Binding many NetScaler Gateways to a content switching vServer on Citrix NetScaler, Method 2


Or: Admin partitions

Update, December 2020: It does not work with current versions

This is a work around for a well-known problem in NetScaler: Binding NetScaler Gateways to content switching vServers.

This solution does not follow Citrix best practices. Avoid using it, if you can!

My solution will work with NetScaler 11.1 upward.

The Problem

Up to 11.0 it was impossible to bind a NetSaler Gateway to a Content Switching vServer. By now (firmware versions 12) this is limited to a single NetScaler Gateway. This limitation may be an obstacle to overcome in certain environments. Most companies nowadays suffer under a lack of public IPs. But mos of all: Users don’t like complex environments with tons of different URLs to handle, one for mobile devices, one for PCs, one for trusted, one for untrusted devices and so on. Instead they want to use a single URL for all use cases.

Content switching may mitigate this issue by hiding very different configurations behind a single URL. But this is not true for NetScaler Gateways. In days of old we could not bind any gateway to a content switching vServer at all, now (starting from version 11) we can bind a maximum of one gateway to it.

Why may one gateway not be enough? First of all, it is complexity. It may confuse you if you have to bind tons of different scenarios to one gateway. In my real world experience I see often buggy environments being buggy, as complexity may over work the admins. But there may also be technical reasons. One of my costumer would have to bind round about 50 LDAP sources of costumers and partners. All of them are geographical dispersed and some of them may even be misconfigured and therefore slow. Logon to the last ADs in the list would be painful. Splitting the gateway up into some gateways would speed up things very much.

The solution

I already posted a solution for NetScaler 10 using the ANY service. There are pros and cons about it. My new solution uses admin partitions

What’s great about it?

Well, this one is much closer to a supported solution!

And there are down sides for sure?

You’re right! There is a serious downside: We need an external router. Sorry for that.

How to bind multiple Citrix NetScaler Gateways to a single Content switching vServer


We need:

  • NetScaler with sufficient bandwidth (VPX, MPX, VPX, CPX).
  • a router
  • 3 subnets

Traffic flow:

I assume, the external firewall is The internal firewall is

The external firewall forwards traffic from (external IP) to (Content Switching vServer)

The Content Switching vServer splits trafic based on host name to 3 NetScaler Gateways (,, These gateways are available via a router

why do we need a dedicated router?

There is no chance to directly send traffic from on

Creating the admin partition

About the author

Johannes Norz

Johannes Norz is a Citrix Certified Expert on Networking and a Citrix Technology Advocate.

He frequently works for Citrix international Consulting Services and several education centres round the globe.

Add comment

By Johannes Norz

Recent Posts

Recent Comments