Citrix Blogs

Lessons from the Field: Scaling Citrix Gateway for business continuity

Citrix Consulting helps you shorten the distance between great ideas and game-changing business outcomes. Our experts partner closely with customers to apply their decades of technical expertise and leading practices to design and implement Citrix solutions, improve adoption, and enhance security. This is the first post in a series in which Citrix consultants will share lessons from the field.

As many of our customers expand their remote work programs or extend into the cloud (or both!), there is an increasing need to securely scale HDX connections, no matter where user resources are located. Ensuring that you have the user workload capacity on-prem or in the cloud is only half the equation. In this blog post, I’m going to discuss how to scale your Citrix Gateway capabilities using either physical or virtual Citrix ADC appliances.

If you look at our Citrix ADC MPX device datasheet, you’ll see that our largest hardware appliances are rated at a maximum of 35,000 concurrent HDX proxy connections. Similarly, our virtual ADC VPX appliances are limited by the underlying hypervisor or cloud platform and have a maximum limit of 9,000 concurrent HDX connections to a single appliance.

So what happens when you need more concurrent HDX proxy users than a single high-availability ADC pair can handle?

That’s where multi-tier ADC architecture comes into play.

Diagram 1 – An example of multi-tier ADC architecture

Multi-tier ADC architectures enable us to expand the number of supported HDX proxy users in a single data center while still using a single access URL. If done correctly, the user experience is no different from what you get using a single HA ADC pair!

You might be asking, what about Clustering? Clustering is another great method of scaling out Citrix ADC services (just ask some of our largest customers)! In this article I’ll be focusing on multi-tier ADC as an alternative to clustering for those customers whose needs are scoped solely to HDX proxy communication.

How It Works

The idea behind the Citrix ADC multi-tier architecture is to use a set of Tier 1 Citrix ADCs configured in an active-passive high-availability (HA) pair using SSL bridge load balancing to intelligently send HDX connections to a set of Tier 2 ADC appliances running Citrix Gateway vServers.

In this deployment architecture, all user authentication and SSL connection termination are completed at Tier 2. The Tier 1 ADC appliances are solely used to intelligently load balance the overall client connection load amongst the Tier 2 devices. This way, Tier 1 ADCs are not responsible for SSL encrypt\decrypt but rather offload those connections to Tier 2.

Diagram 2 – Tier services

High Availability

Citrix Consulting always recommends that customers deploy Citrix ADCs in HA pairs to ensure availability of critical user resources. With multi-tier architecture, this rule applies to Tier 1 ADCs, which are in the critical data flow path. A failure of one of these devices without HA would be a denial of service for any remote HDX users.

In contrast, at Tier 2 we have multiple options to provide HA. The first option is to use active standalone ADCs in an N+1 configuration to provide availability of HDX resources (see Diagrams 1 and 2). In this configuration if a Tier 2 ADC fails, the affected sessions will need to re-authenticate and launch their (still running) resources. However, by using N+1 or higher, we ensure there is enough ADC capacity to deal with the failure of at least one Tier 2 device.

The other option is to use Tier 2 ADCs in HA pairs. This configuration requires additional ADC appliances but ensures that a failure of a single device will not disrupt user connections if Session Reliability is configured.

Diagram 3 – Tier 2 using HA pairs

Both of these architectures can provide high availability of resources. When deciding between them, consider the business requirements and cost of each.

Key Configurations

If you’re looking to set up your own ADC multi-tier architecture, here are the key configurations to include:

Considerations

Now that you understand how multi-tier ADC architecture works, here are some additional considerations and lessons learned from our field teams:

Multi-tier ADC architecture is a design that our Consulting teams have successfully used for years to scale Citrix ADC deployments beyond single appliances. If you need to quickly deploying scalable and flexible remote access to your HDX resources, consider ADC multi-tier and contact our experienced Professional Services group to assist in designing and building a solution to meet your needs.

Exit mobile version