Talk to us
by CitrixTechBag Intel Page

NetScaler Gateway

Your users reach DaaS, web apps and servers from outside. That front door has to be one you can patch tonight — NetScaler Gateway is the Citrix appliance in front of DaaS — SSL VPN, ICA proxy, clientless and RDP access with AAA sign-in, on MPX or VPX you run. Patch status: only 14.1-73.37 and 13.1-64.23 or later fix the September 2026 zero-days.

SSL VPN, ICA proxy, clientless, RDPPatch to 14.1-73.37 or 13.1-64.23+Quoted, no public price

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No published price; bought as NetScaler Fixed Capacity or within a Citrix platform subscription
Quote
Safe build
Or 13.1-64.23 and later; anything earlier is open to the exploited September 2026 flaws
14.1-73.37
Analysts
No current Gartner Magic Quadrant places NetScaler, so no analyst standing is claimed here
Not ranked
India
Sessions terminate on the MPX or VPX you install, in an Indian data centre if you choose
Your site

Quick answer

NetScaler Gateway is Citrix’s remote-access edge in front of DaaS: SSL VPN, ICA proxy, clientless VPN, RDP proxy and an AAA sign-in server, on MPX hardware or a VPX virtual appliance you run. Citrix publishes no price. It is also the surface hit by CitrixBleed 2 and the exploited September 2026 flaws, fixed only in 14.1-73.37 or 13.1-64.23 and later. Sessions end on your own box, in India if you put it there. Read more ↓ Show less ↑
Part 01 · Orient

The Citrix platform family

This page covers NetScaler Gateway — the remote-access role of NetScaler, in Advanced and Premium editions. The rest:

Quick facts

30-second orientation
Product
SSL VPN, ICA proxy, clientless VPN, RDP proxy and AAA sign-in on one NetScaler edge
Maker
Citrix, a business unit of privately held Cloud Software Group (CEO Tom Krause); run by co-presidents
Editions
Advanced and Premium, on MPX physical appliances or VPX virtual appliances
Price
No list price; quoted as NetScaler Fixed Capacity or inside UHMC or the Citrix Platform licence
Add-ons
EPA, SmartAccess and SmartControl for virtual-app use need extra universal licences
Patch now
CVE-2026-88771 and 88772 (Sept 2026, exploited) are fixed only in 14.1-73.37 and 13.1-64.23 or later
Lifecycle
No 13.1 maintenance since 15 Sep 2026, with end of life on 15 Sep 2027; 14.1 is supported until Aug 2030
Licensing
Since 15 April 2026, activation goes through the License Activation Service, not licence files
India
Self-hosted, so sessions end where you place it; Citrix has a Bengaluru office but no INR price
In India via
TechBag — build audit, patch plan, quote in INR with GST
Part 02 · Learn

Understand remote access gateways before you buy one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a remote access gateway?

One internet-facing appliance that signs users in and then gives them a VPN tunnel, a virtual-app session or a browser path inward.

A VPN, a jump host and a VDI portal vs one Gateway — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA VPN, a jump host and a VDI portalNetScaler Gateway
Front doors to maintainA VPN, an RDP jump host and a VDI portalOne Gateway vserver for VPN, ICA proxy and RDP
Reaching virtual appsFull tunnel first, then the desktopICA proxy straight to the DaaS session
Unmanaged devicesInstall a client or refuse accessClientless browser access to web apps
Device checksTrust whatever connectsEPA scan, then SmartAccess rules (extra licence)
Where sessions endScattered across boxes and cloudsOn the MPX or VPX you place, in India if you choose
What it is NOT—Per-app zero trust, or a box you can leave unpatched

The cheapest first step is a build check: list every Gateway and AAA vserver with its running version and compare it with 14.1-73.37 and 13.1-64.23.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where remote users connect

Gateway vserver

NetScaler Gateway virtual server

One virtual server on the appliance carries the user-facing modes: a full SSL VPN tunnel, ICA proxy for virtual apps, clientless web access and RDP proxy.

02
Who gets in

AAA

AAA virtual server with nFactor

An authentication, authorisation and auditing server checks every sign-in first; it is also a configuration named in the CitrixBleed advisories, so patch it with the gateway.

03
What runs on the device

Clients

Secure Access and EPA clients

The Citrix Secure Access client builds the full tunnel on Windows and macOS, and the Endpoint Analysis client scans the device first; both took fixes in July 2026.

04
Where it all runs

Appliance

MPX hardware or VPX virtual appliance

Gateway ships on MPX physical boxes or VPX virtual ones that you host; hardware is bought apart from the software subscription and keeps RMA cover for the device’s life.

One appliance at the edge — AAA sign-in first, then SSL VPN, ICA proxy, clientless or RDP proxy on MPX or VPX you run.

