Just a few days ago Citrix announced the NetScaler 10.5, again packed with lots of cool new and useful features, but that’s not all, they also decided it was time to simplify the NetScaler license structure just a tat. And although that sounds wonderful to some, unfortunately, it has a downside as well. Iโll first elaborate a bit more on the licensing structure as we know it today and take it from there.
Other (related) articles from these series include:
- Citrix NetScaler Gateway, the basics!
- Citrix NetScaler… The basics continued, part one. VIP’s, Monitors and other objects!
- Citrix NetScaler… The basics continued, part two. Static routes, SNIP and MIP
- Citrix NetScaler… The basics continued, part three. High Availability!
- Citrix NetScaler… The basics continued. Part four. What about SSL?
- Citrix NetScalerโฆ The basics continued, part five. Global Server Load Balancing!
- Citrix NetScaler… The basics continued, Part six. Content Switching!
- Citrix NetScalerโฆ The basics continued, part seven. Split Tunneling!
NetScaler ADC and Gateway
Most of the confusion starts with the terms; Citrix NetScaler and Citrix NetScaler Gateway, although they sound very similar, and they do have an overlap, there are some distinct differences depending on the licenses used.
Citrix NetScaler refers to their Application Delivery Controller, or ADC, line of products, while the NetScaler Gateway, formerly know as the Citrix Access Gateway, or CAG, is primarily used for secure remote access. You basically buy a โnormalโ NetScaler but with limited functionality due to the NetScaler Gateway License you upload. NetScaler ADCโs are capable of doing much more than ‘just’ remote access, they can be used for load balancing and HA, content switching, application offloading, application firewalling, cloud connectivity, hybrid cloud solutions and more.ย
Physical and virtual
A NetScaler (ADC or Gateway) can either be physical, as in an appliance, or virtual. If you decide to go virtual, be aware that the underlying hypervisor, or virtual machine, that it runs on needs to have sufficient resources to handle your external connections, SSL offload and what not. As far as the physical appliances are concerned, Citrix offers a whole range to choose from. Depending on the physical model you choose your network throughput will increase (this goes for the virtual platforms as well) as does the amount of RAM and/or dedicated SSL chip capabilities. A NetScaler VPX is a virtual appliance which runs on your hypervisor of choice, a NetScaler MPX is a physical appliance, and last but not least, a NetScaler SDX is a physical appliance which is capable of running multiple VPX appliances, up to 40 in total, depending on your underlying physical resources. It comes with a (branded) XenServer pre-installed. Check outย the main Citrix NetScaler products pageย it will provide you with an overview on all physical as well as virtual models available.
ADC Edition licenses
No matter which type, or model, of ADC NetScaler you pick, you have three different edition, or version, licenses to choose from (aka as platform licenses), knowing: standard, enterprise or platinum. Depending on the edition you purchase different functionality becomes available after you upload your license file. NetScalers are upgraded using the so called: pay as you grow, model. For example, you start out with a standard NetScaler license, never mind the physical or virtual underlying platform for now, after a while it turns out you need certain functionality not available within the standard license portfolio. Than you simply buy an enterprise license providing you with the feature, or features, you need (HA / load balancing between data centers for example), and all you have to do next is upload the license file and youโre done.
Theyโre basically all the same
This works because all NetScalers, and this goes for all (physical) models, are exactly alike when it comes to the features they can potentially offer. Which features become available all depends on the type of edition (or platform) license you purchase and upload. They’re sometimes also referred to as Retail NetScaler (physical box) Licenses. Yes, VPX licenses are separate, read on.
A whole bunch of licenses
Other NetScaler licenses include: Internal, Partner use, demo, evaluation, express, developer and/or VPX. Licenses are assigned to physical and virtual appliances. NetScaler SDX appliances require licenses for each physical appliance and each virtual instance. Although NetScaler VPX edition licenses are handled and purchased separately, they work in the same way as the ADC MPX and SDX licenses as far as feature enablement goes, the same applies to ‘Burst Packs’ by the way, see below.
Citrix also offers so called ‘Burst Pack’ licenses, these will temporarily increase the network throughput capabilities of your NetScaler appliance (physical and virtual). This way you can handle sudden, and perhaps unforeseen, traffic spikes without having to heavily invest in new hardware. Make sure you check out the Citrix NetScaler data sheetย it willย show you all the different features available per edition, it’s a lot to take in, so take your time and if you’re not sure about what you’re reading, it’s probably best to contact one of your Citrix sales representatives.
