Citrix Gateway

配置ure time-out settings

You can configure Citrix Gateway to force a disconnection if there is no activity on the connection for a specified number of minutes. One minute before a session times out (disconnects), the user receives an alert indicating the session closes. If the session closes, the user must log on again.

The following time-out options are available.

  • Forced time-out.如果启用此设置,Citrix网关disconnects the session after the timeout interval elapses regardless of what the user is doing. There is no action the user can take to prevent the disconnection from occurring when the timeout interval elapses. This setting is enforced for users who connect with the Citrix Gateway plug-in, Citrix Workspace app, Secure Hub, or through a web browser. Minimum value is 1, and maximum value is 65535.
  • 会话超时。如果启用此设置,Citrix网关disconnects the session if no network activity is detected for the specified interval. This setting is enforced for users who connect with the Citrix Gateway plug-in, Citrix Workspace app, Citrix Secure Hub, or through a web browser. The default timeout setting is 30 minutes. Minimum value is 1, and maximum value is 65535.
  • Idle session time-out.The duration after which the Citrix Gateway plug-in terminates an idle session if there is no user activity, such as from the mouse, keyboard, or touch for the specified interval. This setting is enforced for users who connect with the Citrix Gateway plug-in only. Minimum value is 1, and maximum value is 9999.

You can enable any of the timeout settings by entering a value between 1 and 65536 to specify the minutes for the time-out interval. If you enable more than one of these settings, the first time-out interval to elapse closes the user device connection.

You configure time-out settings by configuring global settings or by using a session profile. When you add the profile to a session policy, the policy is then bound to a user, group, or virtual server. When you configure the time-out settings globally, the settings are applied to all user sessions.

Note:

  • In Always On (service mode or user mode), the VPN client ignores all the timeouts. Forced timeout and session timeout decisions occur on the Citrix ADC appliance and therefore those timeouts work as intended. If such timeout occurs, the VPN plug-in tries to perform automatic authentication.

    In Always On, as the user device must be connected via the VPN tunnel all the time, do not configure forced timeout or client idle timeout. However, session timeout can be configured to get rid of stale sessions.

  • Some applications, such as Microsoft Outlook, automatically send network traffic probes to email servers without any user intervention. Citrix recommends that you configure Idle session time-out with session time-out to ensure that a session left unattended on a user device times out in a reasonable time.

配置ure forced time-outs

A forced time-out disconnects the Citrix Gateway plug-in automatically after a specified amount of time. You can configure a forced time-out globally or as part of a session policy.

配置ure a global forced time-out

  1. In the configuration utility, on the配置urationtab, in the navigation pane, expand Citrix Gateway and then clickGlobal Settings.
  2. In the details pane, underSettings, clickChange global settings.
  3. On theNetwork Configurationtab, clickAdvanced Settings.
  4. In Forced Time-out (mins), type the number of minutes users can stay connected.
  5. In Forced Time-out Warning (mins), type the number of minutes before users are warned that the connection is due to be disconnected and then clickOK.

配置ure a forced time-out within a session policy

If you want to have further control over who receives the forced time-out, create a session policy and then apply the policy to a user or group.

  1. In the configuration utility, on the配置urationtab, in the navigation pane, expandCitrix Gateway>Policiesand then clickSession.
  2. In the details pane, clickAdd.
  3. In Name, type a name for the policy.
  4. Next to Request Profile, clickNew.
  5. In Name, type a name for the profile.
  6. On theNetwork Configurationtab, clickAdvanced.
  7. Under Timeouts, click Override Global and in Forced Time-out (mins) type the number of minutes users can stay connected.
  8. Next to Forced Time-out Warning (mins), clickOverride Globaland type the number of minutes users are warned that the connection is due to be disconnected. ClickOKtwice.
  9. In theCreate Session Policydialog box, next to命名表达式, select General, selectTrue value, clickAdd Expression, clickCreate,and then clickClose.

配置ure session or idle time-outs

You can use the Citrix ADC GUI to configure session and client time-out settings globally or to create a session policy. When you create a session policy and profile, set the expression to True.

To configure a session or client idle time-out globally by using the GUI

  1. On the配置urationtab, in the navigation pane, expandCitrix Gatewayand then clickGlobal Settings.
  2. In the details pane, underSettings, clickChange global settings.
  3. On theClient Experiencetab, do one or both of the following:
    • InSession Time-out (mins), type the number of minutes.
    • InClient Idle Time-out (mins), type the number of minutes and then clickOK.

To configure session or client idle time-out settings by using a session policy by using the GUI

  1. On the配置urationtab, in the navigation pane, expandCitrix Gateway>Policiesand then clickSession
  2. In theCitrix Gateway Session Policies and Profilespage, clickSession Profiles, and then clickAdd.
  3. In Name, type a name for the profile.
  4. On theClient Experiencetab, do one or both of the following:
    • Next toSession Time-out (mins), clickOverride Globaland then type the number of minutes and then clickCreate.
    • Next toClient Idle Time-out (mins), clickOverride Global, type the number of minutes and then clickCreate.
    1. In theCitrix Gateway Session Policies and Profilespage, clickSessions Policies, and then clickAdd.
  5. In theCreate Citrix Gateway Session Policy,
    • InName, enter the name for the policy.
    • InProfile, select the profile that specifies the action to be applied by the new session policy if the rule criteria are met.
    • selectAdvanced policy.
    • In theExpressionfield, add your expression or name of a named expression, specifying the traffic that matches the policy.
    • ClickCreate, and then clickClose.