Part 03 · Evaluate

Nine capabilities. Connect, verify, operate.

NetScaler Gateway signs remote users in once, then hands them a tunnel, a virtual-app session or a browser path.

Connect
SSL VPN

Full tunnel to the network

The Secure Access client opens an SSL VPN tunnel from Windows or macOS, so thick-client and legacy apps work as if users sat in the office.

Connect
ICA proxy

Front door to virtual apps

ICA proxy relays Citrix DaaS sessions through the appliance, so users open published apps and desktops without any network tunnel.

Connect
Clientless + RDP

Browser and RDP paths

Clientless VPN serves internal web apps in a browser with nothing installed, and RDP proxy carries remote-desktop sessions without a full tunnel.

Verify
nFactor

Chained sign-in factors

nFactor strings together SAML, OAuth, LDAP, RADIUS, TACACS, client certificates and native or push OTP before any session starts.

Verify
EPA

Device scan at the door

Endpoint Analysis checks the device before access is granted; for virtual-app policies it needs extra universal licences on top of the edition.

Verify
SmartAccess

Session rules from scan results

SmartAccess and SmartControl turn scan outcomes into rules for what a virtual-app session may do; both sit behind the same extra licence.

Operate
WAF in front

Shield the sign-in pages

NetScaler’s WAF and API security tools can sit in front of Gateway and authentication vservers, as Citrix’s own NetScaler demo shows.

Operate
Certificates

ACME renewals from Console

NetScaler Console, formerly ADM, can set up ACME and zero-touch certificate management, so Gateway certificates renew without a manual swap.

Operate
Activation

Licences through LAS

Since 15 April 2026 Citrix products activate through the License Activation Service; appliances left on licence files stop working.

See it, don’t just read it

Watch NetScaler Gateway in action

WAF protection for Gateway and sign-in vservers, ACME certificate renewals from NetScaler Console, and a 2017 Unified Gateway overview for background.

NetScaler (official)·Live demo, 2024

Live Demo: Secure NetScaler Gateway/Auth vServers with NetScaler WAF and API Security tools

Putting NetScaler’s WAF and API security tools in front of Gateway and authentication virtual servers.

Citrix (official)·How-to, 2026

Citrix NetScaler: How to configure ACME and Zero Touch Certificate Management in NetScaler Console

Setting up ACME and zero-touch certificate handling for NetScaler appliances from NetScaler Console.

Citrix (official)·Overview, 2017

Citrix NetScaler Unified Gateway Overview

A 2017 overview of Unified Gateway; names, builds and licensing have all changed since, so treat it as background.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why NetScaler Gateway

Every remote path needs a front door. Gateway puts DaaS, VPN and RDP behind one sign-in.

Here’s what genuinely sets it apart — and exactly where it stops.

01

One edge for virtual apps and the VPN

The same appliance relays Citrix DaaS sessions through ICA proxy and runs a full SSL VPN for everything else, with clientless web access and RDP proxy beside them. For a Citrix estate that means one internet-facing edge, one sign-in through the AAA server and one set of certificates, not three separate front ends.

02

It terminates where you put it

Gateway is an MPX appliance or a VPX virtual appliance in your own data centre or cloud account, so every remote session ends on infrastructure you control. That suits Indian teams that want the termination point in India, since Citrix Cloud itself offers only US, EU and Asia Pacific South regions.

03

Device checks tied to virtual-app policy

Endpoint Analysis scans a device before it connects, and SmartAccess and SmartControl let the result decide what a virtual-app session may do. For virtual apps and desktops those features need extra universal licences, so put them in the first quote rather than finding them mid-rollout.

04

Where it stops

This is the most attacked part of a Citrix estate: CitrixBleed in 2023, CitrixBleed 2 and two more KEV-listed flaws in 2025, then the exploited CVE-2026-88771 and 88772 in September 2026. Builds before 14.1-73.37 or 13.1-64.23 are exposed. And as a VPN it grants network reach, not per-app zero trust.

The idea
One front door for DaaS and the VPN
The residency
Sessions end on the box you place
The patch line
14.1-73.37 or 13.1-64.23 and later
Proof, not promises

The numbers behind the platform

2 editions
Advanced and Premium, each sold on MPX hardware or VPX virtual appliances
— Vendor
5 edge roles
SSL VPN, ICA proxy, clientless VPN, RDP proxy and the AAA sign-in server
— Vendor
5 KEV entries
NetScaler Gateway flaws CISA listed as exploited between June 2025 and September 2026
— CISA
2026
the September bulletin: fixes ship only in 14.1-73.37 and 13.1-64.23 or later builds
— NVD
2029
the year 14.1 leaves maintenance, on 8 August; 13.1 already left it on 15 September 2026
— Vendor
999 instances
of each NetScaler form factor bundled into a Universal Hybrid Multi-Cloud subscription
— Vendor

What your NetScaler Gateway clean-up looks like

Day 1Patch

Check every build tonight

Read the running version on each Gateway; anything below 14.1-73.37 or 13.1-64.23 is exposed to the exploited September 2026 flaws.

