For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

halsi82_117121's avatar
halsi82_117121
Icon for Nimbostratus rankNimbostratus
Feb 28, 2014

Citrix - Change Client IP or Client Name

Hi all together!

 

We had an Citrix Access Gateway. Now we have F5 BIG-IP APM. Everything works fine with Citrix. But now we have a challenge.

 

The Citrix Access Gateway had the feature to change the CLIENT Name or the Client IP adress showed on the citrix servers.

 

We have to change that, because we want to differ between Internal & External Users. External Users get different policies than internal ones.

 

So if some user try to connect through the F5 (External) we would send the Citrix Broker Server the IP from the F5 and not the local client IP. From internal the connection is direct to Citrix Broker.

 

I tried to change the variable session.user.clientip but with no success. IP changed, but on the citrix Broker log there is still the same IP as before.

 

Any ideas?

 

please help me out.

 

Greetings, Wolfgang

 

3 Replies

  • Hamish's avatar
    Hamish
    Icon for Cirrocumulus rankCirrocumulus

    Yep. You need to add the CLientName= into the [WFCLIENT] section (Located in the 'Custom Parameters' of the Remote Desktop config. e.g.

    [WFCLIENT]
    ClientName=F5-%{session.user.sessionid}
    

    APM sets it by default in the Application section (IIRC), but that only works for Windows. Not Mac. Adding it into [WFCLIENT] makes it work for everyone...

    H

  • f5's from version 11.0 onwards have had the feature to send smart access filters to the Wi's, that's how we did it in our environment to do the same thing.

     

    The filters get set in your APM Policy

     

  • Great. Worked for me to set

        [WFCLIENT]
    ClientName=F5-%{session.user.sessionid}
    

    Thanks.