1Y0-201 · Question #104
Scenario: When accessing Citrix Receiver for Web on the StoreFront through NetScaler Gateway, a user receives an error.Click on the Exhibit button to view the error. Users NOT connecting through…
The correct answer is A. The callback URL configured on StoreFront is incorrect. When StoreFront is accessed via NetScaler Gateway but direct access works, an incorrect callback URL on StoreFront prevents it from properly validating the Gateway authentication token.
Question
Scenario: When accessing Citrix Receiver for Web on the StoreFront through NetScaler Gateway, a user receives an error.Click on the Exhibit button to view the error. Users NOT connecting through NetScaler Gateway are successful. What is the likely cause of this error?
Exhibit
Options
- AThe callback URL configured on StoreFront is incorrect.
- BThe NetScaler Gateway CANNOT resolve the StoreFront FQDN.
- CThe StoreFront server CANNOT resolve the Delivery Controller FQDN.
- DThe 'User name and password' authentication method is NOT enabled on the StoreFront server.
How the community answered
(52 responses)- A69% (36)
- B17% (9)
- C6% (3)
- D8% (4)
Why each option
When StoreFront is accessed via NetScaler Gateway but direct access works, an incorrect callback URL on StoreFront prevents it from properly validating the Gateway authentication token.
StoreFront uses the callback URL to communicate back to NetScaler Gateway to verify authentication assertions during the Gateway passthrough authentication flow. If the callback URL is misconfigured, StoreFront cannot complete the handshake with Gateway, causing an error exclusively for Gateway-connected users while direct StoreFront access - which bypasses this validation step - continues to work.
If NetScaler Gateway could not resolve the StoreFront FQDN, it would be unable to proxy requests to StoreFront at all, and no users through Gateway would reach the Receiver for Web page.
An inability to resolve the Delivery Controller FQDN would affect application enumeration for all users regardless of access path, not only those connecting through Gateway.
The 'User name and password' authentication method being disabled would prevent direct users from authenticating as well, not only Gateway users, since both paths rely on StoreFront authentication methods.
Concept tested: StoreFront callback URL configuration for NetScaler Gateway authentication
Source: https://docs.citrix.com/en-us/storefront/current-release/configure-manage-stores/manage-citrix-gateways.html
Topics
Community Discussion
No community discussion yet for this question.