Week 1Respond

Upgrade, then look back

Upgrade each appliance, then review sessions and logs for earlier compromise; a patch does not remove an intruder already inside.

Week 2Plan

Plan the move off 13.1

13.1 left maintenance on 15 September 2026, so schedule the move to 14.1, which Citrix maintains until 8 August 2029.

Month 1Model

Map who needs a tunnel

Sort users into ICA proxy only, clientless web, RDP admins and true full-tunnel needs; DaaS-only users can stay on ICA proxy.

Month 2Commit

Shrink the VPN

Pilot SecurAccess ZTNA beside the VPN for private web and TCP apps; Citrix supports running both together for a gradual move.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

3.9
48+ reviews*
74% would recommend
ICA proxy for DaaS4.4
SSL VPN reliability4.0
Sign-in options4.1
Patch burden2.9
Value for money3.4
5★
34%
4★
38%
3★
16%
2★
8%
1★
4%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“After the September advisory we went from 13.1-58.32 to 13.1-64.23 overnight. The CitrixBleed 2 build alone was not enough.”
Network Security Engineer
BFSI
Insurance
“ICA proxy is why we keep it. Branch staff open their DaaS desktops from one URL and never get a full network tunnel.”
Head of End-User Computing
Insurance
Manufacturing
“The EPA scan stops unpatched laptops before login, but the extra universal licences surprised our finance team at renewal.”
IT Security Manager
Manufacturing
Healthcare
“We run a VPX pair in our own Mumbai data centre, so every remote session ends on infrastructure we control.”
Infrastructure Lead
Healthcare
IT Services
“Moving activation to the License Activation Service before April mattered; a lab box still on a licence file went dark.”
Citrix Administrator
IT Services
Logistics
“Contractors use clientless access for two web apps with nothing to install, and RDP proxy covers our server admins.”
Systems Administrator
Logistics
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the remote access gateway market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Remote Access Gateway Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
NetScaler GatewayThis page

Quoted; Fixed Capacity or inside a Citrix platform subscription.

Grid 02 · The architecture

Access Breadth × Edge Run For You

The grid nobody publishes — how many access paths the product offers vs how much of the internet-facing edge the vendor runs and patches for you.

Vendor-run, narrow pathsVendor-run, broad pathsSelf-run, single pathSelf-run multi-path gateways
NetScaler GatewayThis page

VPN, ICA proxy, clientless and RDP proxy; every box is yours to patch.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

NetScaler Gateway vs the remote access field

Against Palo Alto GlobalProtect, Fortinet FortiGate VPN, Cisco Secure Client, Zscaler ZPA and F5 BIG-IP Zero Trust Access — on access modes, VDI, posture, price, exploited flaws, patching and India.

DimensionNetScaler GatewayPalo Alto GlobalProtectFortinet FortiGate VPNCisco Secure ClientZscaler Private Access (ZPA)F5 BIG-IP Zero Trust Access
What it isCitrix VPN + ICA proxyNGFW or Prisma VPNVPN on the firewallClient for Cisco kitCloud ZTNA, no VPNBIG-IP access module
Where it runsMPX or VPX, yoursFirewall or Prisma cloudYour FortiGateYour Cisco headendCloud plus connectorsBIG-IP you host
Access modesTunnel, clientless, RDPAgent + clientlessIPsec dial-up clientDevice or per-app VPNConnector app + browserProxy, Per-App, IPsec
Virtual desktop accessNative ICA proxyInside the tunnelThrough the IPsec tunnelTunnel to the desktopDesktop as a private appCitrix VDI listed
Device postureEPA, extra licenceHIP needs a licencePosture is a paid tierPosture in PremierAgent + browser signalsMDM verdicts gate access
Identity and MFAnFactor, SAML, OTPLDAP, SAML, RADIUS…FortiAuthenticator addsSAML at the headendSAML, OIDC, SCIMSAML, OAuth, OIDC
Pricing modelEdition on an applianceFree base, paid extrasFirewall-bundledPer unique userPer-user editionsBIG-IP licence models
Published entry priceNot publishedBasic VPN at no chargeNo public price25-user minimumReported $4–11/userUnpriced on f5.com
Included vs add-onUniversal licences extraGateway licence per boxEnterprise for supportPremier for postureNetwork Connector extraModule plus platform
Exploited flaws5 KEV entries since 2025CVE-2024-3400CVE-2024-21762CVE-2023-20269No VPN listenerTwo exploited in 2026
Who patches the edgeYou, every applianceYou, or Palo AltoYou, on each FortiGateYou, on each headendZscaler, mostlyYou; old trains lapsed
India terminationYour Indian siteYour site or MumbaiYour Indian FortiGateYour Indian headendIndian PoPs unnamedYour own Indian BIG-IP
Lock-in and exitTied to Citrix DaaSPalo Alto firewallsFortiGate requiredCisco headendsZscaler’s cloudBIG-IP policy flows
Best fitCitrix DaaS estatesPalo Alto firewall shopsFortiGate estatesCisco network estatesRetiring the VPNBIG-IP owners
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose NetScaler Gateway if…

