI34unF5Ueb3fjk0VUqu90QF7NV2xznrAK5Znxx1wYND
q3qIWvcUUIpiVEi7czrnKF8GFT7pWtKruqXclEGpp/sv49lSnyP3kPXtbgBcsQGd
ERAlGvxeEqI2VrMCsGwYtTOXzdd+AIsXb48vIKNXV0V47fvPPp3MLQXzpU5mKZBM
PVPLkL34OQ/qb8KlsOS6IC+j32dRGrxY6SIamYQNu6c9eX/9n+dMT2ynAZgxsAdP
R15QRbsB1ljd6svAxwVvhjuORrmDGfNhRMsgjNbSxdFTW16XosGagG4Eu6SPJX2/
S+SmoxIfZbdwyc908JDU4iJM+7vOBiWtYt8YuD/U/VkHiCrbGCyLnYO+auRPpyMb
hswMZJ5j4hkvcRi87BLVM2x6Ax5i1vFwKaeJRLQrCI3cB1sVF7GX2xRoyM5ZX2Ae
JAMjV6IZvS6e6hSgXlnxWiqv3M3jNrjQ2sy4lwSzrWo71Zd5jRjB2y9jrd/0l6d6
u+SIrNDuV7Hv41YZAEXCplvcc4VAe0DwIhOqy6T6gF8T8131UFt54sAi/sQPdDm9
J9PzWN4xURGLX9rlxr8eGWKe1RjOGR/spZ7Q5zxsNiE5Xj83HVI3VJykLM04NC+X
rchx5f6i9OyaaW0Wa4NkPEhTou8uGhiXmQtommSADo8OJadDVkcJca6nx4yRjdi4
uVoepod2cJfzb18/zeP0LAF+4cTIGag8iaTfOccBNvPhsHuXp9RuYdfvgMMUobRj
XXAETnIDs96lQUUjf2Mr6rog3qxNCtnHbQe6/6uZdhvYzH4dbbviWhRQ4YobhVef
/c/slb/ssl/certs/request 1
/c/slb/ssl/certs/import request "1" text
-----BEGIN CERTIFICATE REQUEST-----
MIIChzCCAW8CAQAwQjEhMB8GA1UEAwwYc3RvcmVmcm9udC5jdHJhZHdhcmUuY29t
MQswCQYDVQQGEwJJTDEQMA4GA1UECgwHUmFkd2FyZTCCASIwDQYJKoZIhvcNAQEB
BQADggEPADCCAQoCggEBANBRXnTiDOcdkPsC6dgn9BkxAsdXuGIUk/Qbf8GOlnnl
dGKDzZvBwkWOOyw/9aiZJAKhzeaCOb1dfFIyhFpwwMzoXDJu0ziuVXNu7zmjg1eE
P14OLRvxx55K3yVhXBqLTV1cpq1QuBJsltr9DgiD9bAjyUgxsA0J45aki7QBadIJ
xF9swaXC7Fg/r1W5jy5LbXDbaPUJPMU/s44lyVVLXqFbCgQo6HPLEk3zwIkxyeFD
JpoVi4pgolN7Cr6GtpwKk+nYqLoLXyIOJPEWZdyZ9mVaZZzphcW7QoLXfgdmfPMh
H8z2xNCu6hYMHN/nfZ6FY5KIjtEDN++k+2FamLtBuXUCAwEAAaAAMA0GCSqGSIb3
DQEBBQUAA4IBAQA+DNR2SpbVw2ilK8DW+G2t2yUBGuNDhvK3trSml7k0AXuI8Rfw
+1HK4M0q2o5X49qtNT6GXRI2esWfqI7sWgnlfhUzgg8QS6jLOVuvWPiYEK4TjqgW
zXiOl5FY9H5LmPmQpekfUzBmgMi3p0VMoEuhkD/1NQr0XzbLEKrSviEf+WF/0tMY
WI694ENqgnIfI1cPxp/v1f9rXEZhGZ1gSyAcPToWP5LXSGMMztzZcEnRv6BIsbs0
Rey8iqNMqd0RKCLMnRJpkWCRATnRNm9x0+uih1FNRc9tFegphWs6q1DQpU7ylp7W
BunHxpBPm+nVUv6OvJK3/J1YWcxYpdCZ6L1w
-----END CERTIFICATE REQUEST-----
/c/slb/ssl/certs/cert 1
/c/slb/ssl/certs/import cert "1" text
-----BEGIN CERTIFICATE-----
MIID+TCCAuGgAwIBAgIEVeLGQDANBgkqhkiG9w0BAQsFADBCMSEwHwYDVQQDDBhz
dG9yZWZyb250LmN0cmFkd2FyZS5jb20xCzAJBgNVBAYTAklMMRAwDgYDVQQKDAdS
YWR3YXJlMB4XDTE1MDgzMTEwMTUzMFoXDTE2MDgzMDEwMTUzMFowQjEhMB8GA1UE
AwwYc3RvcmVmcm9udC5jdHJhZHdhcmUuY29tMQswCQYDVQQGEwJJTDEQMA4GA1UE
CgwHUmFkd2FyZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANBRXnTi
DOcdkPsC6dgn9BkxAsdXuGIUk/Qbf8GOlnnldGKDzZvBwkWOOyw/9aiZJAKhzeaC
Ob1dfFIyhFpwwMzoXDJu0ziuVXNu7zmjg1eEP14OLRvxx55K3yVhXBqLTV1cpq1Q
uBJsltr9DgiD9bAjyUgxsA0J45aki7QBadIJxF9swaXC7Fg/r1W5jy5LbXDbaPUJ
/c/slb/ssl
on
/c/slb/ssl/sslpol 1
name "SSL.Policy"
ena
SLB Configuration
/c/slb/accel/caching
on
/c/slb
on
/c/slb/adv
direct ena
vstat ena
submac "ena"
/c/slb/real 1
ena
ipver v4
rip 192.168.141.21
name "Citrix.WebAPP1"
/c/slb/pip/type port
/c/slb/pip/add 192.168.141.201 1
Sync Configuration
/c/slb/sync
prios d
certs e
/c/slb/sync/peer 1
ena
addr 192.168.141.5
Network Configuration
/c/sys/mmgmt
dhcp disabled
addr 192.168.142.5
mask 255.255.255.0
broad 192.168.142.255
gw 192.168.142.254
ena
/c/sys/access
tnet ena
/c/port 1
pvid 5
/c/l2/vlan 1
learn ena
def 0
/c/l2/vlan 5
ena
name "VLAN 5"
learn ena
def 1
/c/l2/stg 1/clear
/c/l2/stg 1/add 1 2 5
/c/sys/access/sshd/ena
/c/sys/access/sshd/sshv1 dis
/c/sys/access/sshd/on
/c/l3/if 1
ena
ipver v4
addr 192.168.141.5
VRRP Configuration
/c/l3/vrrp/vr 11
ena
ipver v4
vrid 11
if 1
addr 192.168.141.4
/c/l3/vrrp/vr 12
ena
ipver v4
vrid 12
if 1
addr 192.168.141.200
/c/l3/vrrp/vr 13
ena
ipver v4
vrid 13
if 1
addr 192.168.141.205
Sync Configuration
/c/slb/sync
prios d
certs e
/c/slb/sync/peer 1
ena
addr 192.168.141.3
/c/slb/pip/type port
/c/slb/pip/add 192.168.141.202 1
© 2015 Radware, Ltd. All Rights Reserved. Radware and all other Radware product and service names are registered
trademarks of Radware in the U.S. and other countries. All other trademarks and names are the property of their respective
owners. Printed in the U.S.A