A breakdown
To keep it simple, think of it like this, when purchasing a NetScaler you follow these steps:
1. First you decide which physical or virtual model to go with, think about the amount of network throughput you may need, SSL offloading capabilities, that sort of thing. 2. Depending on specific features or functions you would like to use, you choose your edition (platform) license. 3. Finally you may want to purchase a maintenance contract with Citrix, they come in gold, silver or bronze, representing 1, 2 or 3 years of support. Contact your Citrix representative for more information.
The NetScaler Gateway before version 10.5
Formerly know as the Citrix Access Gateway, or CAG, and primarily used for secure remote access (SSL Proxy). You basically buy a โnormalโ NetScaler but with limited functionality due to the Access Gateway platform (edition) license you upload, so it’s slightly different from the other ADC licenses mentioned earlier. This ‘platform’ license enables secure access only to the XenApp hosted applications or XenDesktop hosted desktops. It also increases the Independent Computing Architecture (ICA) connections up to 10.000 which by default is 0, this applies to the other NetScaler editions, or platforms, as well. Just to be clear, these 10.000 ICA connection licenses are, or were, part of the Access Gateway Platform license by default and didn’t cost anything extra, let’s just call them administrative overhead.
Next to the Access gateway edition, or platform license, you might also need a Access Gateway universal license. This license enables the Access Gateway Enterprise Edition appliance to support a specific number of concurrent users to make use of some specific Access Gateway features like full SSL VPN’s, Smart Access Endpoint Analysis, clientless access to the Web sites or Micro VPN’s in the case of Citrix XenMobile for example. Due note that, these licenses also apply to the ADC NetScaler family highlighted earlier and that they are optional, you don’t necessarily need them.ย The NetScaler Gateway is available as a virtual appliance as well as physical and upgrading, if itโs more than standard Gateway functionality that you need, also works by uploading a standard, enterprise or platinum (ADC) license file. So you see, thereโs a lot of overlap between the two platforms, it basically all comes down to the license you purchase and upload, with the NetScaler Gateway license being the most โbasicโ one.
Note: The ADC NetScalers, and this goes for all editions, offer gateway functionality by default. Itโs just that, if secure remote access is all youโre looking for, thereโs no need in buying a ADC NetScaler license since they’re more expensive.
What’s new with NetScaler 10.5
Of course the NetScaler 10.5 offers a lot of new functionality and features, sure, but that’s not all, they’ve also slightly changed the NetScaler Gateway licensing model. To start, you’ll still need the universal license to use and control features like full SSL VPN’s, Smart Access or Microso VPN’s as mentioned earlier, no changes there, but… You will no longer need to buy a Access Gateway platform license, or perhaps better said, you can’t. What does this mean?
No more Access Gateway platform license
The ICA Proxy, or Access Gateway platform, license is now build-in by default and instead of increasing the number of ICA users up to 10.000, itโs now set to unlimited. The Proxy functionality (for unlimited users) is now included in all platform / editions by default, NSGW, Std, Entp and Plat. So with the exception of Universal licenses, if itโs Smart Access or Micro VPNโs that you might need for example, you will no longer need to buy any additional licenses. Let me give you an example:
Before: If you had a NetScaler Std, Entp or Platinum license / appliance and you also wanted to do ICA proxy, then you needed to buy an additional Access gateway Platform license (to increase ICA users to 10.000), and perhaps an additional universal license (optional).
New situation: If you have a NetScaler Std, Entp or platinum license / appliance and you also want to do ICA proxy, well, youโre good to go! You wonโt need any more additional Access Gateway platform licenses, itโs all build-in. Again, the Universal license is still optional depending on your needs.
If ICA proxy is all you need you can simply buy a NetScaler Gateway edition license, yes theyโre still there, either in the form of VPX or MPX and thatโs it. By default it will be configured to except an unlimited number of ICA users.
Just one more thing, as mentioned, the number of allowed ICA users is now set to unlimited by default, and this goes for all platforms, editions, licenses or whatever you would like to call them ;-) However, that doesn’t mean that the underlying (virtual) hardware can handle an unlimited amount of ICA connections as well. For example, if we take the virtual NetScaler platform, the VPX, it can handle up to 1500 concurrent ICA connections, if you need more then you’ll have to upgrade and purchase a physical MPX appliance, which, depending on the model, can handle anything ranging from 10.000 to 35.000 concurrent ICA connections at a time. You will find the exact numbers in the NetScaler Datasheet.