  • ✓Your users reach Citrix DaaS from outside, and you want ICA proxy, SSL VPN and RDP proxy on one appliance you own
  • ✓Remote sessions must end on hardware in your own Indian data centre rather than in a vendor’s cloud
  • ✓You already run NetScaler and can commit to patching within days of each Citrix security bulletin

Compare alternatives if…

  • ✓You want per-app access without a network tunnel — Citrix SecurAccess ZTNA or Zscaler ZPA work that way
  • ✓Your firewalls already carry a VPN you are licensed for — GlobalProtect, FortiGate or Cisco Secure Client
  • ✓You would rather not run an internet-facing appliance at all — a cloud-brokered ZTNA hands that job to the vendor

Do not expect…

  • ✓A published price, or device checks for virtual apps without extra universal licences
  • ✓Per-application zero trust — this is a VPN and proxy; SecurAccess ZTNA is Citrix’s product for that
  • ✓Safety on an old build: the CitrixBleed 2 fixes (14.1-43.56, 13.1-58.32) do not cover the September 2026 flaws

TechBag has no remote access gateway guide yet, so NetScaler Gateway sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What do scattered remote-access front ends cost you?

Drag the sliders (remote users; admin-hour cost). Estimates model IT time spent per remote user on client installs, access tickets and separate VPN, RDP and VDI front ends at an assumed 1.5 hours per user a year, with 70% of it removed by one gateway and one sign-in. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual remote-access admin cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Citrix publishes no price for NetScaler Gateway or any current offering. Gateway runs on NetScaler, bought standalone as NetScaler Fixed Capacity (throughput and instances bought individually) or bundled into Universal Hybrid Multi-Cloud and Citrix Platform subscriptions; MPX hardware is bought separately and carries RMA for the device’s life. For virtual-app use, EPA, SmartAccess and SmartControl need extra universal licences. Citrix shows no rupee price. TechBag checks your builds and users first, then quotes in INR with GST.

NetScaler Fixed Capacity

Best for a Gateway bought on its own

  • Advanced or Premium edition
  • Throughput and instances bought individually
  • MPX hardware priced separately

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Inside a Citrix subscription

Best for estates already licensing Citrix DaaS

  • NetScaler instances bundled in UHMC
  • Unlimited throughput in the Citrix Platform licence
  • Universal licences for EPA and SmartAccess

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Build

Is every Gateway and AAA vserver on 14.1-73.37, 13.1-64.23 or later, or on 14.1-73.37 FIPS or 13.1-37.279 FIPS?

2
Version line

Is any appliance still on 13.1, out of maintenance since 15 Sep 2026, or on 12.1 or 13.0, already end-of-life?

3
Activation

Has every appliance moved to the License Activation Service, which replaced licence files on 15 April 2026?

4
Edition

Advanced or Premium, and does the quote include universal licences for EPA, SmartAccess and SmartControl?

5
Clients

Are Windows Secure Access and EPA clients updated for July 2026’s CVE-2026-53565 and CVE-2026-53566?

6
Access modes

Which users truly need a full tunnel, and which can use ICA proxy, clientless access or RDP proxy instead?

7
Sign-in

Does nFactor enforce MFA, through SAML, RADIUS or native OTP, on every Gateway mode you expose?

8
Placement

Will the appliances sit in an Indian data centre or cloud region, and is a hardware RMA path agreed?

FAQ

Questions buyers ask

It is the remote-access side of Citrix NetScaler: an MPX or VPX appliance that runs SSL VPN, ICA proxy for Citrix DaaS, clientless VPN, RDP proxy and an AAA virtual server for sign-in. It comes in Advanced and Premium editions, and for most Citrix estates it is the front door users reach from outside.

Ready to evaluate NetScaler Gateway?

Check your builds against the September 2026 fixes first, or let a TechBag advisor map which users need a tunnel and which only need ICA proxy.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.