A Citrix Administrator needs to ensure that all ICA traffic between the Citrix Gateway and the internal VDA is encrypted using TLS. Which setting must be enabled on the Delivery Group properties to achieve this?
Trap 1: Enable 'Session Reliability' on the Delivery Group.
Session Reliability keeps sessions active during network interruptions by maintaining the connection between the client and the server. It does not enforce encryption protocols for the ICA traffic, which is the primary objective of protecting data packets against eavesdropping or unauthorized interception during the transmission process.
Trap 2: Enable 'SmartAccess' filters on the Delivery Group.
SmartAccess filters are used to control application or desktop availability based on the connection context or endpoint device posture. While this adds a layer of access control, it does not mandate the use of TLS encryption for the actual ICA traffic flow between components.
Trap 3: Install a digital certificate on the VDA.
While installing a certificate is a prerequisite for TLS communication, simply having one does not force the VDA to encrypt ICA traffic. The policy must be explicitly configured within the Delivery Group settings to enforce TLS for all session traffic, otherwise, the VDA might revert to unencrypted communication.
- A
Enable 'Session Reliability' on the Delivery Group.
Why it fails: Session Reliability keeps sessions active during network interruptions by maintaining the connection between the client and the server. It does not enforce encryption protocols for the ICA traffic, which is the primary objective of protecting data packets against eavesdropping or unauthorized interception during the transmission process.
- B
Set 'ICA Encryption' to 'TLS' on the Delivery Group.
Setting the ICA encryption level to TLS ensures that the VDA will only accept encrypted connections. This configuration forces the Citrix Gateway to establish a secure handshake with the VDA, ensuring that all session traffic is protected via encryption protocols across the internal backend network segments.
- C
Enable 'SmartAccess' filters on the Delivery Group.
Why it fails: SmartAccess filters are used to control application or desktop availability based on the connection context or endpoint device posture. While this adds a layer of access control, it does not mandate the use of TLS encryption for the actual ICA traffic flow between components.
- D
Install a digital certificate on the VDA.
Why it fails: While installing a certificate is a prerequisite for TLS communication, simply having one does not force the VDA to encrypt ICA traffic. The policy must be explicitly configured within the Delivery Group settings to enforce TLS for all session traffic, otherwise, the VDA might revert to unencrypted communication.