The ADC-to-StoreFront server communication is SSL/TLS encrypted, not HTTP – this traffic contains user credentials.
The Load Balancing VIP sends SSL traffic to two or more StoreFront servers in the local data center – for redundancy.
Someone is responsible for ensuring the certificate is not expired and receives pending certificate expiration notifications.
The certificate for the SSL Load Balancing VIP is valid: trusted, not expired, matches FQDN, no errors in Chrome, etc.
GSLB) to a VIP in a different data center if the primary data center is down.
The FQDN automatically fails over (e.g.
) resolves to a Load Balancing VIP, not a single server.
The FQDN that users use to access Citrix (e.g.
Some upgrades are performed differently for HA/DR than for single components. – enables testing changes, including HA/DR changes, before performing those changes in production.
Separate test Citrix environment has identical architecture as production: multiple data centers, high availability for all components, etc.
Citrix connectivity infrastructure design is documented: StoreFront, Gateways, ADCs, multiple datacenters, Delivery Controllers, SQL, etc.
The rest of this article is an incomplete list of health check assertions for Citrix environments. Health Checks tend to focus on non-functional qualities like the following: Health Checks review an environment for configurations that might cause future problems, not necessarily existing problems.
2019 Sep 15 – added WEM assertions from CTP James Kindon.
2019 Sep 17 – added assertions from citrixguyblog in the comments.
2019 Sep 22 – added new items from CVAD 1909.
#2012 PREP SA DIRECTOR PLAYER ERROR LICENSE#
2019 Sep 25 – added License Server vulnerability.
2019 Sep 26 – external beacons should not use.
2019 Oct 8 – ADM Security Vulnerability.
2019 Nov 23 – Offload Compositing for App Layering.
#2012 PREP SA DIRECTOR PLAYER ERROR UPGRADE#
2019 Dec 4 – added info from Citrix Blog Post Upgrade your ADC from 10.5 to 11.x/12.x - Lessons from the field.
2019 Dec 12 – added Chrome detection of Workspace app.
2019 Dec 12 – prefer multiple master images instead of one master image.
2020 Jan 24 – added link to Indicator of Compromise Scanner for CVE-2019-19781.
2020 Apr 1 – Delivery Controllers – upgrade LHC LocalDB to version 2017.
2020 Apr 10 – Hypervisor – added vCenter 6.7 critical vulnerability with CVSSv3 base score of 10.0.
2020 Jun 22 – If LTSR Receiver 4.9, then version is or newer to resolve security vulnerabilities.
2020 July 7 – CTX276688 Citrix ADC vulnerabilities.
2020 July 21 – CTX277662 Citrix Workspace app vulnerabilities.
#2012 PREP SA DIRECTOR PLAYER ERROR UPDATE#
2020 Sep 8 – StoreFront servers – added info from CTX277455 Citrix StoreFront Security Update.
2020 Sep 9 – VDA Master Image – upgrade Teams periodically (no auto-update).