Conclusion
Some of you might have visited this post before, if so, you’ve probably noticed that I changed / updated the part with regards to Access Gateway Platform license. It turned out that the information I picked up earlier (which, back than, was shared under NDA), wasnโt written in stone so the speak, and as such slightly changed afterwordโs. I didnโt mean to cause any confusion, so if I did, my apologies! At least now you know what’s new! Citrix took a step in the right direction, simplifying the licensing structure slightly without forcing the consumer to spend more money then needed!
Reference materials used: Citrix.com
17 responses to “Citrix NetScaler (10.5) licensing. What’s new with Access Gateway!”
Good Blog post, but I have one question: Could you refer to an official Citrix paper or website that shows that there is no more seperate Netscaler Gateway license and that you alsways need to buy at least a Netscaler Standard license to get the remote access functions?
Thanks
Hi Raphael,
No I unfortunately I can’t, wish I could. I got this information a few weeks back while it was still under NDA, at least I thought it was, that’s why I haven’t said anything about earlier.
So I guess there are two options, one, I’m wrong, but if so, that’s only because I’ve been mis informed, and believe me, they knew what they where talking about :-) or secondly, I’m right and Citrix still needs to get their documentation and licensing information updated, which is often the case when they release a new product. So I wouldn’t be surprised if it takes another week or so, maybe even longer, before this goes ‘public’ so to speak.
Another option could be that, back than, I mis interpreted, if so, my apologies, but I’m pretty sure that, that didn’t happen.
So if you do come across some official documentation, please feel free to share!
Thanks Raphael!
Regards,
Bas.
Thank you for the quick reply. I will try to find some more information on it and let you know.
I was just wondering because within the Download section on the Citrix Website you can also download a Netscaler Gateway VPX 10.5
Yes I know and I can understand your confusion. I updated the article slightly, just near the end, did you read it already?
But look at it this way, if I am wrong, at least the prizes wonโt go up! ;-)
Nice write up Bas. Dont know who provided the ‘NDA’ info you refer to but your local NetScaler rep is only a phone call away and knows the ins and outs :)
Hi Antal, thanks! It was during the CiTIE last month where they shared this information, they also explicitly mentioned it was still under NDA until the official NetScaler 10.5 release. The only thing that made me question my article was that Citrix hasn’t changed their E-Docs section on this. But it looks like it’s still valid, I talked to some other folks as well. If I have any questions I will definitely let you know! Thanks again and enjoy the game :-)
He Bas, there has Been some misunderstanding after CiTie. One thing that disappeared for sure is the additional license file (platform license) you needed to import to get the number of ICA users to 10.000. This is now unlimited on all platforms / license models, thus not needing a separate license file. The numbers in the datasheet represent the validated numbers that (virtual) hardware can handle. AFAIK the NetScaler Gateway is still for sale, also for 10.5. With a way improved GUI! :-)
Thanks Matthijs,
I got it sorted. They were only referring to the Access Gateway back then (and I though you were to). I guess Iโll wait and let Citrix do the official announcement before writing some more about it!
Regards,
Bas.
And why checks the new XenDesktop and XenApp wizard verify that AAA feature is enabled?
Forget my previous comment, you are reffering to this: http://discussions.citrix.com/topic/353404-netscaler-gateway-105-the-following-licenses-are-not-available-aaa/ right?
[…] wichtige Info: Ab NetScaler 10.5 benรถtigt man keine Plattform Lizenz fรผr Citrix ICA-Zugriffe mehr, denn es ist bereits ein unlimitierter Zugriff bis 10.000 Verbindungen automatisch integriert. Dies vereinfacht das Lizenzthema immens, da man bisher immer eine Hardware/VPX Lizenz und zusรคtzlich eine Plattform Lizenz benรถtigt hat: https://www.basvankaam.com/2014/07/01/citrix-netscaler-10-5-licensing/ […]
Hello
So netscaler sdx acts like an hypervisor where we can have multiplr netscaler vpx?
Yes you could say that, it has a special (branded) edition of XenServer installed on it that takes care of the Hypervisor part. As of NetScaler 10.5 the maximum number of potential virtual SDX appliances has been doubled up to 80!
Great Article !! Cleared up many things !!
Thanks!
Loved this one ! thanks buddy :-)
You’re welcome, glad it helped!