Citrix Gateway VPN clients and supported features 编辑

Citrix Gateway VPN clients and supported features

Important:

  • The legacy Citrix VPN client was built using Apple’s private VPN APIs that is now deprecated. VPN support in the Citrix SSO app for iOS and Citrix Secure Access agent for macOS is rewritten using Apple’s public Network Extension framework. Citrix Gateway plug-in and Citrix VPN for iOS and macOS are no longer supported. Citrix SSO app for iOS and Citrix Secure Access agent for macOS is the recommended VPN app to be used.

  • General availability of nFactor authentication support for Android devices would be available in one of the upcoming releases.

The following table lists some of the commonly used features supported for each VPN client.

FeatureCitrix Secure Access for WindowsMac plug-inLinuxCitrix Secure Access for macOSSSO for iOSSSO for Android
Always On (user mode)Yes (11.1 and later)NoNoNoNoYes (via MDM) Android 7.0+
PAC file pushYes (12.0 and later)YesNoYesYesNo
Client proxy supportYesYesYesNoNoYes. See note 1
Max limit of Intranet Applications512128128No limitNo limitNo limit
Intranet IP (IIP) supportYesYesYesYesYesYes
Split tunnel ONYesYesYesYesYesYes
Split tunnel reverseYesYesYesYesYesYes. See note 5
Split DNS REMOTENoYesYesYesYesYes. See note 6
Split DNS BOTHYesYesNoYesYesYes. See note 6
FQDN based split tunnelYes-Only ON (13.0 and later)NoNoYesYesYes. See note 5
Client idle timeoutYesYesYesNoNoNo
Endpoint analysisYesYesYesYesNoNo
Device certificate (classic)YesYesNoYesNoNo
nFactor authenticationYes (12.1 and later)NoNoYesYesYes. See note 3
EPA (nFactor)Yes (12.1 and later)NoNoYesNoNo
Device certificate (nFactor)Yes (12.1 and later)NoNoYesNoNo
Push notificationYes (12.1 and later)NoNoNoYesYes (device registration only)
OTP token autofill support. See note 2NoNoNoNoYesYes
DTLS support. See note 4Yes (13.0 and later)NoNoNoNoNo

Note:

  1. Setting a proxy in the client configuration on the VPN virtual server in the gateway configuration for Android 10 and later is supported. Only basic HTTP proxy configuration with IP address and port is supported.
  2. Only QR code scanned tokens are eligible for auto filling. Auto filling is not supported in the nFactor authentication flow.
  3. nFactor authentication support for Android devices is under preview and the feature is disabled, by default. Contact Citrix Support for enabling this feature. Customers must provide their Citrix Gateway’s FQDN to the support team for enabling nFactor authentication for Android devices.
  4. For details, see Configure DTLS VPN virtual server using SSL VPN virtual server.
  5. FQDN based split tunnel support and reverse split tunnel for Android devices is under preview and the feature is disabled, by default. Contact Citrix Support for enabling this feature. Customers must provide their Citrix Gateway’s FQDN to the support team for enabling it for Android devices.
  6. For Split DNS BOTH mode, DNS suffixes must be configured on the gateway and only DNS A record queries ending in those suffixes are sent to the gateway. Rest of the queries are resolved locally. Android Citrix SSO app also supports Split DNS LOCAL mode.

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。
列表为空,暂无数据

词条统计

浏览:61 次

字数:6267

最后编辑:7 年前

编辑次数:0 次

    我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
    原文